Determining Risks from Advanced Multi-step Attacks to Critical Information Infrastructures

被引:0
|
作者
Ma, Zhendong [1 ]
Smith, Paul [1 ]
机构
[1] Austrian Inst Technol, Safety & Secur Dept, A-2444 Seibersdorf, Austria
关键词
Risk analysis; critical infrastructure; vulnerability;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) monitor and control industrial processes, and enable automation in industry facilities. Many of these facilities are regarded as Critical Infrastructures (CIs). Due to the increasing use of Commercial-Off-The-Shelf (COTS) IT products and connectivity offerings, CIs have become an attractive target for cyber-attacks. A successful attack could have significant consequences. An important step in securing Critical Information Infrastructures (CIIs) against cyber-attacks is risk analysis -understanding security risks, based on a systematic analysis of information on vulnerabilities, cyber threats, and the impacts related to the targeted system. Existing risk analysis approaches have various limitations, such as scalability and practicability problems. In contrast to previous work, we propose a practical and vulnerability-centric risk analysis approach for determining security risks associated with advanced, multi-step cyber-attacks. In order to examine multi-step attacks that exploit chains of vulnerabilities, we map vulnerabilities into preconditions and effects, and use rule-based reasoning for identifying advanced attacks and their path through a CII.
引用
收藏
页码:142 / 154
页数:13
相关论文
共 50 条
  • [41] DEEP RESIDUAL NETWORKS WITH COMMON LINEAR MULTI-STEP AND ADVANCED NUMERICAL SCHEMES
    Luo, Zhengbo
    Zhou, Weilian
    Kamata, Sei-ichiro
    Hu, Xuehui
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 3286 - 3290
  • [42] Application of the Advanced Multi-Step Brazing for fabrication of the high heat flux component
    Tokitani, M.
    Hamaji, Y.
    Hiraoka, Y.
    Masuzaki, S.
    Tamura, H.
    Noto, H.
    Tanaka, T.
    Muroga, T.
    Sagara, A.
    JOURNAL OF NUCLEAR MATERIALS, 2020, 538
  • [43] Multi-Step Prediction of TBM Tunneling Speed Based on Advanced Hybrid Model
    Liu, Defu
    Yang, Yaohong
    Yang, Shuwen
    Zhang, Zhixiao
    Sun, Xiaohu
    BUILDINGS, 2024, 14 (12)
  • [44] An Advanced Multistage Multi-Step Tidal Current Speed and Direction Prediction Model
    Safari, Nima
    Khorramdel, Benyamin
    Zare, Alireza
    Chung, Chi Yung
    2017 IEEE ELECTRICAL POWER AND ENERGY CONFERENCE (EPEC), 2017, : 591 - 596
  • [45] A Comparison of Re-Sampling Techniques for Detection of Multi-Step Attacks on Deep Learning Models
    Jamal, Muhammad Hassan
    Naz, Naila
    Khattak, Muazzam A. Khan
    Saeed, Faisal
    Altamimi, Saad Nasser
    Qasem, Sultan Noman
    IEEE ACCESS, 2023, 11 : 127446 - 127457
  • [46] NAPOLI FUTURA: Novel Approaches for Protecting Critical Infrastructures from Cyber Attacks
    Avallone, Stefano
    Carrozza, Gabriella
    Cinque, Marcello
    Della Corte, Raffaele
    Marotta, Antonio
    Pecchia, Antonio
    Savignano, Agostino
    2014 IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2014, : 33 - 36
  • [47] The Journey from Two-Step to Multi-Step Phosphorelay Signaling Systems
    Singh, Deepti
    Gupta, Priyanka
    Singla-Pareek, Sneh Lata
    Siddique, Kadambot H. M.
    Pareek, Ashwani
    CURRENT GENOMICS, 2021, 22 (01) : 59 - 74
  • [48] INFORM : Information eNtropy based multi-step reasoning FOR large language Models
    Zhou, Chuyue
    You, Wangjie
    Li, Juntao
    Ye, Jing
    Chen, Kehai
    Zhang, Min
    2023 CONFERENCE ON EMPIRICAL METHODS IN NATURAL LANGUAGE PROCESSING, EMNLP 2023, 2023, : 3565 - 3576
  • [49] Formalizing 'living guidelines' using LASSIE: A multi-step information extraction method
    Kaiser, Katharina
    Miksch, Silvia
    ARTIFICIAL INTELLIGENCE IN MEDICINE, PROCEEDINGS, 2007, 4594 : 401 - 410
  • [50] Optimal and self-tuning information fusion kalman multi-step predictor
    Sun, Shuli
    IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 2007, 43 (02) : 418 - 427