Association Analysis-Based Cybersecurity Risk Assessment for Industrial Control Systems

被引:20
|
作者
Qin, Yuanqing [1 ]
Peng, Yuan [1 ]
Huang, Kaixing [1 ]
Zhou, Chunjie [1 ]
Tian, Yu-Chu [2 ]
机构
[1] Huazhong Univ Sci & Technol, Sch Artificial Intelligence & Automat, MOE Key Lab Image Proc & Intelligent Control, Wuhan 430074, Peoples R China
[2] Queensland Univ Technol, Sch Elect Engn & Comp Sci, Brisbane, Qld 4001, Australia
来源
IEEE SYSTEMS JOURNAL | 2021年 / 15卷 / 01期
基金
澳大利亚研究理事会; 美国国家科学基金会;
关键词
Risk management; Computer security; Adaptation models; Control systems; Correlation; Data mining; Association network (AN); data driven; industrial cybersecurity; risk assessment; INTERNET;
D O I
10.1109/JSYST.2020.3010977
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the adoption of various information and communication technologies and commercial off-the-shelf components, industrial control systems (ICSs) become highly vulnerable to cyberattacks. Dynamic cybersecurity risk assessment (CSRA) plays a vital role in the security protection of ICSs. To reduce the complexity of the modeling process in the dynamic CSRA, an association analysis-based CSRA approach is proposed in this article. It designs a three-layer association network (AN) to infer the probabilities of security incidents. The parameters of the AN are derived through mining the data of historical attack records. From a distance correlation analysis of the process data of the target system, an association matrix is obtained between the system state variables and the key security variables to quantify the cybersecurity risk of the system. A case study is conducted on a coupling tanks control system to demonstrate the effectiveness and timeliness of the proposed approach.
引用
收藏
页码:1423 / 1432
页数:10
相关论文
共 50 条
  • [21] Remote training in cybersecurity for industrial control systems
    Dominguez, Manuel
    Perez, Daniel
    Moran, Antonio
    Alonso, Serafin
    Prada, Miguel A.
    Fuertes, Juan J.
    IFAC PAPERSONLINE, 2022, 55 (17): : 320 - 325
  • [22] Ensuring the Cybersecurity of Plant Industrial Control Systems
    Weiss, Joe
    POWER, 2012, 156 (06) : 26 - +
  • [23] Cybersecurity Risk Assessment for Space Systems
    Vessels, Ly
    Heffner, Kenneth
    Johnson, Daniel
    2019 IEEE SPACE COMPUTING CONFERENCE (SCC), 2019, : 11 - 19
  • [24] A Systems Approach for Cybersecurity Risk Assessment
    Meshkat, Leila
    Miller, Robert L.
    2022 68TH ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2022), 2022,
  • [25] Radius Analysis-Based Control for Switched Positive Systems
    Fei, Zhongyang
    Chen, Weizhong
    Yang, Hao
    Sun, Xi-Ming
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2025, 70 (01) : 649 - 656
  • [26] Extended multilevel flow model-based dynamic risk assessment for cybersecurity protection in industrial production systems
    Zhu, Qianxiang
    Qin, Yuanqing
    Zhou, Chunjie
    Gao, Weiwei
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2018, 14 (06):
  • [27] Cybersecurity Risk Assessment of Industrial Control Systems Based on Order-α Divergence Measures Under an Interval-Valued Intuitionistic Fuzzy Environment
    Guo, Huijuan
    Ding, Lei
    Xu, Wenchao
    IEEE ACCESS, 2022, 10 : 43751 - 43765
  • [28] Ecological input-output analysis-based sustainability analysis of industrial systems
    Piluso, Cristina
    Huang, Yinlun
    Lou, Helen H.
    INDUSTRIAL & ENGINEERING CHEMISTRY RESEARCH, 2008, 47 (06) : 1955 - 1966
  • [29] Pinch analysis-based approach to industrial safety risk and environmental management
    Raymond R. Tan
    Mustafa Kamal Abdul Aziz
    Denny K. S. Ng
    Dominic C. Y. Foo
    Hon Loong Lam
    Clean Technologies and Environmental Policy, 2016, 18 : 2107 - 2117
  • [30] Pinch analysis-based approach to industrial safety risk and environmental management
    Tan, Raymond R.
    Aziz, Mustafa Kamal Abdul
    Ng, Denny K. S.
    Foo, Dominic C. Y.
    Lam, Hon Loong
    CLEAN TECHNOLOGIES AND ENVIRONMENTAL POLICY, 2016, 18 (07) : 2107 - 2117