Assets Criticality Assessment of Industrial Control Systems: A Wind Farm Case Study

被引:0
|
作者
Gowdanakatte, Shwetha [1 ]
Abdelgawad, Mahmoud [2 ]
Ray, Indrakshi [2 ]
机构
[1] Colorado State Univ, Dept Syst Engn, Ft Collins, CO 80523 USA
[2] Colorado State Univ, Dept Comp Sci, Ft Collins, CO 80523 USA
关键词
Industrial Control Systems (ICS); assets criticality assessment; wind farm system; threat models; formal methods; Coloured Petri Nets (CPN); UML;
D O I
10.1109/QRS62785.2024.00042
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The increasing growth of threats to Industrial Control Systems (ICS) in the energy sector puts this critical infrastructure at high risk. Consequently, holistic approaches are needed to assess the criticality of ICS assets, identify relevant security threats, and develop mitigation techniques to make the energy critical infrastructure cyber-resilient. This paper presents a methodology for analyzing the criticality and resiliency of ICS assets by assessing the impact caused by attacks on such assets. Our approach consists of modeling the ICS architecture in a form that is suitable for analysis. We use Coloured Petri Nets (CPN) for formal representation and analysis - CPN is supported by automated tools for analysis and it has been used for verification of real-world systems. We use Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) for evaluating the threats in the ICS architecture. We use Microsoft Threat Modeling Tool (MTMT) for ICS threat modeling that classifies the threats into the categories defined in STRIDE. Based on the type of threat on each asset and its impact on the entire ICS, we rank the asset's criticality. The threat modeling framework assesses the criticality and resiliency of tangible and intangible assets, thus addressing the gap in the current research. Threat models are also converted into CPN models. The CPN models of the ICS architecture and the threat model are then composed. The methodology then verifies the resulting CPN. This verification explores the system states where the ICS cannot resist the attacks and identifies the ICS's critical assets that have been compromised. The methodology is applied to a wind farm system comprising many distributed subsystems connected via various networks. The result shows that the methodology is practical for the ICS verification and assets criticality assessment, providing recommended mitigations to construct a robust ICS.
引用
收藏
页码:352 / 363
页数:12
相关论文
共 50 条
  • [41] Techno-Economic Assessment of a Hybrid Offshore Wind-Wave Farm: Case Study in Norway
    Ronkko, Jaan
    Khosravi, Ali
    Syri, Sanna
    ENERGIES, 2023, 16 (11)
  • [42] A primary offshore wind farm site assessment using reanalysis data: a case study for Samothraki island
    Nezhad, M. Majidi
    Neshat, M.
    Groppi, D.
    Marzialetti, P.
    Heydari, A.
    Sylaios, G.
    Garcia, D. Astiaso
    RENEWABLE ENERGY, 2021, 172 : 667 - 679
  • [43] Study of wind farm control potential based on SCADA data
    Schreiber, J.
    Salbert, B.
    Bottasso, C. L.
    SCIENCE OF MAKING TORQUE FROM WIND (TORQUE 2018), 2018, 1037
  • [44] Study on Coordinated Voltage Control Strategy of DFIG Wind Farm
    Chen, Hui-fen
    Qiao, Ying
    Lu, Zong-xiang
    2012 IEEE POWER AND ENERGY SOCIETY GENERAL MEETING, 2012,
  • [45] Tanks criticality assessment by the dependability method. Case study
    Hammoum, Hocine
    Bouzelha, Karima
    Aider, Hacene Ait
    Hannachi, Naceur Eddine
    ENGINEERING FAILURE ANALYSIS, 2014, 41 : 10 - 22
  • [46] Assessment of Knowledge Domains of PNRA for their Maturity and Criticality: A Case Study
    Mallick, Shahid A.
    Ermine, Jean Louis
    Awan, Mohammad Ali
    Mehdi, M. Ammar
    IMCIC'11: THE 2ND INTERNATIONAL MULTI-CONFERENCE ON COMPLEXITY, INFORMATICS AND CYBERNETICS, VOL II, 2011, : 236 - 241
  • [47] A Study on Quantitative Risk Assessment Methods in Security Design for Industrial Control Systems
    Kawanishi, Yasuyuki
    Nishihara, Hideaki
    Souma, Daisuke
    Yoshida, Hirotaka
    Hata, Yoichi
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 62 - 69
  • [48] Integration of an energy storage system in a wind farm, case study
    Araya Rodriguez, Jorge David
    Rojas, Juan J.
    Richmond-Navarro, Gustavo
    TECNOLOGIA EN MARCHA, 2022, 35 : 58 - 66
  • [49] Moroccan wind farm potential feasibility. Case study
    Nouri, Abdellatif
    Babram, Mohamed Ait
    Elwarraki, Elmostafa
    Enzili, Mustapha
    ENERGY CONVERSION AND MANAGEMENT, 2016, 122 : 39 - 51
  • [50] Prioritizing of wind farm locations for hydrogen production: A case study
    Rezaei-Shouroki, Mostafa
    Mostafaeipour, Ali
    Qolipour, Mojtaba
    INTERNATIONAL JOURNAL OF HYDROGEN ENERGY, 2017, 42 (15) : 9500 - 9510