Association Analysis-Based Cybersecurity Risk Assessment for Industrial Control Systems

被引:20
|
作者
Qin, Yuanqing [1 ]
Peng, Yuan [1 ]
Huang, Kaixing [1 ]
Zhou, Chunjie [1 ]
Tian, Yu-Chu [2 ]
机构
[1] Huazhong Univ Sci & Technol, Sch Artificial Intelligence & Automat, MOE Key Lab Image Proc & Intelligent Control, Wuhan 430074, Peoples R China
[2] Queensland Univ Technol, Sch Elect Engn & Comp Sci, Brisbane, Qld 4001, Australia
来源
IEEE SYSTEMS JOURNAL | 2021年 / 15卷 / 01期
基金
澳大利亚研究理事会; 美国国家科学基金会;
关键词
Risk management; Computer security; Adaptation models; Control systems; Correlation; Data mining; Association network (AN); data driven; industrial cybersecurity; risk assessment; INTERNET;
D O I
10.1109/JSYST.2020.3010977
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the adoption of various information and communication technologies and commercial off-the-shelf components, industrial control systems (ICSs) become highly vulnerable to cyberattacks. Dynamic cybersecurity risk assessment (CSRA) plays a vital role in the security protection of ICSs. To reduce the complexity of the modeling process in the dynamic CSRA, an association analysis-based CSRA approach is proposed in this article. It designs a three-layer association network (AN) to infer the probabilities of security incidents. The parameters of the AN are derived through mining the data of historical attack records. From a distance correlation analysis of the process data of the target system, an association matrix is obtained between the system state variables and the key security variables to quantify the cybersecurity risk of the system. A case study is conducted on a coupling tanks control system to demonstrate the effectiveness and timeliness of the proposed approach.
引用
收藏
页码:1423 / 1432
页数:10
相关论文
共 50 条
  • [41] Implementation and Evaluation of Physical, Hybrid, and Virtual Testbeds for Cybersecurity Analysis of Industrial Control Systems
    Robles-Durazno, Andres
    Moradpoor, Naghmeh
    McWhinnie, James
    Russell, Gordon
    Porcel-Bustamante, Jorge
    SYMMETRY-BASEL, 2021, 13 (03):
  • [42] Consider the Consequences: A Risk Assessment Approach for Industrial Control Systems
    Kim, Aram
    Oh, Junhyoung
    Kwon, Kookheui
    Lee, Kyungho
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [43] Research on Risk Analysis-Based Access Control Model of Application System
    Gao, Zhimin
    Wang, Shengyuan
    PROCEEDINGS OF 2010 CROSS-STRAIT CONFERENCE ON INFORMATION SCIENCE AND TECHNOLOGY, 2010, : 750 - +
  • [44] Cybersecurity Self-assessment Tools: Evaluating the Importance for Securing Industrial Control Systems in Critical Infrastructures
    Lykou, Georgia
    Anagnostopoulou, Argiro
    Stergiopoulos, George
    Gritzalis, Dimitris
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2018), 2019, 11260 : 129 - 142
  • [45] A Dynamic Cybersecurity Protection Method based on Software-defined Networking for Industrial Control Systems
    Wang, Fang
    Qi, Weimin
    Qian, Tonghui
    2019 CHINESE AUTOMATION CONGRESS (CAC2019), 2019, : 1831 - 1834
  • [46] A Cybersecurity Risk Assessment Method and its Application for Instrumentation and Control Systems in Nuclear Power Plants
    Tian, Y.
    Li, J.
    Huang, X.
    IFAC PAPERSONLINE, 2022, 55 (09): : 238 - 243
  • [47] Automated Knowledge-Based Cybersecurity Risk Assessment of Cyber-Physical Systems
    Phillips, Stephen C.
    Taylor, Steve
    Boniface, Michael
    Modafferi, Stefano
    Surridge, Mike
    IEEE ACCESS, 2024, 12 : 82482 - 82505
  • [48] Curriculum Development for Teaching Cybersecurity of Industrial Control Systems & Critical Infrastructure
    Hamdan, Basil
    Al Nsour, Rawan
    2022 INTERMOUNTAIN ENGINEERING, TECHNOLOGY AND COMPUTING (IETC), 2022,
  • [49] Cybersecurity Fundamentals Are Not Just for Industrial Control Systems: Guidance and Direction Are Available
    Dunn, Donald G.
    Cosman, Eric
    IEEE INDUSTRY APPLICATIONS MAGAZINE, 2024, 30 (06) : 56 - 63
  • [50] Detecting Cybersecurity Threats for Industrial Control Systems Using Machine Learning
    Choi, Woohyun
    Pandey, Suman
    Kim, Jongwon
    IEEE ACCESS, 2024, 12 : 153550 - 153563