Evaluation of a Cyber Risk Assessment Approach for Cyber-Physical Systems: Maritime- and Energy-Use Cases

被引:11
作者
Amro, Ahmed [1 ]
Gkioulos, Vasileios [1 ]
机构
[1] Norwegian Univ Sci & Technol, Fac Informat Technol & Elect Engn, Dept Informat Secur & Commun Technol, N-2815 Gjovik, Norway
关键词
cyber risk assessment; evaluation; cyber-physical systems; ATT&CK; FMECA; maritime; energy; autonomous passenger ship; digital substation;
D O I
10.3390/jmse11040744
中图分类号
U6 [水路运输]; P75 [海洋工程];
学科分类号
0814 ; 081505 ; 0824 ; 082401 ;
摘要
In various domains such as energy, manufacturing, and maritime, cyber-physical systems (CPSs) have seen increased interest. Both academia and industry have focused on the cybersecurity aspects of such systems. The assessment of cyber risks in a CPS is a popular research area with many existing approaches that aim to suggest relevant methods and practices. However, few works have addressed the extensive and objective evaluation of the proposed approaches. In this paper, a standard-aligned evaluation methodology is presented and empirically conducted to evaluate a newly proposed cyber risk assessment approach for CPSs. The approach, which is called FMECA-ATT&CK is based on failure mode, effects and criticality analysis (FMECA) risk assessment process and enriched with the semantics and encoded knowledge in the Adversarial Tactics, Techniques, and Common Knowledge framework (ATT&CK). Several experts were involved in conducting two risk assessment processes, FMECA-ATT&CK and Bow-Tie, against two use cases in different application domains, particularly an autonomous passenger ship (APS) as a maritime-use case and a digital substation as an energy-use case. This allows for the evaluation of the approach based on a group of characteristics, namely, applicability, feasibility, accuracy, comprehensiveness, adaptability, scalability, and usability. The results highlight the positive utility of FMECA-ATT&CK in model-based, design-level, and component-level cyber risk assessment of CPSs with several identified directions for improvements. Moreover, the standard-aligned evaluation method and the evaluation characteristics have been demonstrated as enablers for the thorough evaluation of cyber risk assessment methods.
引用
收藏
页数:23
相关论文
共 32 条
[1]  
Abkowitz M., 2011, WIT T BUILT ENV, V119, P221
[2]  
Alford R., 2022, Caldera: A Red-Blue Cyber Operations Automation Platform
[3]  
Amro A., 2019, LECT NOTES COMPUT SC, P69
[4]   Assessing Cyber Risk in Cyber-Physical Systems Using the ATT&CK Framework [J].
Amro, Ahmed ;
Gkioulos, Vasileios ;
Katsikas, Sokratis .
ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (02)
[5]   Communication architecture for autonomous passenger ship [J].
Amro, Ahmed ;
Gkioulos, Vasileios ;
Katsikas, Sokratis .
PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART O-JOURNAL OF RISK AND RELIABILITY, 2023, 237 (02) :459-484
[6]  
[Anonymous], 2018, Information TechnologySecurity TechniquesInformation Security Risk Management
[7]  
[Anonymous], 2015, 152882015 IECIEEE
[8]  
[Anonymous], 2018, COSCO SHIPP LIN FALL
[9]  
[Anonymous], 2019, 31010 IEC ISO
[10]  
Autoferry, 2018, Autonomous all-electric passenger ferries for urban water transport