An Integrated Cyber Security Risk Management Approach for a Cyber-Physical System

被引:68
|
作者
Kure, Halima Ibrahim [1 ]
Islam, Shareeful [1 ]
Razzaque, Mohammad Abdur [2 ]
机构
[1] Univ East London, Sch Architecture Comp & Engn, London E16 2RD, England
[2] Teesside Univ, Sch Comp Media & Arts, Middlesbrough TS1 3BX, England
来源
APPLIED SCIENCES-BASEL | 2018年 / 8卷 / 06期
关键词
cybersecurity; risk management; cyber-physical systems; cybersecurity attack scenario; supervisory control and data acquisition (SCADA) systems; cascading effect; MODEL; VULNERABILITY; ATTACK;
D O I
10.3390/app8060898
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
A cyber-physical system (CPS) is a combination of physical system components with cyber capabilities that have a very tight interconnectivity. CPS is a widely used technology in many applications, including electric power systems, communications, and transportation, and healthcare systems. These are critical national infrastructures. Cybersecurity attack is one of the major threats for a CPS because of many reasons, including complexity and interdependencies among various system components, integration of communication, computing, and control technology. Cybersecurity attacks may lead to various risks affecting the critical infrastructure business continuity, including degradation of production and performance, unavailability of critical services, and violation of the regulation. Managing cybersecurity risks is very important to protect CPS. However, risk management is challenging due to the inherent complex and evolving nature of the CPS system and recent attack trends. This paper presents an integrated cybersecurity risk management framework to assess and manage the risks in a proactive manner. Our work follows the existing risk management practice and standard and considers risks from the stakeholder model, cyber, and physical system components along with their dependencies. The approach enables identification of critical CPS assets and assesses the impact of vulnerabilities that affect the assets. It also presents a cybersecurity attack scenario that incorporates a cascading effect of threats and vulnerabilities to the assets. The attack model helps to determine the appropriate risk levels and their corresponding mitigation process. We present a power grid system to illustrate the applicability of our work. The result suggests that risk in a CPS of a critical infrastructure depends mainly on cyber-physical attack scenarios and the context of the organization. The involved risks in the studied context are both from the technical and nontechnical aspects of the CPS.
引用
收藏
页数:29
相关论文
共 50 条
  • [41] Cyber Security Based on Artificial Intelligence for Cyber-Physical Systems
    Sedjelmaci, Hichem
    Guenab, Fateh
    Senouci, Sidi-Mohammed
    Moustafa, Hassnaa
    Liu, Jiajia
    Han, Shuai
    IEEE NETWORK, 2020, 34 (03): : 6 - 7
  • [42] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan WANG
    Zhi-yun LIN
    Xiao LIANG
    Wen-yuan XU
    Qiang YANG
    Gang-feng YAN
    Frontiers of Information Technology & Electronic Engineering, 2016, 17 (05) : 465 - 478
  • [43] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan Wang
    Zhi-yun Lin
    Xiao Liang
    Wen-yuan Xu
    Qiang Yang
    Gang-feng Yan
    Frontiers of Information Technology & Electronic Engineering, 2016, 17 : 465 - 478
  • [44] Toward Enhancing Cyber-Physical System Security with System Unidentifiability
    Mao, Xiangyu
    He, Jianping
    Fang, Chongrong
    Peng, Yunfeng
    IFAC PAPERSONLINE, 2023, 56 (02): : 1692 - 1697
  • [45] Power System Security With Cyber-Physical Power System Operation
    Oyewole, Peju Adesina
    Jayaweera, Dilan
    IEEE ACCESS, 2020, 8 (08): : 179970 - 179982
  • [46] Cooling tower management in manufacturing companies: A cyber-physical system approach
    Schulze, Christine
    Thiede, Sebastian
    Thiede, Bastian
    Kurle, Denis
    Blume, Stefan
    Herrmann, Christoph
    JOURNAL OF CLEANER PRODUCTION, 2019, 211 : 428 - 441
  • [47] Security-Oriented Cyber-Physical Risk Assessment for Cyberattacks on Distribution System
    Zhang, Yuhang
    Ni, Ming
    APPLIED SCIENCES-BASEL, 2023, 13 (20):
  • [48] A Survey on Cyber-Physical Systems Security
    Yu, Zhenhua
    Gao, Hongxia
    Cong, Xuya
    Wu, Naiqi
    Song, Houbing Herbert
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (24) : 21670 - 21686
  • [49] Security Enumerations for Cyber-Physical Systems
    Schlette, Daniel
    Menges, Florian
    Baumer, Thomas
    Pernul, Guenther
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXIV, DBSEC 2020, 2020, 12122 : 64 - 76
  • [50] Cyber-Physical Security of a Chemical Plant
    Dunaka, Prakash Rao
    McMillin, Bruce
    2017 IEEE 18TH INTERNATIONAL SYMPOSIUM ON HIGH ASSURANCE SYSTEMS ENGINEERING (HASE 2017), 2017, : 33 - 40