A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection

被引:2
|
作者
Henriques, Joao [1 ,2 ]
Caldeira, Filipe [2 ,3 ]
Cruz, Tiago [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Ctr Informat & Syst, Dept Informat Engn, P-3030290 Coimbra, Portugal
[2] Polytech Inst Viseu, CISeD Res Ctr Digital Serv, P-3504510 Viseu, Portugal
[3] Polytech Inst Viseu, Informat Dept, P-3504510 Viseu, Portugal
关键词
Critical infrastructure protection; industrial automation and control systems; cybersecurity; forensics; compliance auditing; DIGITAL FORENSICS; ANOMALY DETECTION; DETECTION FRAMEWORK; INTRUSION DETECTION; CLOUD; SECURITY; INFORMATION; PROVENANCE; CHALLENGES; TAXONOMY;
D O I
10.1109/ACCESS.2023.3348552
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The broadening dependency and reliance that modern societies have on essential services provided by Critical Infrastructures is increasing the relevance of their trustworthiness. However, Critical Infrastructures are attractive targets for cyberattacks, due to the potential for considerable impact, not just at the economic level but also in terms of physical damage and even loss of human life. Complementing traditional security mechanisms, forensics and compliance audit processes play an important role in ensuring Critical Infrastructure trustworthiness. Compliance auditing contributes to checking if security measures are in place and compliant with standards and internal policies. Forensics assist the investigation of past security incidents. Since these two areas significantly overlap, in terms of data sources, tools and techniques, they can be merged into unified Forensics and Compliance Auditing (FCA) frameworks. In this paper, we survey the latest developments, methodologies, challenges, and solutions addressing forensics and compliance auditing in the scope of Critical Infrastructure Protection. This survey focuses on relevant contributions, capable of tackling the requirements imposed by massively distributed and complex Industrial Automation and Control Systems, in terms of handling large volumes of heterogeneous data (that can be noisy, ambiguous, and redundant) for analytic purposes, with adequate performance and reliability. The achieved results produced a taxonomy in the field of FCA whose key categories denote the relevant topics in the literature. Also, the collected knowledge resulted in the establishment of a reference FCA architecture, proposed as a generic template for a converged platform. These results are intended to guide future research on forensics and compliance auditing for Critical Infrastructure Protection.
引用
收藏
页码:2409 / 2444
页数:36
相关论文
共 50 条
  • [1] A forensics and compliance auditing framework for critical infrastructure protection
    Henriques, Joao
    Caldeira, Filipe
    Cruz, Tiago
    Simoes, Paulo
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2023, 42
  • [2] Achieving Critical Infrastructure Protection through the Interaction of Computer Security and Network Forensics
    Hunt, Ray
    Slay, Jill
    PST 2010: 2010 EIGHTH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, 2010, : 23 - 30
  • [3] Critical infrastructure protection
    George, Richard
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2008, 1 : 4 - 5
  • [4] Critical infrastructure protection
    Goetz, Eric
    Shenoi, Sujeet
    IFIP Advances in Information and Communication Technology, 2008, 253
  • [5] Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack
    Madi, Taous
    Majumdar, Suryadipta
    Wang, Yushun
    Jarraya, Yosr
    Pourzandi, Makan
    Wang, Lingyu
    CODASPY'16: PROCEEDINGS OF THE SIXTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, 2016, : 195 - 206
  • [6] Image and Video Forensics: A Critical Survey
    Harpreet Kaur
    Neeru Jindal
    Wireless Personal Communications, 2020, 112 : 1281 - 1302
  • [7] Image and Video Forensics: A Critical Survey
    Kaur, Harpreet
    Jindal, Neeru
    WIRELESS PERSONAL COMMUNICATIONS, 2020, 112 (02) : 1281 - 1302
  • [8] Leadership for Critical Infrastructure Protection
    Tvaronaviciene, Manuela
    SUSTAINABLE LEADERSHIP FOR ENTREPRENEURS AND ACADEMICS, ESAL2018, 2019, : 389 - 397
  • [9] Critical Infrastructure Protection Editorial
    Shenoi, Sujeet
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2018, 20 : 1 - 2
  • [10] Committed to Protection? Partnerships in Critical Infrastructure Protection
    Koski, Chris
    JOURNAL OF HOMELAND SECURITY AND EMERGENCY MANAGEMENT, 2011, 8 (01):