Risk Assessments Considering Safety, Security, and Their Interdependencies in OT Environments

被引:7
|
作者
Hollerer, Siegfried [1 ]
Sauter, Thilo [2 ,3 ]
Kastner, Wolfgang [1 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Techn, Vienna, Austria
[3] Danube Univ Krems, Dept Integrated Sensor Syst, Krems, Austria
来源
PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022 | 2022年
关键词
Threat Modeling; OT Security; Safety; IT / OT convergence; MODELS;
D O I
10.1145/3538969.3543814
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information Technology (IT) and Operational Technology (OT) are converging further, which increases the number of interdependencies of safety and security risks arising in industrial architectures. Cyber attacks interfering safety functionality may lead to serious injuries as a consequence. Intentionally triggering a safety function may introduce a security vulnerability during the emergency procedure, e.g., by opening emergency exit doors leading to enabling unauthorized physical access. This paper introduces a risk evaluation methodology to prioritize and manage identified threats considering security, safety, and their interdepedencies. The presented methodology uses metrics commonly used in the industry to increase its applicability and enable the combination with other risk assessment approaches. These metrics are Common Vulnerability Scoring System (CVSS), Security Level (SL) from the standard IEC 62443 and Safety Integrity Level (SIL) from the standard IEC 61508. Conceptional similarities of those metrics are considered during the risk calculation, including an identified relation between CVSS and SL. Besides this relation, the skill level and resources of threat actors, threats enabling multiple identified attacks, the SIL of safety-relevant components affected, business criticality of the targeted asset, and the SL-T of the zone targeted by the attack are considered for risk evaluation. The industrial architecture to be analyzed is separated into zones and conduits according to IEC 62443, enabling the analyzed system to be compliant with its requirements.
引用
收藏
页数:8
相关论文
共 50 条
  • [41] Arguments for Considering Uncertainty in QSAR Predictions in Hazard and Risk Assessments
    Sahlin, Ullrika
    Golsteijn, Laura
    Iqbal, M. Sarfraz
    Peijnenburg, Willie
    ATLA-ALTERNATIVES TO LABORATORY ANIMALS, 2013, 41 (01): : 91 - 110
  • [42] Risk Communication for Safety and Sense of Security
    Kitano, Masaru
    FOOD HYGIENE AND SAFETY SCIENCE, 2012, 53 (06): : J412 - J415
  • [43] Security risk prediction technology for power monitoring system under the integration of OT and IT
    Zhu, Zhennan
    Jin, Jingquan
    International Journal for Simulation and Multidisciplinary Design Optimization, 2024, 15
  • [44] Effectiveness of Security Control Risk Assessments for Enterprises: Assess on the Business Perspective of Security Risks
    Atyam, Satyanandan B.
    INFORMATION SECURITY JOURNAL, 2010, 19 (06): : 343 - 350
  • [45] Identification of Threats and Security Risk Assessments for Recursive Internet Architecture
    Asgari, Hamid
    Haines, Sarah
    Rysavy, Ondrej
    IEEE SYSTEMS JOURNAL, 2018, 12 (03): : 2437 - 2448
  • [46] FUZZY RISK ASSESSMENTS ON SECURITY POLICIES FOR DIGITAL RIGHTS MANAGEMENT
    Zhang, Zhiyong
    Lian, Shiguo
    Pei, Qingqi
    Pu, Jiexin
    NEURAL NETWORK WORLD, 2010, 20 (03) : 265 - 284
  • [47] A Test of Structured Threat Descriptions for Information Security Risk Assessments
    Karlzen, Henrik
    Bengtsson, Johan
    Hallberg, Jonas
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 469 - 476
  • [48] The 'troika of security': merging retrospective and futuristic 'risk' and 'security' assessments before Euro 2020
    Ludvigsen, Jan Andre Lee
    LEISURE STUDIES, 2020, 39 (06) : 844 - 858
  • [49] Investigation of Resource Constraints for the Automation of Industrial Security Risk Assessments
    Ehrlich, Marco
    Lukas, Georg
    Trsek, Henning
    Jasperneite, Juergen
    Diedrich, Christian
    18TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS 2022 (WFCS 2022), 2022, : 151 - 158
  • [50] MEGA-EVENT ORGANIZATION CONSIDERING SAFETY, SECURITY AND RESILIENCE
    Girgin, Funda Atun
    Tasci, Ozlem Edizel
    TEMA-JOURNAL OF LAND USE MOBILITY AND ENVIRONMENT, 2019, 12 (03) : 249 - 264