Quantitative Risk Modeling and Analysis for Large-Scale Cyber-Physical Systems

被引:11
作者
Malik, Adeel A. [1 ]
Tosh, Deepak K. [1 ]
机构
[1] Univ Texas El Paso, Dept Comp Sci, El Paso, TX 79968 USA
来源
2020 29TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2020) | 2020年
关键词
Quantitative risk modeling; Risk assessment; Interdependent risk assessment; cyber security risks; risk metrics;
D O I
10.1109/icccn49398.2020.9209654
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Threats of cyber attacks are very real today and greatly impact everything including the public health sector, economics, electric grids, internet of things (IoT), and national security. The number of new evolving threats and reported vulnerabilities has severely increased in the last few years [1]. Perpetually refined cyber-attacks have set data, organizational assets, organizations, and individuals at considerable risk. Protecting sophisticated networks and interdependent systems, or reducing the impact of cyber-attacks has become a major challenge, where today's effective countermeasures can be completely ineffective tomorrow. The various risk assessment frameworks and methodologies are either high-level, missing risk metrics values, not suitable for all kinds of networks, or publicly not available. To address this issue, we present a quantitative risk assessment model, that helps to model the organizational security posture, evaluates the security controls in place, and provides an understanding of the associated risks. We further provide a detailed explanation of the formulations and evaluate the proposed model on an industrial scenario.
引用
收藏
页数:6
相关论文
共 28 条
[1]  
Aksu MU, 2017, INT CARN CONF SECU
[2]   Why information security is hard - An economic perspective [J].
Anderson, R .
17TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2001, :358-365
[3]  
[Anonymous], 2019, NVD YEARLY REPORT
[4]  
Anupindi R., 2006, MANAGING BUSINESS PR
[5]   Critical asset and portfolio risk analysis: An all-hazards framework [J].
Ayyub, Bilal M. ;
McGill, William L. ;
Kaminskiy, Mark .
RISK ANALYSIS, 2007, 27 (04) :789-801
[6]   European Integration: A Restart of the Idea of "Social Europe" [J].
Borko, Y. ;
Bisson, L. .
CONTEMPORARY EUROPE-SOVREMENNAYA EVROPA, 2019, (06) :5-17
[7]   Mission oriented risk and design analysis of critical information systems [J].
Buckshaw, DL ;
Parnell, GS ;
Unkenholz, WL ;
Parks, DL ;
Wallner, JM ;
Saydjari, OS .
MILITARY OPERATIONS RESEARCH, 2005, 10 (02) :19-38
[8]  
C. Coalition, 2019, POL PRIOR COORD VULN
[9]  
Cisco, 2019, CISC CYB REP
[10]  
ENISA, 2018, EC VULN DISCL ENISA