An Integrated Cyber Security Risk Management Approach for a Cyber-Physical System

被引:75
|
作者
Kure, Halima Ibrahim [1 ]
Islam, Shareeful [1 ]
Razzaque, Mohammad Abdur [2 ]
机构
[1] Univ East London, Sch Architecture Comp & Engn, London E16 2RD, England
[2] Teesside Univ, Sch Comp Media & Arts, Middlesbrough TS1 3BX, England
来源
APPLIED SCIENCES-BASEL | 2018年 / 8卷 / 06期
关键词
cybersecurity; risk management; cyber-physical systems; cybersecurity attack scenario; supervisory control and data acquisition (SCADA) systems; cascading effect; MODEL; VULNERABILITY; ATTACK;
D O I
10.3390/app8060898
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
A cyber-physical system (CPS) is a combination of physical system components with cyber capabilities that have a very tight interconnectivity. CPS is a widely used technology in many applications, including electric power systems, communications, and transportation, and healthcare systems. These are critical national infrastructures. Cybersecurity attack is one of the major threats for a CPS because of many reasons, including complexity and interdependencies among various system components, integration of communication, computing, and control technology. Cybersecurity attacks may lead to various risks affecting the critical infrastructure business continuity, including degradation of production and performance, unavailability of critical services, and violation of the regulation. Managing cybersecurity risks is very important to protect CPS. However, risk management is challenging due to the inherent complex and evolving nature of the CPS system and recent attack trends. This paper presents an integrated cybersecurity risk management framework to assess and manage the risks in a proactive manner. Our work follows the existing risk management practice and standard and considers risks from the stakeholder model, cyber, and physical system components along with their dependencies. The approach enables identification of critical CPS assets and assesses the impact of vulnerabilities that affect the assets. It also presents a cybersecurity attack scenario that incorporates a cascading effect of threats and vulnerabilities to the assets. The attack model helps to determine the appropriate risk levels and their corresponding mitigation process. We present a power grid system to illustrate the applicability of our work. The result suggests that risk in a CPS of a critical infrastructure depends mainly on cyber-physical attack scenarios and the context of the organization. The involved risks in the studied context are both from the technical and nontechnical aspects of the CPS.
引用
收藏
页数:29
相关论文
共 50 条
  • [21] Cyber-Physical Systems - Security
    Zseby, T.
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2018, 135 (03): : 249 - 249
  • [22] Cyber-Physical Security in a Substation
    Hong, Junho
    Stefanov, Alexandru
    Liu, Chen-Ching
    Govindarasu, Manimaran
    2012 IEEE POWER AND ENERGY SOCIETY GENERAL MEETING, 2012,
  • [23] AN INTEGRATED CYBER-PHYSICAL SYSTEM FOR CLOUD MANUFACTURING
    Wang, Lihui
    Gao, Robert
    Ragai, Ihab
    PROCEEDINGS OF THE ASME 9TH INTERNATIONAL MANUFACTURING SCIENCE AND ENGINEERING CONFERENCE, 2014, VOL 1, 2014,
  • [24] Coordinated cyber-physical attacks of cyber-physical power system
    Yang Y.
    Lan S.
    Qin Z.
    Liu H.
    Dianli Zidonghua Shebei/Electric Power Automation Equipment, 2020, 40 (02): : 97 - 102
  • [25] Understanding the impact of cyber-physical correlation on security analysis of Cyber-Physical Systems
    Jiang, Luanjuan
    Chen, Xin
    2021 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS DASC/PICOM/CBDCOM/CYBERSCITECH 2021, 2021, : 529 - 534
  • [26] A Cyber-Security Methodology for a Cyber-Physical Industrial Control System Testbed
    Noorizadeh, Mohammad
    Shakerpour, Mohammad
    Meskin, Nader
    Unal, Devrim
    Khorasani, Khashayar
    IEEE ACCESS, 2021, 9 : 16239 - 16253
  • [27] Cyber-physical system
    Garibaldo, Francesco
    Rebecchi, Emilio
    AI & SOCIETY, 2018, 33 (03) : 299 - 311
  • [28] Cyber LOPA: An Integrated Approach for the Design of Dependable and Secure Cyber-Physical Systems
    Tantawy, Ashraf
    Abdelwahed, Sherif
    Erradi, Abdelkarim
    IEEE TRANSACTIONS ON RELIABILITY, 2022, 71 (02) : 1075 - 1091
  • [29] Safety and security risk assessment in cyber-physical systems
    Lyu, Xiaorong
    Ding, Yulong
    Yang, Shuang-Hua
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2019, 4 (03) : 221 - 232
  • [30] Cyber-Physical System Security for the Electric Power Grid
    Sridhar, Siddharth
    Hahn, Adam
    Govindarasu, Manimaran
    PROCEEDINGS OF THE IEEE, 2012, 100 (01) : 210 - 224