Vulnerability Identification and Assessment for Critical Infrastructures in the Energy Sector

被引:4
|
作者
Nikolaou, Nikolaos [1 ]
Papadakis, Andreas [1 ,2 ]
Psychogyios, Konstantinos [1 ]
Zahariadis, Theodore [1 ,3 ]
机构
[1] Synelixis Solut SA, Chalkida GR-34100, Greece
[2] Sch Pedag & Technol Educ, Dept Elect & Elect Engn Educators, Athens GR-15122, Greece
[3] Natl & Kapodistrian Univ Athens, Gen Dept, Athens GR-15772, Greece
基金
欧盟地平线“2020”;
关键词
vulnerability identification; vulnerability assessment; CVSS assessment; critical infrastructure; STIX format; CTI; correlation analysis;
D O I
10.3390/electronics12143185
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Vulnerability identification and assessment is a key process in risk management. While enumerations of vulnerabilities are available, it is challenging to identify vulnerability sets focused on the profiles and roles of specific organizations. To this end, we have employed systematized knowledge and relevant standards (including National Electric Sector Cybersecurity Organization Resource (NESCOR), ISO/IEC 27005:2018 and National Vulnerability Database (NVD)) to identify a set of 250 vulnerabilities for operators of energy-related critical infrastructures. We have elaborated a "double-mapping" scheme to associate (arbitrarily) categorized assets, with the pool of identified Physical, Cyber and Human/Organizational vulnerabilities. We have designed and implemented an extensible vulnerability identification and assessment framework, allowing historized assessments, based on the CVSS (Common Vulnerability Scoring System) scoring mechanism. This framework has been extended to allow modelling of the vulnerabilities and assessments using the Structured Threat Information eXpression (STIX) JSON format, as Cyber Threat Intelligence (CTI) information, to facilitate information sharing between Electrical Power and Energy Systems (EPES) and to promote collaboration and interoperability scenarios. Vulnerability assessments from the initial analysis of the project in the context of Research and Technology Development (RTD) projects have been statistically processed, offering insights in terms of the assessment's importance and distribution. The assessments have also been transformed into a dynamic dataset processed to identify and quantify correlation and start the discussion on the interpretation of the way assessments are performed.
引用
收藏
页数:18
相关论文
共 50 条
  • [41] Hydrometeorological resilience assessment of interconnected critical infrastructures
    Passos, Marlon Vieira
    Barquet, Karina
    Kan, Jung-Ching
    Destouni, Georgia
    Kalantari, Zahra
    SUSTAINABLE AND RESILIENT INFRASTRUCTURE, 2025,
  • [42] Modelling Security of Critical Infrastructures: A Survivability Assessment
    Rodriguez, Ricardo J.
    Merseguer, Jose
    Bernardi, Simona
    COMPUTER JOURNAL, 2015, 58 (10): : 2313 - 2327
  • [43] Vulnerability Assessment of Interdependent Infrastructures Based on a Cascading Failure Model
    Wang, Ying
    Guo, Peng
    Wu, Yanfang
    Chen, Yang
    Zio, Enrico
    2022 6TH INTERNATIONAL CONFERENCE ON SYSTEM RELIABILITY AND SAFETY, ICSRS, 2022, : 40 - 44
  • [44] Vulnerability Distribution Model of Critical Infrastructures Based on Topological System Simulation
    Yao, Xiaobo
    Han, Chuanfeng
    Chen, Qian
    Meng, Lingpeng
    ADVANCED COMPUTING STRATEGIES FOR ENGINEERING, PT I, 2018, 10863 : 498 - 515
  • [45] Simulation platform for cyber-security and vulnerability analysis of critical infrastructures
    Ficco, Massimo
    Choras, Michal
    Kozik, Rafal
    JOURNAL OF COMPUTATIONAL SCIENCE, 2017, 22 : 179 - 186
  • [46] Vulnerability Analysis of Interdependent Critical Infrastructures upon a Cyber-attack
    Abdelgawad, Ahmed Abdeltawab
    Farstad, Tor-Edin
    Gonzalez, Jose J.
    PROCEEDINGS OF THE 52ND ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2019, : 629 - 638
  • [47] Transmission System Vulnerability Assessment based on Practical Identification of Critical Relays and Contingencies
    Bai, Hua
    Ajjarapu, Venkataramana
    2008 IEEE POWER & ENERGY SOCIETY GENERAL MEETING, VOLS 1-11, 2008, : 4244 - 4251
  • [48] Energy and conflict: Security outsourcing in the protection of critical energy infrastructures
    Zabyelina, Yuliya
    Kustova, Irina
    COOPERATION AND CONFLICT, 2015, 50 (04) : 531 - 549
  • [49] Research of critical energy infrastructures taking into account energy security
    Pyatkova, Natalia
    Beresneva, Natalia
    Edelev, Alexey
    METHODOLOGICAL PROBLEMS IN RELIABILITY STUDY OF LARGE ENERGY SYSTEMS (RSES 2017), 2017, 25
  • [50] Energy sector vulnerability to climate change: A review
    Schaeffer, Roberto
    Szklo, Alexandre Salem
    Pereira de Lucena, Andre Frossard
    Moreira Cesar Borba, Bruno Soares
    Pupo Nogueira, Larissa Pinheiro
    Fleming, Fernanda Pereira
    Troccoli, Alberto
    Harrison, Mike
    Boulahya, Mohammed Sadeck
    ENERGY, 2012, 38 (01) : 1 - 12