An Integrated Cyber Security Risk Management Approach for a Cyber-Physical System

被引:68
|
作者
Kure, Halima Ibrahim [1 ]
Islam, Shareeful [1 ]
Razzaque, Mohammad Abdur [2 ]
机构
[1] Univ East London, Sch Architecture Comp & Engn, London E16 2RD, England
[2] Teesside Univ, Sch Comp Media & Arts, Middlesbrough TS1 3BX, England
来源
APPLIED SCIENCES-BASEL | 2018年 / 8卷 / 06期
关键词
cybersecurity; risk management; cyber-physical systems; cybersecurity attack scenario; supervisory control and data acquisition (SCADA) systems; cascading effect; MODEL; VULNERABILITY; ATTACK;
D O I
10.3390/app8060898
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
A cyber-physical system (CPS) is a combination of physical system components with cyber capabilities that have a very tight interconnectivity. CPS is a widely used technology in many applications, including electric power systems, communications, and transportation, and healthcare systems. These are critical national infrastructures. Cybersecurity attack is one of the major threats for a CPS because of many reasons, including complexity and interdependencies among various system components, integration of communication, computing, and control technology. Cybersecurity attacks may lead to various risks affecting the critical infrastructure business continuity, including degradation of production and performance, unavailability of critical services, and violation of the regulation. Managing cybersecurity risks is very important to protect CPS. However, risk management is challenging due to the inherent complex and evolving nature of the CPS system and recent attack trends. This paper presents an integrated cybersecurity risk management framework to assess and manage the risks in a proactive manner. Our work follows the existing risk management practice and standard and considers risks from the stakeholder model, cyber, and physical system components along with their dependencies. The approach enables identification of critical CPS assets and assesses the impact of vulnerabilities that affect the assets. It also presents a cybersecurity attack scenario that incorporates a cascading effect of threats and vulnerabilities to the assets. The attack model helps to determine the appropriate risk levels and their corresponding mitigation process. We present a power grid system to illustrate the applicability of our work. The result suggests that risk in a CPS of a critical infrastructure depends mainly on cyber-physical attack scenarios and the context of the organization. The involved risks in the studied context are both from the technical and nontechnical aspects of the CPS.
引用
收藏
页数:29
相关论文
共 50 条
  • [1] Cyber security of railway cyber-physical system (CPS) - A risk management methodology
    Wang, Zezhou
    Liu, Xiang
    COMMUNICATIONS IN TRANSPORTATION RESEARCH, 2022, 2
  • [2] Cyber-physical system homeostatic security management
    Zegzhda D.P.
    Pavlenko E.Y.
    Automatic Control and Computer Sciences, 2017, 51 (8) : 805 - 816
  • [3] An Integrated Cyber-Physical Fault Management Approach
    Ghosh, Purboday
    Karsai, Gabor
    2020 IEEE 23RD INTERNATIONAL SYMPOSIUM ON REAL-TIME DISTRIBUTED COMPUTING (ISORC 2020), 2020, : 148 - 149
  • [4] Event Correlation in the Integrated Cyber-Physical Security System
    Kotenko, Igor V.
    Levshun, Dmitry S.
    Chechulin, Andrey A.
    PROCEEDINGS OF THE XIX IEEE INTERNATIONAL CONFERENCE ON SOFT COMPUTING AND MEASUREMENTS (SCM 2016), 2016, : 484 - 486
  • [5] The Importance Of Security In Cyber-Physical System
    alrefaei, Faisal
    2020 IEEE 6TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2020,
  • [6] Boosting Cyber-Physical System Security
    Kutzler, Tobias
    Wolter, Alexandra
    Kenner, Andy
    Dassow, Stephan
    IFAC PAPERSONLINE, 2021, 54 (01): : 976 - 981
  • [7] Security Analysis of Cyber-Physical System
    Li, Bo
    Zhang, Lichen
    MATERIALS SCIENCE, ENERGY TECHNOLOGY, AND POWER ENGINEERING I, 2017, 1839
  • [8] An integrated approach of designing functionality with security for distributed cyber-physical systems
    Tripathi, Dipty
    Biswas, Amit
    Tripathi, Anil Kumar
    Singh, Lalit Kumar
    Chaturvedi, Amrita
    JOURNAL OF SUPERCOMPUTING, 2022, 78 (13): : 14813 - 14845
  • [9] An integrated approach of designing functionality with security for distributed cyber-physical systems
    Dipty Tripathi
    Amit Biswas
    Anil Kumar Tripathi
    Lalit Kumar Singh
    Amrita Chaturvedi
    The Journal of Supercomputing, 2022, 78 : 14813 - 14845
  • [10] An Integrated Scheme for Cyber-physical Building Energy Management System
    Wang, Shaolin
    Zhang, Guiqing
    Shen, Bin
    Xie, Xiuying
    CEIS 2011, 2011, 15