Association Analysis-Based Cybersecurity Risk Assessment for Industrial Control Systems

被引:20
|
作者
Qin, Yuanqing [1 ]
Peng, Yuan [1 ]
Huang, Kaixing [1 ]
Zhou, Chunjie [1 ]
Tian, Yu-Chu [2 ]
机构
[1] Huazhong Univ Sci & Technol, Sch Artificial Intelligence & Automat, MOE Key Lab Image Proc & Intelligent Control, Wuhan 430074, Peoples R China
[2] Queensland Univ Technol, Sch Elect Engn & Comp Sci, Brisbane, Qld 4001, Australia
来源
IEEE SYSTEMS JOURNAL | 2021年 / 15卷 / 01期
基金
澳大利亚研究理事会; 美国国家科学基金会;
关键词
Risk management; Computer security; Adaptation models; Control systems; Correlation; Data mining; Association network (AN); data driven; industrial cybersecurity; risk assessment; INTERNET;
D O I
10.1109/JSYST.2020.3010977
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the adoption of various information and communication technologies and commercial off-the-shelf components, industrial control systems (ICSs) become highly vulnerable to cyberattacks. Dynamic cybersecurity risk assessment (CSRA) plays a vital role in the security protection of ICSs. To reduce the complexity of the modeling process in the dynamic CSRA, an association analysis-based CSRA approach is proposed in this article. It designs a three-layer association network (AN) to infer the probabilities of security incidents. The parameters of the AN are derived through mining the data of historical attack records. From a distance correlation analysis of the process data of the target system, an association matrix is obtained between the system state variables and the key security variables to quantify the cybersecurity risk of the system. A case study is conducted on a coupling tanks control system to demonstrate the effectiveness and timeliness of the proposed approach.
引用
收藏
页码:1423 / 1432
页数:10
相关论文
共 50 条
  • [31] VNWTS: A Virtual Water Chlorination Process for Cybersecurity Analysis of Industrial Control Systems
    Durazno, Andres Robles
    Moradpoor, Naghmeh
    McWhinnie, James
    Porcel-Bustamante, Jorge
    2021 14TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS (SIN 2021), 2021,
  • [32] Filters based Approach with Temporal and Combinational Constraints for Cybersecurity of Industrial Control Systems
    Sicard, Franck
    Zamai, Eric
    Flaus, Jean-Marie
    IFAC PAPERSONLINE, 2018, 51 (24): : 96 - 103
  • [33] Cybersecurity Analysis of Industrial Control System Functionality
    Lou, Xinxin
    Waedt, Karl
    Schuermann, Tim
    Kauthold, Hauke
    Watson, Venesa
    Gupta, Deeksha
    2019 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER PHYSICAL SYSTEMS (ICPS 2019), 2019, : 73 - 80
  • [34] A Logical Risk Assessment Schema for Industrial Control Systems
    Wang Yufei
    Ye Qian
    PROCEEDINGS OF THE 2016 INTERNATIONAL FORUM ON MECHANICAL, CONTROL AND AUTOMATION (IFMCA 2016), 2017, 113 : 556 - 560
  • [35] Cybersecurity in industrial control systems: Issues, technologies, and challenges
    Asghar, Muhammad Rizwan
    Hu, Qinwen
    Zeadally, Sherali
    COMPUTER NETWORKS, 2019, 165
  • [36] MEASURING IMPACT OF CYBERSECURITY ON THE PERFORMANCE OF INDUSTRIAL CONTROL SYSTEMS
    Stouffer, Keith
    Candell, Rick
    MECHANICAL ENGINEERING, 2014, 136 (12) : 59 - 62
  • [37] Application Perspective on Cybersecurity Testbed for Industrial Control Systems
    Pospisil, Ondrej
    Blazek, Petr
    Kuchar, Karel
    Fujdiak, Radek
    Misurec, Jiri
    SENSORS, 2021, 21 (23)
  • [38] On Cybersecurity Risk Assessment in Nuclear Power Systems
    Baybulatov, A. A.
    Promyslov, V. G.
    IFAC PAPERSONLINE, 2022, 55 (09): : 233 - 237
  • [39] Towards Self-Defending Control Systems in Cybersecurity Analysis and Measures in Industrial Automation Systems
    Soufian, M.
    2017 IEEE 26TH INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2017, : 1887 - 1892
  • [40] Industrial Control System Cybersecurity Assessment Handling Delay Estimation
    Baybulatov, A. A.
    Promyslov, V. G.
    ADVANCES IN AUTOMATION III, 2022, 857 : 462 - 473