A Cyber Incident Response and Recovery Framework to Support Operators of Industrial Control Systems

被引:8
|
作者
Staves, Alexander [1 ]
Anderson, Tom [1 ]
Balderstone, Harry [1 ]
Green, Benjamin [1 ]
Gouglidis, Antonios [1 ]
Hutchison, David [1 ]
机构
[1] Univ Lancaster, Sch Comp & Commun, Lancaster LA1 4WA, England
基金
英国工程与自然科学研究理事会;
关键词
ICS; CNI; OT; Cyber Security; Cyber Incident; Response and Recovery; SECURITY; MANAGEMENT;
D O I
10.1016/j.ijcip.2021.100505
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the last decade, we have seen a shift in the focus of cyber attacks, moving from traditional IT systems to include more specialised Industrial Control Systems (ICS), often found within Critical National Infrastructure (CNI). Despite a push from governments to introduce appropriate legislation and guidance for such systems, operators of ICS and CNI still face multiple challenges in their cyber incident response and recovery capabilities, a theme that is often viewed as a last line of defence in minimising the impact of cyber attacks. This paper provides the following contributions: Firstly, we analyse existing standards and guidelines within cyber incident response and recovery. This analysis provides a structure on key response and recovery phases, a foundational understanding of associated requirements for these, and identifies challenges that could affect the quality of in-practice response and recovery capabilities. Using this analysis as a baseline, we examine how response and recovery processes are currently undertaken in practice through engagement with UK-based CNI operators and regulators. Secondly, as a starting point towards improving identified challenges in existing standards and guidelines and their use in practice, we propose a framework, built using the outputs identified from the document analysis and the stakeholder engagement, for use by operators to support them in assessing and improving their response and recovery capabilities.
引用
收藏
页数:24
相关论文
共 50 条
  • [31] Security framework for industrial collaborative robotic cyber-physical systems
    Khalid, Azfar
    Kirisci, Pierre
    Khan, Zeashan Hameed
    Ghrairi, Zied
    Thoben, Klaus-Dieter
    Pannek, Juergen
    COMPUTERS IN INDUSTRY, 2018, 97 : 132 - 145
  • [32] Virtual incident response functions in control systems
    Murillo Piedrahita, Andres F.
    Gaur, Vikram
    Giraldo, Jairo
    Cardenas, Alvaro A.
    Julieta Rueda, Sandra
    COMPUTER NETWORKS, 2018, 135 : 147 - 159
  • [33] Current cyber-defense trends in industrial control systems
    Enrique Rubio, Juan
    Alcaraz, Cristina
    Roman, Rodrigo
    Lopez, Javier
    COMPUTERS & SECURITY, 2019, 87
  • [34] Cyber (In-)security of Industrial Control Systems: A Societal Challenge
    Luiijf, Eric
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2015, 2015, 9337 : 7 - 15
  • [35] Cyber Terror Attack Analysis for Industrial Control Systems (SCADA)
    Sogut, Esra
    Erdem, O. Ayhan
    JOURNAL OF POLYTECHNIC-POLITEKNIK DERGISI, 2020, 23 (02): : 557 - 566
  • [36] Poisoning Attacks on Cyber Attack Detectors for Industrial Control Systems
    Kravchik, Moshe
    Biggio, Battista
    Shabtai, Asaf
    36TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2021, 2021, : 116 - 125
  • [37] Interval forecasting of cyber-attacks on industrial control systems
    Ivanyo, Y. M.
    Krakovsky, Y. M.
    Luzgin, A. N.
    INTERNATIONAL CONFERENCE ON MECHANICAL ENGINEERING, AUTOMATION AND CONTROL SYSTEMS 2017, 2018, 327
  • [38] Review on Cyber Vulnerabilities of Communication Protocols in Industrial Control Systems
    Xu, Yikai
    Yang, Yi
    Li, Tianran
    Ju, Jiaqi
    Wang, Qi
    2017 IEEE CONFERENCE ON ENERGY INTERNET AND ENERGY SYSTEM INTEGRATION (EI2), 2017,
  • [39] A Connective Framework to Support the Lifecycle of Cyber-Physical Production Systems
    Harrison, Robert
    Vera, Daniel A.
    Ahmad, Bilal
    PROCEEDINGS OF THE IEEE, 2021, 109 (04) : 568 - 581
  • [40] Digital Twin-Enhanced Incident Response for Cyber-Physical Systems
    Allison, David
    Smith, Paul
    McLaughlin, Kieran
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,