Guidelines for Cyber Risk Management in Autonomous Shipping

被引:1
|
作者
Li, Meixuan [1 ]
Yousaf, Awais [1 ]
Goh, Mark [1 ]
Zhou, Jianying [1 ]
Chattopadhyay, Sudipta [1 ]
机构
[1] Singapore Univ Technol & Design, iTrust, Singapore, Singapore
基金
新加坡国家研究基金会;
关键词
Autonomous ship; Ship systems; Maritime operations; Cyber risk; Cybersecurity; Risk analysis;
D O I
10.1007/978-3-031-61489-7_9
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The emergence of autonomous ships represents a significant advancement in maritime technology, promising enhanced efficiency, reduced operating costs and reducing or even completely removing crews from hazardous environments. However, the progress is accompanied by a burgeoning concern on the cyber security of these autonomous ships due to their exposure to the "connected world". The four key systems investigated in this study are: 1) Shore Control Centre (SCC); 2) Communication System; 3) Autonomous Ship Controller (ASC), and 4) Autonomous Navigation System (ANS). The paper highlights specific operational technology (OT) risks associated with MASS (Maritime Autonomous Surface Ship). For completeness, the study also drills down to cyber risks and impacts associated with sub-systems of these major OT systems. A comprehensive cyber risk assessment methodology employing the MITRE framework is provided to evaluate the severity of risks. Recommended mitigations include defence-in-depth cybersecurity protections for all systems, security-by-design approaches, personnel training and redundancy in certain critical systems (The full version of guidelines is accessible through this link for further reference). Taking into account all aspects, this paper functions as a case study examining cyber risks of the OT system of autonomous ships.
引用
收藏
页码:143 / 161
页数:19
相关论文
共 50 条
  • [21] Cyber-risk management not feasible
    Parker, DB
    COMMUNICATIONS OF THE ACM, 2003, 46 (05) : 12 - 13
  • [22] Connected and autonomous vehicles: A cyber-risk classification framework
    Sheehan, Barry
    Murphy, Finbarr
    Mullins, Martin
    Ryan, Cian
    TRANSPORTATION RESEARCH PART A-POLICY AND PRACTICE, 2019, 124 : 523 - 536
  • [23] Risk guidelines as a risk management tool
    Hendershot, DC
    PROCESS SAFETY PROGRESS, 1996, 15 (04) : 213 - 218
  • [24] Risk guidelines as a risk management tool
    Rohm and Haas Co, Bristol, United States
    Process Saf Prog, 4 (213-218):
  • [25] Heuristic Evaluation of Vulnerability Risk Management Leaders' Presentations of Cyber Threat and Cyber Risk
    Nichols, Chris
    Stoker, Geoff
    Clark, Ulku
    HCI FOR CYBERSECURITY, PRIVACY AND TRUST (HCI-CPT 2021), 2021, 12788 : 212 - 225
  • [26] Cyber risk definition and classification for financial risk management
    Curti, Filippo
    Gerlach, Jeffrey
    Kazinnik, Sophia
    Lee, Michael
    Mihov, Atanas
    JOURNAL OF OPERATIONAL RISK, 2023, 18 (02): : 37 - 58
  • [27] Survey and Guidelines about Learning Cyber Security Risk Assessment
    Ponsard, Christophe
    Massonet, Philippe
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2021, : 536 - 543
  • [28] Risk Management Principles and Guidelines
    Luko, Stephen N.
    QUALITY ENGINEERING, 2013, 25 (04) : 451 - 454
  • [29] Guidelines and risk factor management
    Primatesta, P
    HEART, 2005, 91 (04) : 417 - 418
  • [30] Cyber Threat Intelligence in Risk Management A Survey of the Impact of Cyber Threat Intelligence on Saudi Higher Education Risk Management
    Aljuhami, Amira M.
    Bamasoud, Doaa M.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (10) : 156 - 164