A Cyber Incident Response and Recovery Framework to Support Operators of Industrial Control Systems

被引:8
|
作者
Staves, Alexander [1 ]
Anderson, Tom [1 ]
Balderstone, Harry [1 ]
Green, Benjamin [1 ]
Gouglidis, Antonios [1 ]
Hutchison, David [1 ]
机构
[1] Univ Lancaster, Sch Comp & Commun, Lancaster LA1 4WA, England
基金
英国工程与自然科学研究理事会;
关键词
ICS; CNI; OT; Cyber Security; Cyber Incident; Response and Recovery; SECURITY; MANAGEMENT;
D O I
10.1016/j.ijcip.2021.100505
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the last decade, we have seen a shift in the focus of cyber attacks, moving from traditional IT systems to include more specialised Industrial Control Systems (ICS), often found within Critical National Infrastructure (CNI). Despite a push from governments to introduce appropriate legislation and guidance for such systems, operators of ICS and CNI still face multiple challenges in their cyber incident response and recovery capabilities, a theme that is often viewed as a last line of defence in minimising the impact of cyber attacks. This paper provides the following contributions: Firstly, we analyse existing standards and guidelines within cyber incident response and recovery. This analysis provides a structure on key response and recovery phases, a foundational understanding of associated requirements for these, and identifies challenges that could affect the quality of in-practice response and recovery capabilities. Using this analysis as a baseline, we examine how response and recovery processes are currently undertaken in practice through engagement with UK-based CNI operators and regulators. Secondly, as a starting point towards improving identified challenges in existing standards and guidelines and their use in practice, we propose a framework, built using the outputs identified from the document analysis and the stakeholder engagement, for use by operators to support them in assessing and improving their response and recovery capabilities.
引用
收藏
页数:24
相关论文
共 50 条
  • [21] Cyber Crisis Management: A decision-support framework for disclosing security incident information
    Kulikova, Olga
    Heil, Ronald
    van den Berg, Jan
    Pieters, Wolter
    2012 ASE INTERNATIONAL CONFERENCE ON CYBER SECURITY (CYBERSECURITY), 2012, : 103 - 112
  • [22] A survey of cyber security management in industrial control systems
    Knowles, William
    Prince, Daniel
    Hutchison, David
    Disso, Jules Ferdinand Pagna
    Jones, Kevin
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2015, 9 : 52 - 80
  • [23] Cyber Physical Security for Industrial Control Systems and IoT
    Kobara, Kazukuni
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2016, E99D (04): : 787 - 795
  • [24] Adversarial Attacks in Industrial Control Cyber Physical Systems
    Figueroa, Henry
    Wang, Yi
    Giakos, George C.
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGING SYSTEMS AND TECHNIQUES (IST 2022), 2022,
  • [25] Modeling cyber-attacks on Industrial Control Systems
    Paliath, Vivin
    Shakarian, Paulo
    IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS: CYBERSECURITY AND BIG DATA, 2016, : 316 - 318
  • [26] A Survey of Cyber Security and Safety in Industrial Control Systems
    Ma, Yi-Wei
    Tu, Yi-Hao
    Tsou, Chia-Wei
    Chiang, Yen-Neng
    Chen, Jiann-Liang
    JOURNAL OF INTERNET TECHNOLOGY, 2024, 25 (04): : 541 - 550
  • [27] Adversarial Attacks in Industrial Control Cyber Physical Systems
    Figueroa, Henry
    Wang, Yi
    Giakos, George C.
    IST 2022 - IEEE International Conference on Imaging Systems and Techniques, Proceedings, 2022,
  • [28] Cyber security threats in industrial control systems and protection
    Marali, Mounesh
    Sudarsan, Sithu D.
    Gogioneni, Ashok
    PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING & COMMUNICATION ENGINEERING (ICACCE-2019), 2019,
  • [29] Recovery Scheme for Industrial Control Systems
    Khalili, Abdullah
    Keikha, Mahsa
    Sami, Ashkan
    Safavi, Ali Akbar
    2013 5TH CONFERENCE ON INFORMATION AND KNOWLEDGE TECHNOLOGY (IKT), 2013, : 279 - 283
  • [30] A Spiking One-Class Anomaly Detection Framework for Cyber-Security on Industrial Control Systems
    Demertzis, Konstantinos
    Iliadis, Lazaros
    Spartalis, Stefanos
    ENGINEERING APPLICATIONS OF NEURAL NETWORKS, EANN 2017, 2017, 744 : 122 - 134