Cyber Threat Intelligence for Improving Cybersecurity and Risk Management in Critical Infrastructure

被引:0
|
作者
Kure, Halima Ibrahim [1 ]
Islam, Shareeful [1 ]
机构
[1] Univ East London, Sch Architecture Comp & Engn, London, England
关键词
Cybersecurity; Cyber Threat Intelligence; Cyber Security Risk Management; Critical Infrastructure; Security Control; SECURITY;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cyber-attack is one of the significant threats affecting to any organisation specifically to the Critical Infrastructure (CI) organisation. These attacks are nowadays more sophisticated, multi-vectored and less predictable, which make the Cyber Security Risk Management (CSRM) task more challenging. Critical Infrastructure needs a new line of security defence to control these threats and minimise risks. Cyber Threat Intelligence (CTI) provides evidence-based information about the threats aiming to prevent threats. There are existing works and industry practice that emphasise the necessity of CTI and provides methods for threat intelligence and sharing. However, despite these significant efforts, there is a lack of focus on how CTI information can support the CSRM activities so that the organisation can undertake appropriate controls to mitigate the risk proactively. This paper aims to fill this gap by integrating CTI for improving cybersecurity risks management practice specifically focusing on the critical infrastructure. In particular, the proposed approach contributes beyond state of the art practice by incorporating CTI information for the risk management activities. This helps the organisation to provide adequate and appropriate controls from strategic, tactical and operational perspectives. We have integrated concepts relating to CTI and CSRM so that threat actor's profile, attack detailed can support calculating the risk. We consider smart grid system as a Critical Infrastructure to demonstrate the applicability of the work. The result shows that cyber risks in critical infrastructures can be minimised if CTI information is gathered and used as part of CSRM activities. CTI not only supports understanding of threat for accurate risk estimation but also evaluates the effectiveness of existing controls and recommend necessity controls to improve overall cybersecurity. Also, the result shows that our approach provides early warning about issues that need immediate attention.
引用
收藏
页码:1478 / 1502
页数:25
相关论文
共 50 条
  • [1] Cyber threat intelligence for critical infrastructure security
    Osliak, Oleksii
    Saracino, Andrea
    Martinelli, Fabio
    Mori, Paolo
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (23):
  • [2] Cyber Threat Intelligence in Risk Management A Survey of the Impact of Cyber Threat Intelligence on Saudi Higher Education Risk Management
    Aljuhami, Amira M.
    Bamasoud, Doaa M.
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (10) : 156 - 164
  • [3] Assets focus risk management framework for critical infrastructure cybersecurity risk management
    Kure, Halima Ibrahim
    Islam, Shareeful
    [J]. IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2019, 4 (04) : 332 - 340
  • [4] Critical Infrastructure Cyber-Security Risk Management
    Spyridopoulos, Theodoros
    Maraslis, Konstantinos
    Tryfonas, Theo
    Oikonomou, George
    [J]. TERRORISTS' USE OF THE INTERNET: ASSESSMENT AND RESPONSE, 2017, 136 : 59 - 76
  • [5] Critical Infrastructure Cyber Threat - A Case Study
    Wangdi, Y.
    Veal, D.
    Maj, S. P.
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2011, 11 (06): : 20 - 23
  • [6] A Systematic Literature Review on Cyber Threat Intelligence for Organizational Cybersecurity Resilience
    Saeed, Saqib
    Suayyid, Sarah A.
    Al-Ghamdi, Manal S.
    Al-Muhaisen, Hayfa
    Almuhaideb, Abdullah M.
    [J]. SENSORS, 2023, 23 (16)
  • [7] Cyber Security Risk Management in the SCADA Critical Infrastructure Environment
    Henrie, Morgan
    [J]. ENGINEERING MANAGEMENT JOURNAL, 2013, 25 (02) : 38 - 45
  • [8] Evaluating and Improving Cybersecurity Capabilities of the Energy Critical Infrastructure
    Curtis, Pamela D.
    Mehravari, Nader
    [J]. 2015 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2015,
  • [9] A Review of Cybersecurity Risk and Consequences for Critical Infrastructure
    Touhiduzzaman, Md
    Gourisetti, Sri Nikhil Gupta
    Eppinger, Crystal
    Somani, Abhishek
    [J]. 2019 RESILIENCE WEEK (RWS), 2019, : 7 - 13
  • [10] Risk Assessment of Sharing Cyber Threat Intelligence
    Albakri, Adham
    Boiten, Eerke
    Smith, Richard
    [J]. COMPUTER SECURITY, ESORICS 2020 INTERNATIONAL WORKSHOPS, 2020, 12580 : 92 - 113