Towards an Automated and Dynamic Risk Management Response System

被引:6
|
作者
Gonzalez-Granadillo, Gustavo [1 ]
Alvarez, Ender [1 ]
Motzek, Alexander [2 ]
Merialdo, Matteo [3 ]
Garcia-Alfaro, Joaquin [1 ]
Debar, Herve [1 ]
机构
[1] Telecom SudParis, Inst Mines Telecom, SAMOVAR, CNRS UMR 5157, 9 Rue Charles Fourier, F-91011 Evry, France
[2] Univ Lubeck, Inst Informat Syst, Ratzeburger Allee 160, D-23562 Lubeck, Germany
[3] RHEA Grp, Ave Pasteur 23, B-1300 Wavre, Belgium
来源
基金
欧盟第七框架计划;
关键词
Dynamic response system; RORI; Operational impact; Automatic response; Critical infrastructures;
D O I
10.1007/978-3-319-47560-8_3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Achieving a fully automated and dynamic system in critical infrastructure scenarios is an open issue in ongoing research. Generally, decisions in SCADA systems require a manual intervention, that in most of the cases is performed by highly experienced operators. In this paper we propose a framework consisting of a proactive management software that aims at anticipating the occurrence of potential attacks. It conducts an initial evaluation of reported proactive evidences based on a quantitative metric of monetary return on response investment. The framework evaluates and selects mitigation actions from a pool of candidates, by ranking them in terms of financial and operational impacts. The purpose of this process is to select an optimal set of mitigation actions from financial and operational perspectives and propose them to reduce the risk of threats against the monitored system, without sacrificing an organization's missions in favor of security. A real world case study of a SCADA environment shows the applicability of the model, from the analysis of the input data to the selection of the response plan.
引用
收藏
页码:37 / 53
页数:17
相关论文
共 50 条
  • [41] Integrated Risk Management for Automated Driving
    Lee, Jun-Yung
    Kim, Beom-Jun
    Yi, Kyong-Su
    2014 14TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND SYSTEMS (ICCAS 2014), 2014, : 1452 - 1457
  • [42] Data Integration for Thailand Disaster Risk and Response Management System
    Kovavisaruch, L.
    Kamolvej, P.
    Prommoon, G.
    Iamrahong, N.
    2013 PROCEEDINGS OF TECHNOLOGY MANAGEMENT IN THE IT-DRIVEN SERVICES (PICMET'13), 2013, : 1239 - 1248
  • [43] TOWARDS A DYNAMIC URBAN MANAGEMENT SCIENCE
    TAPIERO, CS
    TRANSACTIONS OF THE NEW YORK ACADEMY OF SCIENCES, 1973, 35 (04): : 271 - 282
  • [44] Towards distributed and dynamic network management
    Sahai, A
    Morin, C
    NOMS '98 - 1998 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, VOLS 1-3, 1998, : 455 - 464
  • [45] Automated Event Driven Dynamic Case Management
    Scheit, Stefan
    Ploom, Tarmo
    O'Reilly, Barry
    Glaser, Axel
    2016 IEEE 20TH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING WORKSHOP (EDOCW), 2016, : 62 - 71
  • [46] Skeptical Dynamic Dependability Management for Automated Systems
    Arnez, Fabio
    Ollier, Guillaume
    Radermacher, Ansgar
    Adedjouma, Morayo
    Gerasimou, Simos
    Mraidha, Chokri
    Terrier, Francois
    2022 25TH EUROMICRO CONFERENCE ON DIGITAL SYSTEM DESIGN (DSD), 2022, : 118 - 125
  • [47] Automated and Dynamic Access Control Management in OSN
    Abid, Sohail
    Daud, Imran
    4TH INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING (IC)2, 2021, : 348 - 353
  • [48] Automated System Testing for a Learning Management System
    Krisper, Lukas
    Ebner, Markus
    Ebner, Martin
    INTERNATIONAL JOURNAL OF EMERGING TECHNOLOGIES IN LEARNING, 2020, 15 (24) : 89 - 100
  • [49] DYNAMIC SYSTEM WITH RANDOM STRUCTURE FOR MODELING SECURITY AND RISK MANAGEMENT IN CYBERSPACE
    Dzhalladova, Irada
    Ruzickova, Miroslava
    OPUSCULA MATHEMATICA, 2019, 39 (01) : 23 - 37
  • [50] Ontology-Based System for Dynamic Risk Management in Administrative Domains
    Vega-Barbas, Mario
    Villagra, Victor A.
    Monje, Fernando
    Riesco, Raul
    Larriva-Novo, Xavier
    Berrocal, Julio
    APPLIED SCIENCES-BASEL, 2019, 9 (21):