Using Attack Trees to Assess Security Controls for Supervisory Control and Data Acquisition Systems (SCADA)

被引:0
作者
Lopez, Juan, Jr. [1 ]
Nielsen, Jason [2 ]
Hemmes, Jeffrey [1 ]
Humphries, Jeffrey [1 ]
机构
[1] USAF, Inst Technol, Ctr Cyberspace Res, Dept Elect & Comp Engn, Wright Patterson AFB, OH 45433 USA
[2] USAF, Air Force Intelligence Surveillance & Reconnaissa, San Antonio, TX 78243 USA
来源
PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY | 2012年
关键词
Attack Tree; Security Controls; SCADA; Risk Assessment;
D O I
暂无
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
The recent trend to interconnect industrial control systems with a corporate LAN has dramatically expanded the threat of remote cyber attack. Indeed, adversaries are targeting these systems with increasing frequency and sophistication. Cyber defense options for security decision makers are subsequently increasing in variety and complexity. Determining which set of security controls are most effective against cyber attacks is primarily a risk management and resource constraint problem. This research takes an exploratory approach to apply attack tree modeling to assess which group of security controls can potentially mitigate cyber attacks against industrial control systems. The research methodology combined probabilities of adversary success with impact assessments from control system experts. Subsequent data analysis identified 14 of 30 security controls that are strongly associated with mitigating cyber attacks on an ICS.
引用
收藏
页码:166 / 177
页数:12
相关论文
共 38 条
[1]  
[Anonymous], 1999, P INT C ACC LARG EXP
[2]  
Ashley B.K., 1999, IA NEWSLETTER, V3, P3
[3]  
Ayyub B., 2007, RISK ANAL
[4]  
Baker S., 2011, DARK CRUCIAL IND CON
[5]  
Baker Stewart., 2010, CROSSFIRE CRITICAL I
[6]  
Barnes E., 2010, MYSTERY SURROUNDS CY
[7]  
Buhan I., 2006, ADV BIOMETRICS
[8]  
Bundbury P., 2009, COMPUTER FRAUD SECUR
[9]  
Byres E., 2004, The Myths and Facts behind Cyber Security Risks for Industrial Control Systems
[10]  
Carlson R., 2002, SAND20020729 SAND NA