Bridging the Cyber-Physical Divide: A Novel Approach for Quantifying and Visualising the Cyber Risk of Physical Assets

被引:2
作者
Keenan, Cael [1 ]
Maier, Holger R. [1 ]
van Delden, Hedwig [1 ,2 ]
Zecchin, Aaron C. [1 ]
机构
[1] Univ Adelaide, Sch Architecture & Civil Engn, Adelaide, SA 5005, Australia
[2] Res Inst Knowledge Syst RIKS, POB 463, NL-6200 AL Maastricht, Netherlands
关键词
cyber-physical systems; risk assessment; cyber security; water distribution systems; risk modelling; cyber-physical attack;
D O I
10.3390/w16050637
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Critical infrastructures and their physical assets are under increasing threat of cyber-attacks as technological integration creates cyber-physical systems (CPSs). This has led to an urgent need to better understand which physical assets in these systems are most at risk, but this requires crossing the divide between cyber and physical risk assessments. However, existing cyber-security methods generally focus solely on the vulnerabilities and security of the cyber network and efforts to quantify the impacts of these cyber vulnerabilities on physical assets are generally limited to the consideration of individual attacks, rather than system-wide risk assessments. Similarly, risk assessments of physical infrastructure systems generally ignore potential impacts due to cyber-attacks. To overcome this cyber-physical divide in risk assessment, we introduce a novel approach for assessing risk across this divide. The proposed approach assesses the cyber risk of physical assets as a function of the vulnerabilities of their connected cyber components, and the contribution of cyber components to this risk. The approach is demonstrated with a case study of the C-Town water distribution system. The results indicate that the approach shows a modified prioritisation of risk compared to that obtained using conventional cyber or physical assessments, highlighting the importance of considering the connection between cyber and physical components in risk assessments of critical infrastructure and their physical assets.
引用
收藏
页数:31
相关论文
共 54 条
[1]   Cyber-Physical Systems for Water Supply Network Management: Basics, Challenges, and Roadmap [J].
Adedeji, Kazeem B. ;
Hamam, Yskandar .
SUSTAINABILITY, 2020, 12 (22) :1-30
[2]   SCADA vulnerabilities and attacks: A review of the state-of-the-art and open issues [J].
Alanazi, Manar ;
Mahmood, Abdun ;
Chowdhury, Mohammad Jabed Morshed .
COMPUTERS & SECURITY, 2023, 125
[3]  
[Anonymous], 2018, ISO 31000:2018(en) Risk Management-Guidelines
[4]   Measuring cyber-physical security in industrial control systems via minimum-effort attack strategies [J].
Barrere, Martin ;
Hankin, Chris ;
Nicolaou, Nicolas ;
Eliades, Demetrios G. ;
Parisini, Thomas .
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 52
[5]  
Broad D.R., 2005, Impacts of Global Climate Change, P1, DOI [10.1061/40792(173)17, DOI 10.1061/40792(173)17]
[6]   Reliable, resilient and sustainable water management: the Safe & SuRe approach [J].
Butler, David ;
Ward, Sarah ;
Sweetapple, Chris ;
Astaraie-Imani, Maryam ;
Diao, Kegong ;
Farmani, Raziyeh ;
Fu, Guangtao .
GLOBAL CHALLENGES, 2017, 1 (01) :63-77
[7]  
Byers R, 2022, National vulnerability database
[8]  
Cardenas Alvaro A., 2008, 2008 28th International Conference on Distributed Computing Systems Workshops (ICDCS Workshops), P495, DOI 10.1109/ICDCS.Workshops.2008.40
[9]   Quantitative Assessment of System Response during Disruptions: An Application to Water Distribution Systems [J].
Cassottana, Beatrice ;
Aydin, Nazli Yonca ;
Tang, Loon Ching .
JOURNAL OF WATER RESOURCES PLANNING AND MANAGEMENT, 2021, 147 (03)
[10]   Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review [J].
Cheimonidis, Pavlos ;
Rantos, Konstantinos .
FUTURE INTERNET, 2023, 15 (10)