Vulnerability Identification and Assessment for Critical Infrastructures in the Energy Sector

被引:4
|
作者
Nikolaou, Nikolaos [1 ]
Papadakis, Andreas [1 ,2 ]
Psychogyios, Konstantinos [1 ]
Zahariadis, Theodore [1 ,3 ]
机构
[1] Synelixis Solut SA, Chalkida GR-34100, Greece
[2] Sch Pedag & Technol Educ, Dept Elect & Elect Engn Educators, Athens GR-15122, Greece
[3] Natl & Kapodistrian Univ Athens, Gen Dept, Athens GR-15772, Greece
基金
欧盟地平线“2020”;
关键词
vulnerability identification; vulnerability assessment; CVSS assessment; critical infrastructure; STIX format; CTI; correlation analysis;
D O I
10.3390/electronics12143185
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Vulnerability identification and assessment is a key process in risk management. While enumerations of vulnerabilities are available, it is challenging to identify vulnerability sets focused on the profiles and roles of specific organizations. To this end, we have employed systematized knowledge and relevant standards (including National Electric Sector Cybersecurity Organization Resource (NESCOR), ISO/IEC 27005:2018 and National Vulnerability Database (NVD)) to identify a set of 250 vulnerabilities for operators of energy-related critical infrastructures. We have elaborated a "double-mapping" scheme to associate (arbitrarily) categorized assets, with the pool of identified Physical, Cyber and Human/Organizational vulnerabilities. We have designed and implemented an extensible vulnerability identification and assessment framework, allowing historized assessments, based on the CVSS (Common Vulnerability Scoring System) scoring mechanism. This framework has been extended to allow modelling of the vulnerabilities and assessments using the Structured Threat Information eXpression (STIX) JSON format, as Cyber Threat Intelligence (CTI) information, to facilitate information sharing between Electrical Power and Energy Systems (EPES) and to promote collaboration and interoperability scenarios. Vulnerability assessments from the initial analysis of the project in the context of Research and Technology Development (RTD) projects have been statistically processed, offering insights in terms of the assessment's importance and distribution. The assessments have also been transformed into a dynamic dataset processed to identify and quantify correlation and start the discussion on the interpretation of the way assessments are performed.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] Seismic Vulnerability of Structures and Infrastructures: Strategies for Assessment and Mitigation
    Castaldo, Paolo
    Cavaleri, Liborio
    Di Trapani, Fabio
    INGEGNERIA SISMICA, 2017, 34 (03): : 3 - 3
  • [32] Seismic vulnerability of structures and infrastructures: Strategies for assessment and mitigation
    2017, Patron Editore S.r.l., via Badini 12 - Quarto Inferiore, Granarolo dell'Emilia - Bologna, 40057, Italy (34): : 3 - 4
  • [33] Towards a Unified Definition of Cyber and Physical Vulnerability in Critical Infrastructures
    Marrone, Stefano
    2017 2ND IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW), 2017, : 167 - 173
  • [34] A Framework for Analyzing Vulnerability of Critical Infrastructures Under Localized Attacks
    Yan, KeSheng
    Rong, Lili
    Lu, Tao
    Ni, ZiJian
    KNOWLEDGE AND SYSTEMS SCIENCES, (KSS 2016), 2016, 660 : 94 - 103
  • [35] An All-Hazard approach for the vulnerability analysis of critical infrastructures
    Zio, E.
    Piccinelli, R.
    Sansavini, G.
    ADVANCES IN SAFETY, RELIABILITY AND RISK MANAGEMENT, 2012, : 2451 - 2458
  • [36] Risk management goals and identification of critical infrastructures
    Fekete, Alexander
    Lauwe, Peter
    Geier, Wolfram
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2012, 8 (04) : 336 - 353
  • [37] Critical Infrastructures: IT Security and Threats from Private Sector Ownership
    Warfield, Douglas
    INFORMATION SECURITY JOURNAL, 2012, 21 (03): : 127 - 136
  • [38] Vulnerability assessment framework for interdependent critical infrastructures: case-study for Great Britain's rail network
    Pant, Raghav
    Hall, Jim W.
    Blainey, Simon P.
    EUROPEAN JOURNAL OF TRANSPORT AND INFRASTRUCTURE RESEARCH, 2016, 16 (01): : 174 - 194
  • [39] Decision support for the management of aging nuclear critical infrastructures: vulnerability assessment and multi-criteria decision analysis
    Levy, Jason K.
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2005, 1 (04) : 357 - 366
  • [40] Assessment process of the resilience potential of critical infrastructures
    Hemond, Yannick
    Robert, Benoit
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2014, 10 (3-4) : 200 - 217