Vulnerability Identification and Assessment for Critical Infrastructures in the Energy Sector

被引:4
|
作者
Nikolaou, Nikolaos [1 ]
Papadakis, Andreas [1 ,2 ]
Psychogyios, Konstantinos [1 ]
Zahariadis, Theodore [1 ,3 ]
机构
[1] Synelixis Solut SA, Chalkida GR-34100, Greece
[2] Sch Pedag & Technol Educ, Dept Elect & Elect Engn Educators, Athens GR-15122, Greece
[3] Natl & Kapodistrian Univ Athens, Gen Dept, Athens GR-15772, Greece
基金
欧盟地平线“2020”;
关键词
vulnerability identification; vulnerability assessment; CVSS assessment; critical infrastructure; STIX format; CTI; correlation analysis;
D O I
10.3390/electronics12143185
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Vulnerability identification and assessment is a key process in risk management. While enumerations of vulnerabilities are available, it is challenging to identify vulnerability sets focused on the profiles and roles of specific organizations. To this end, we have employed systematized knowledge and relevant standards (including National Electric Sector Cybersecurity Organization Resource (NESCOR), ISO/IEC 27005:2018 and National Vulnerability Database (NVD)) to identify a set of 250 vulnerabilities for operators of energy-related critical infrastructures. We have elaborated a "double-mapping" scheme to associate (arbitrarily) categorized assets, with the pool of identified Physical, Cyber and Human/Organizational vulnerabilities. We have designed and implemented an extensible vulnerability identification and assessment framework, allowing historized assessments, based on the CVSS (Common Vulnerability Scoring System) scoring mechanism. This framework has been extended to allow modelling of the vulnerabilities and assessments using the Structured Threat Information eXpression (STIX) JSON format, as Cyber Threat Intelligence (CTI) information, to facilitate information sharing between Electrical Power and Energy Systems (EPES) and to promote collaboration and interoperability scenarios. Vulnerability assessments from the initial analysis of the project in the context of Research and Technology Development (RTD) projects have been statistically processed, offering insights in terms of the assessment's importance and distribution. The assessments have also been transformed into a dynamic dataset processed to identify and quantify correlation and start the discussion on the interpretation of the way assessments are performed.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Identification of Critical Objects in Reliance on Cyber Threats in the Energy Sector
    Massel, Aleksei
    Gaskova, Daria
    ACTA POLYTECHNICA HUNGARICA, 2020, 17 (08) : 61 - 73
  • [22] Assessment of human factor in critical infrastructures
    Poluyan, L., V
    Malukova, M. G.
    IV INTERNATIONAL CONFERENCE ON SAFETY PROBLEMS OF CIVIL ENGINEERING CRITICAL INFRASTRUCTURES, 2019, 481
  • [23] IEMI Resilience Assessment of Critical Infrastructures
    Pusch, Thorsten
    Lanzrath, Marian
    Suhrke, Michael
    2019 INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY (EMC EUROPE 2019), 2019, : 1132 - 1137
  • [24] Common criteria for the assessment of critical infrastructures
    Alexander Fekete
    International Journal of Disaster Risk Science, 2011, 2 : 15 - 24
  • [25] Common Criteria for the Assessment of Critical Infrastructures
    Fekete, Alexander
    INTERNATIONAL JOURNAL OF DISASTER RISK SCIENCE, 2011, 2 (01) : 15 - 24
  • [26] CYBERSECURITY ASSESSMENT AND CERTIFICATION OF CRITICAL INFRASTRUCTURES
    Bogdan, Ioana Corina
    Simion, Emil
    UPB Scientific Bulletin, Series C: Electrical Engineering and Computer Science, 2024, 86 (04): : 151 - 166
  • [27] Proactive risk assessment of critical infrastructures
    Uusitalo, T.
    Koivisto, R.
    Schmitz, W.
    SAFETY, RELIABILITY AND RISK ANALYSIS: THEORY, METHODS AND APPLICATIONS, VOLS 1-4, 2009, : 2511 - 2517
  • [28] A Security Assessment Methodology for Critical Infrastructures
    Caselli, Marco
    Kargl, Frank
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2014), 2016, 8985 : 332 - 343
  • [29] CYBERSECURITY ASSESSMENT AND CERTIFICATION OF CRITICAL INFRASTRUCTURES
    Bogdan, Ioana Corina
    Simion, Emil
    UNIVERSITY POLITEHNICA OF BUCHAREST SCIENTIFIC BULLETIN SERIES C-ELECTRICAL ENGINEERING AND COMPUTER SCIENCE, 2024, 86 (04): : 151 - 166
  • [30] Interdependencies Between Industrial Infrastructures: Territorial Vulnerability Assessment
    Rey, Benjamin
    Tixier, Jerome
    Bony-Dandrieux, Aurelia
    Dusserre, Gilles
    Munier, Laurent
    Lapebie, Emmanuel
    LP2013 - 14TH SYMPOSIUM ON LOSS PREVENTION AND SAFETY PROMOTION IN THE PROCESS INDUSTRIES, VOLS I AND II, 2013, 31 : 61 - 66