Risk Assessments Considering Safety, Security, and Their Interdependencies in OT Environments

被引:7
|
作者
Hollerer, Siegfried [1 ]
Sauter, Thilo [2 ,3 ]
Kastner, Wolfgang [1 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Techn, Vienna, Austria
[3] Danube Univ Krems, Dept Integrated Sensor Syst, Krems, Austria
来源
PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022 | 2022年
关键词
Threat Modeling; OT Security; Safety; IT / OT convergence; MODELS;
D O I
10.1145/3538969.3543814
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information Technology (IT) and Operational Technology (OT) are converging further, which increases the number of interdependencies of safety and security risks arising in industrial architectures. Cyber attacks interfering safety functionality may lead to serious injuries as a consequence. Intentionally triggering a safety function may introduce a security vulnerability during the emergency procedure, e.g., by opening emergency exit doors leading to enabling unauthorized physical access. This paper introduces a risk evaluation methodology to prioritize and manage identified threats considering security, safety, and their interdepedencies. The presented methodology uses metrics commonly used in the industry to increase its applicability and enable the combination with other risk assessment approaches. These metrics are Common Vulnerability Scoring System (CVSS), Security Level (SL) from the standard IEC 62443 and Safety Integrity Level (SIL) from the standard IEC 61508. Conceptional similarities of those metrics are considered during the risk calculation, including an identified relation between CVSS and SL. Besides this relation, the skill level and resources of threat actors, threats enabling multiple identified attacks, the SIL of safety-relevant components affected, business criticality of the targeted asset, and the SL-T of the zone targeted by the attack are considered for risk evaluation. The industrial architecture to be analyzed is separated into zones and conduits according to IEC 62443, enabling the analyzed system to be compliant with its requirements.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] A Survey of Ontologies Considering General Safety, Security, and Operation Aspects in OT
    Hollerer, Siegfried
    Sauter, Thilo
    Kastner, Wolfgang
    IEEE OPEN JOURNAL OF THE INDUSTRIAL ELECTRONICS SOCIETY, 2024, 5 : 861 - 885
  • [2] Towards a Threat Modeling Approach Addressing Security and Safety in OT Environments
    Hollerer, Siegfried
    Kastner, Wolfgang
    Sauter, Thilo
    17TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS 2021 (WFCS 2021), 2021, : 37 - 40
  • [3] Alignment of safety and security risk assessments for modular production systems
    Ehrlich, Marco
    Broering, Andre
    Harder, Dimitri
    Auhagen-Meyer, Torben
    Kleen, Philip
    Wisniewski, Lukasz
    Trsek, Henning
    Jasperneite, Jurgen
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2021, 138 (07): : 454 - 461
  • [4] CONTROL AND INHERENT RISK ASSESSMENTS IN CLIENT ENGAGEMENTS - AN EXAMINATION OF THEIR INTERDEPENDENCIES
    HASKINS, ME
    DIRSMITH, MW
    JOURNAL OF ACCOUNTING AND PUBLIC POLICY, 1995, 14 (01) : 63 - 83
  • [5] Maritime Security and Risk Assessments
    Perkovic, Marko
    Gucma, Lucjan
    Feuerstack, Sebastian
    JOURNAL OF MARINE SCIENCE AND ENGINEERING, 2024, 12 (06)
  • [6] Probabilistic security assessments: How they differ from safety assessments
    Snell, MK
    PROBABILISTIC SAFETY ASSESSMENT AND MANAGEMENT, VOL I AND II, PROCEEDINGS, 2002, : 1465 - 1470
  • [7] Identification of security threats, safety hazards, and interdependencies in industrial edge computing
    Denzler, Patrick
    Hollerer, Siegfried
    Fruehwirth, Thomas
    Kastner, Wolfgang
    2021 ACM/IEEE 6TH SYMPOSIUM ON EDGE COMPUTING (SEC 2021), 2021, : 397 - 402
  • [8] Automated Security Assessments of Amazon Web Services Environments
    Engstrom, Viktor
    Johnson, Pontus
    Lagerstrom, Robert
    Ringdahl, Erik
    Wallstedt, Max
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (02)
  • [9] A Study on the Classification of OT Security Risk Mitigation Measures
    Kanamaru, Hiroo
    Fujita, Junya
    Arai, Takayuki
    2023 62ND ANNUAL CONFERENCE OF THE SOCIETY OF INSTRUMENT AND CONTROL ENGINEERS, SICE, 2023, : 274 - 279
  • [10] Uniform Approach of Risk Communication in Distributed IT Environments Combining Safety and Security Aspects
    Fruth, Jana
    Nett, Edgar
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, 2014, 8696 : 289 - 300