Maritime Cyber Risk Management: An Experimental Ship Assessment

被引:57
作者
Svilicic, Boris [1 ]
Kamahara, Junzo [2 ]
Rooks, Matthew [2 ]
Yano, Yoshiji [2 ]
机构
[1] Univ Rijeka, Fac Maritime Studies, Studentska Ul 2, Rijeka 51000, Croatia
[2] Kobe Univ, Grad Sch Maritime Sci, Higashinada Ku, 5-1-1 Fukaeminami Machi, Kobe, Hyogo, Japan
关键词
Maritime cyber security; Computational vulnerability scanning; Quantitative risk analysis;
D O I
10.1017/S0373463318001157
中图分类号
U6 [水路运输]; P75 [海洋工程];
学科分类号
0814 ; 081505 ; 0824 ; 082401 ;
摘要
The maritime transport industry is increasingly reliant on computing and communication technologies, and the need for cyber risk management of critical systems and assets on vessels is becoming critically important. In this paper, a comprehensive cyber risk assessment of a ship is presented. An experimental process consisting of assessment preparation activities, assessment conduct and results communication has been developed. The assessment conduct relies on a survey developed and performed by interviewing a ship's crew. Computational vulnerability scanning of the ship's Electronic Chart Display and Information System (ECDIS) is introduced as a specific part of this cyber security assessment. The assessment process presented has been experimentally tested by evaluating the cyber security level of Kobe University's training ship Fukae-maru. For computational vulnerability scanning, an industry-leading software tool has been used, and a quantitative cyber risk analysis has been conducted to evaluate cyber risks on the ship.
引用
收藏
页码:1108 / 1120
页数:13
相关论文
共 20 条
[1]  
[Anonymous], 2018, FRAM IMPR CRIT INFR
[2]  
[Anonymous], 2014, P 30 ANN COMP SEC AP
[3]  
Baltic and International Maritime Council. (BIMCO), 2017, GUID CYB SEC ONB SHI
[4]   ANALYSIS OF SOFTWARE THREATS TO THE AUTOMATIC IDENTIFICATION SYSTEM [J].
Botunac, Ive ;
Grzan, Marijan .
BRODOGRADNJA, 2017, 68 (01) :97-105
[5]  
Burton J, 2016, P 2016 INT C CYB SIT
[6]  
DNV GL, 2016, DNVGLRP0496
[7]   Consistency in the development of performance assessment methods in the maritime domain [J].
Ernstsen J. ;
Nazir S. .
WMU Journal of Maritime Affairs, 2018, 17 (1) :71-90
[8]   Enhancing Navigator Competence by Demonstrating Maritime Cyber Security [J].
Hareide, Odd Sveinung ;
Josok, Oyvind ;
Lund, Mass Soldal ;
Ostnes, Runar ;
Helkala, Kirsi .
JOURNAL OF NAVIGATION, 2018, 71 (05) :1025-1039
[9]  
Hassani V, 2017, PROCEEDINGS OF THE ASME 36TH INTERNATIONAL CONFERENCE ON OCEAN, OFFSHORE AND ARCTIC ENGINEERING, 2017, VOL 7B
[10]  
IMO, 2017, Maritime Cyber Risk Management in Safety Management Systems