Evaluation of industrial network robustness against targeted attacks

被引:4
作者
Alrumaih, Thuraya N. I. [1 ]
Alenazi, Mohammed J. F. [1 ]
机构
[1] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Engn, Riyadh, Saudi Arabia
关键词
cybersecurity; graph theory; industrial control systems; industrial network; resilience; robustness; RESILIENCE;
D O I
10.1002/cpe.7855
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Developing a long-lasting, secure Industry 4.0 system presents a significant challenge for businesses and other interested parties. Industrial control systems (ICSs) are particularly vulnerable to cybercrime because of the operating systems' excessive availability and high robustness requirements. This research investigates five graph-theory-based measures to evaluate the robustness of industrial network topologies against three centrality-based attacks and one random attack. Experiments are conducted to examine the three levels of the ICS network topology, from the field devices to the controllers and the enterprise devices. The results are twofold. On the one hand, the closeness-based attack is the most harmful since it has the highest destructive potential and needs to attack only half of the total nodes in the network to reach the lowest robustness level. The betweenness-based attack follows closely in terms of destruction, whereas the degree-based attack is less destructive but rapidly degrades the robustness of the network. On the other hand, the flow robustness measure provides the best performance in the presence of any of the studied attacks, showing strong perception of robustness reduction when only one percent of the total nodes in the network are attacked. For this reason, the flow robustness measure is suitable to identify and locate the targeted attacks at their early stages, preventing them from becoming more catastrophic. Finally, the results suggest that the industrial network security system should combine at least two measures to ensure robustness against the most destructive attacks and their early-stage detection. The research also confirmed the results by implementing attacks and measures on a real gas transmission network.
引用
收藏
页数:24
相关论文
共 50 条
[1]  
Alenazi MJ., 2017, INT C COMPL NETW APP, P633
[2]   NFV Provisioning in Large-Scale Distributed Networks With Minimum Delay [J].
Alenazi, Mohammed J. F. ;
Almutairi, Abdulrahman ;
Almowuena, Saleh ;
Wadood, Abdul ;
Cetinkaya, Egemen K. .
IEEE ACCESS, 2020, 8 :151753-151763
[3]   Cost-efficient algebraic connectivity optimisation of backbone networks [J].
Alenazi, Mohammed J. F. ;
Cetinkaya, Egemen K. ;
Sterbenz, James P. G. .
OPTICAL SWITCHING AND NETWORKING, 2014, 14 :107-116
[4]   BL-Hybrid: A graph-theoretic approach to improving software-defined networking-based data center network performance [J].
AlShammari, Walaa M. ;
Alenazi, Mohammed J. F. .
TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (01)
[5]  
AlShammari WM, 2020, INT J ADV COMPUT SC, V11, P666
[6]   Metrics and quantitative framework for assessing microgrid resilience against windstorms [J].
Amirioun, M. H. ;
Aminifar, F. ;
Lesani, H. ;
Shahidehpour, M. .
INTERNATIONAL JOURNAL OF ELECTRICAL POWER & ENERGY SYSTEMS, 2019, 104 :716-723
[7]  
Analytica O., 2015, EMERALD EXPERT BRIEF
[8]   A New Metric for Assessing Resilience of Water Distribution Networks [J].
Assad, Ahmed ;
Moselhi, Osama ;
Zayed, Tarek .
WATER, 2019, 11 (08)
[9]   Measuring cyber-physical security in industrial control systems via minimum-effort attack strategies [J].
Barrere, Martin ;
Hankin, Chris ;
Nicolaou, Nicolas ;
Eliades, Demetrios G. ;
Parisini, Thomas .
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 52
[10]   Resilient and Cybersecure Distributed Control of Inverter-Based Islanded Microgrids [J].
Bidram, Ali ;
Poudel, Binod ;
Damodaran, Lakshmisree ;
Fierro, Rafael ;
Guerrero, Josep M. .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2020, 16 (06) :3881-3894