Assessment of the cybersecurity vulnerability of construction networks

被引:14
|
作者
Mantha, Bharadwaj R. K. [1 ]
Garcia de Soto, Borja [1 ]
机构
[1] New York Univ Abu Dhabi NYUAD, Div Engn, SMART Construct Res Grp, Abu Dhabi, U Arab Emirates
关键词
Construction network; CVSS; Cybersecurity; Risk management; Security score; Vulnerability assessment; Vulnerability metrics; RISKS;
D O I
10.1108/ECAM-06-2020-0400
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Purpose The aim of this study is o examine the advantages and disadvantages of different existing scoring systems in the cybersecurity domain and their applicability to the AEC industry and to systematically apply a scoring system to determine scores for some of the most significant construction participants. Design/methodology/approach This study proposes a methodology that uses the Common Vulnerability Scoring System (CVSS) to calculate scores and the likelihood of occurrence based on communication frequencies to ultimately determine risk categories for different paths in a construction network. As a proof of concept, the proposed methodology is implemented in a construction network from a real project found in the literature. Findings Results show that the proposed methodology could provide valuable information to assist project participants to assess the overall cybersecurity vulnerability of construction and assist during the vulnerability-management processes. For example, a project owner can use this information to get a better understanding of what to do to limit its vulnerability, which will lead to the overall improvement of the security of the construction network. Research limitations/implications It has to be noted that the scoring systems, the scores and categories adopted in the study need not necessarily be an exact representation of all the construction participants or networks. Therefore, caution should be exercised to avoid generalizing the results of this study. Practical implications The proposed methodology can provide valuable information and assist project participants to assess the overall cyber-vulnerability of construction projects and support the vulnerability-management processes. For example, a project owner can use this approach to get a better understanding of what to do to limit its cyber-vulnerability exposure, which will ultimately lead to the overall improvement of the construction network's security. This study will also help raise more awareness about the cybersecurity implications of the digitalization and automation of the AEC industry among practitioners and construction researchers. Social implications Given the amount of digitized services and tools used in the AEC industry, cybersecurity is increasingly becoming critical for society in general. In some cases, (e.g. critical infrastructure) incidents could have significant economic and societal or public safety implications. Therefore, proper consideration and action from the AEC research community and industry are needed. Originality/value To the authors' knowledge, this is the first attempt to measure and assess the cybersecurity of individual participants and the construction network as a whole by using the Common Vulnerability Scoring System.
引用
收藏
页码:3078 / 3105
页数:28
相关论文
共 50 条
  • [41] Toward Vulnerability Assessment for 5G Mobile Communication Networks
    Luo, Shibo
    Wu, Jun
    Li, Jianhua
    Guo, Longhua
    Pei, Bei
    2015 IEEE INTERNATIONAL CONFERENCE ON SMART CITY/SOCIALCOM/SUSTAINCOM (SMARTCITY), 2015, : 72 - 76
  • [42] Vulnerability Assessment and Classification based on Influence Metrics in Mobile Social Networks
    Nagaraj, Keerthiraj
    Bhasale, Swapnil Sunilkumar
    McNair, Janise
    Helmy, Ahmed
    MOBIWAC'19: PROCEEDINGS OF THE 17TH ACM INTERNATIONAL SYMPOSIUM ON MOBILITY MANAGEMENT AND WIRELESS ACCESS, 2019, : 9 - 16
  • [43] Efficient Vulnerability Assessment of Large-Scale Dynamic Transportation Networks
    Shekar, Venkateswaran
    Fiondella, Lance
    IEEE TRANSACTIONS ON RELIABILITY, 2024, : 1 - 13
  • [44] Perceived Vulnerability As a Determinant of Increased Risk for Cybersecurity Risk Behavior
    Debb, Scott M.
    McClellan, Marnee K.
    CYBERPSYCHOLOGY BEHAVIOR AND SOCIAL NETWORKING, 2021, 24 (09) : 605 - 611
  • [45] Structural Vulnerability Assessment of Community-Based Routing in Opportunistic Networks
    Alim, Md Abdul
    Li, Xiang
    Nguyen, Nam P.
    Thai, My T.
    Helal, Abdelsalam
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2016, 15 (12) : 3156 - 3170
  • [46] Universal Framework for Vulnerability Assessment of Power Grid Based on Complex Networks
    Sun, Yunhe
    Yang, Dongsheng
    Meng, Lei
    Gao, Xiaoting
    Hu, Bo
    PROCEEDINGS OF THE 30TH CHINESE CONTROL AND DECISION CONFERENCE (2018 CCDC), 2018, : 136 - 141
  • [47] Governance in vulnerability assessment: the role of globalising decision-making networks in determining local vulnerability and adaptive capacity
    Keskitalo, E. Carina H.
    MITIGATION AND ADAPTATION STRATEGIES FOR GLOBAL CHANGE, 2009, 14 (02) : 185 - 201
  • [48] Governance in vulnerability assessment: the role of globalising decision-making networks in determining local vulnerability and adaptive capacity
    E. Carina H. Keskitalo
    Mitigation and Adaptation Strategies for Global Change, 2009, 14 : 185 - 201
  • [49] Automated Student Assessment for Cybersecurity Courses
    Ajjimaporn, Pann
    Gibbons, Michael
    Stoick, Brandon
    Straub, Jeremy
    2019 14TH ANNUAL CONFERENCE SYSTEM OF SYSTEMS ENGINEERING (SOSE), 2019, : 93 - 95
  • [50] Cybersecurity Risk Assessment for Space Systems
    Vessels, Ly
    Heffner, Kenneth
    Johnson, Daniel
    2019 IEEE SPACE COMPUTING CONFERENCE (SCC), 2019, : 11 - 19