Risk Assessments Considering Safety, Security, and Their Interdependencies in OT Environments

被引:7
|
作者
Hollerer, Siegfried [1 ]
Sauter, Thilo [2 ,3 ]
Kastner, Wolfgang [1 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Techn, Vienna, Austria
[3] Danube Univ Krems, Dept Integrated Sensor Syst, Krems, Austria
来源
PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022 | 2022年
关键词
Threat Modeling; OT Security; Safety; IT / OT convergence; MODELS;
D O I
10.1145/3538969.3543814
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information Technology (IT) and Operational Technology (OT) are converging further, which increases the number of interdependencies of safety and security risks arising in industrial architectures. Cyber attacks interfering safety functionality may lead to serious injuries as a consequence. Intentionally triggering a safety function may introduce a security vulnerability during the emergency procedure, e.g., by opening emergency exit doors leading to enabling unauthorized physical access. This paper introduces a risk evaluation methodology to prioritize and manage identified threats considering security, safety, and their interdepedencies. The presented methodology uses metrics commonly used in the industry to increase its applicability and enable the combination with other risk assessment approaches. These metrics are Common Vulnerability Scoring System (CVSS), Security Level (SL) from the standard IEC 62443 and Safety Integrity Level (SIL) from the standard IEC 61508. Conceptional similarities of those metrics are considered during the risk calculation, including an identified relation between CVSS and SL. Besides this relation, the skill level and resources of threat actors, threats enabling multiple identified attacks, the SIL of safety-relevant components affected, business criticality of the targeted asset, and the SL-T of the zone targeted by the attack are considered for risk evaluation. The industrial architecture to be analyzed is separated into zones and conduits according to IEC 62443, enabling the analyzed system to be compliant with its requirements.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] Security risk assessments in public transport networks
    Sanchez, M. M.
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART F-JOURNAL OF RAIL AND RAPID TRANSIT, 2011, 225 (F4) : 417 - 423
  • [22] Potential Problems with Information Security Risk Assessments
    Taylor, Richard G.
    INFORMATION SECURITY JOURNAL, 2015, 24 (4-6): : 177 - 184
  • [23] Offshore system safety and reliability considering microbial influenced multiple failure modes and their interdependencies
    Adumene, Sidum
    Khan, Faisal
    Adedigba, Sunday
    Zendehboudi, Sohrab
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2021, 215
  • [24] Alignment of safety and security risk assessments for modular production systems; [Abgleich von Safety- und Security-Risikobeurteilungen für modulare Produktionssysteme]
    Ehrlich M.
    Bröring A.
    Harder D.
    Auhagen-Meyer T.
    Kleen P.
    Wisniewski L.
    Trsek H.
    Jasperneite J.
    e & i Elektrotechnik und Informationstechnik, 2021, 138 (7) : 454 - 461
  • [25] Information security decisions of firms considering security risk interdependency
    Wu, Yong
    Wang, Linping
    Cheng, Dong
    Dai, Tao
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 178
  • [26] Adversarial safety analysis: Borrowing the methods of security vulnerability assessments
    Johnston, RG
    JOURNAL OF SAFETY RESEARCH, 2004, 35 (03) : 245 - 248
  • [27] A Fuzzy-Based Holistic Approach for Supply Chain Risk Assessment and Aggregation Considering Risk Interdependencies
    Diaz-Curbelo, Alina
    Gento, Angel M.
    Redondo, Alfonso
    Aqlan, Faisal
    APPLIED SCIENCES-BASEL, 2019, 9 (24):
  • [28] Methodology for security risk assessments-is there a best practice?
    Maal, M.
    Busmundrud, O.
    Endregard, M.
    RISK, RELIABILITY AND SAFETY: INNOVATING THEORY AND PRACTICE, 2017, : 860 - 866
  • [29] Integrating risk assessments and safety management systems
    Gould, JH
    Caruana, SA
    Davies, PA
    SAFETY AND RELIABILITY, VOLS 1 AND 2, 2003, : 695 - 700
  • [30] Risk assessments in the context of health and safety on mines
    Anglo American Corp of South Africa, Ltd
    Journal of the Mine Ventilation Society of South Africa, 1996, 49 (02) : 38 - 41