An Integrated Cyber Security Risk Management Approach for a Cyber-Physical System

被引:68
|
作者
Kure, Halima Ibrahim [1 ]
Islam, Shareeful [1 ]
Razzaque, Mohammad Abdur [2 ]
机构
[1] Univ East London, Sch Architecture Comp & Engn, London E16 2RD, England
[2] Teesside Univ, Sch Comp Media & Arts, Middlesbrough TS1 3BX, England
来源
APPLIED SCIENCES-BASEL | 2018年 / 8卷 / 06期
关键词
cybersecurity; risk management; cyber-physical systems; cybersecurity attack scenario; supervisory control and data acquisition (SCADA) systems; cascading effect; MODEL; VULNERABILITY; ATTACK;
D O I
10.3390/app8060898
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
A cyber-physical system (CPS) is a combination of physical system components with cyber capabilities that have a very tight interconnectivity. CPS is a widely used technology in many applications, including electric power systems, communications, and transportation, and healthcare systems. These are critical national infrastructures. Cybersecurity attack is one of the major threats for a CPS because of many reasons, including complexity and interdependencies among various system components, integration of communication, computing, and control technology. Cybersecurity attacks may lead to various risks affecting the critical infrastructure business continuity, including degradation of production and performance, unavailability of critical services, and violation of the regulation. Managing cybersecurity risks is very important to protect CPS. However, risk management is challenging due to the inherent complex and evolving nature of the CPS system and recent attack trends. This paper presents an integrated cybersecurity risk management framework to assess and manage the risks in a proactive manner. Our work follows the existing risk management practice and standard and considers risks from the stakeholder model, cyber, and physical system components along with their dependencies. The approach enables identification of critical CPS assets and assesses the impact of vulnerabilities that affect the assets. It also presents a cybersecurity attack scenario that incorporates a cascading effect of threats and vulnerabilities to the assets. The attack model helps to determine the appropriate risk levels and their corresponding mitigation process. We present a power grid system to illustrate the applicability of our work. The result suggests that risk in a CPS of a critical infrastructure depends mainly on cyber-physical attack scenarios and the context of the organization. The involved risks in the studied context are both from the technical and nontechnical aspects of the CPS.
引用
收藏
页数:29
相关论文
共 50 条
  • [31] A Review of Cyber-Physical Energy System Security Assessment
    Rasmussen, Theis B.
    Yang, Guangya
    Nielsen, Arne H.
    Dong, Zhaoyang
    2017 IEEE MANCHESTER POWERTECH, 2017,
  • [32] Research on Security Estimation and Control of Cyber-Physical System
    Cai, Xiaobo
    Han, Ke
    Li, Yan
    Wang, Huihui
    Zhang, Jiajin
    Zhang, Yue
    2020 IEEE 39TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2020,
  • [33] Cyber-Physical System Security for the Electric Power Grid
    Sridhar, Siddharth
    Hahn, Adam
    Govindarasu, Manimaran
    PROCEEDINGS OF THE IEEE, 2012, 100 (01) : 210 - 224
  • [34] Countermeasures to Enhance Cyber-Physical System Security and Safety
    Sabaliauskaite, Giedre
    Mathur, Aditya P.
    2014 38TH ANNUAL IEEE INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW 2014), 2014, : 13 - 18
  • [35] A Review of Cyber-Physical Security in the Generation System of the Grid
    Siu, Jun Yen
    Panda, Sanjib Kumar
    IECON 2020: THE 46TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2020, : 1520 - 1525
  • [36] Cyber-physical System Security for Networked Industrial Processes
    Shuang Huang
    Chun-Jie Zhou
    Shuang-Hua Yang
    Yuan-Qing Qin
    International Journal of Automation and Computing, 2015, (06) : 567 - 578
  • [37] An integrated safety and security analysis for cyber-physical harm scenarios
    Guzman, Nelson H. Carreras
    Kozine, Igor
    Lundteigen, Mary Ann
    SAFETY SCIENCE, 2021, 144
  • [38] Cyber-physical System Security of Vehicle Charging Stations
    Gottumukkala, Raju
    Merchant, Rizwan
    Tauzin, Adam
    Leon, Kaleb
    Roche, Andrew
    Darby, Paul
    2019 IEEE GREEN TECHNOLOGIES CONFERENCE (GREENTECH), 2019,
  • [39] Integrating artificial intelligence in cyber security for cyber-physical systems
    Alowaidi, Majed
    Sharma, Sunil Kumar
    AlEnizi, Abdullah
    Bhardwaj, Shivam
    ELECTRONIC RESEARCH ARCHIVE, 2023, 31 (04): : 1876 - 1896
  • [40] On modeling of electrical cyber-physical systems considering cyber security
    Wang, Yi-nan
    Lin, Zhi-yun
    Liang, Xiao
    Xu, Wen-yuan
    Yang, Qiang
    Yan, Gang-feng
    FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2016, 17 (05) : 465 - 478