Assessing Cyber Risk in Cyber-Physical Systems Using the ATT&CK Framework

Author:

Amro Ahmed1ORCID,Gkioulos Vasileios1ORCID,Katsikas Sokratis1ORCID

Affiliation:

1. Norwegian University of Science and Technology, Teknologivegen, Gjøvik, Norway

Abstract

Autonomous transport is receiving increasing attention, with research and development activities already providing prototype implementations. In this article we focus on Autonomous Passenger Ships (APS) , which are being considered as a solution for passenger transport across urban waterways. The ambition of the authors has been to examine the safety and security implications of such a Cyber Physical System (CPS) , particularly focusing on threats that endanger the passengers and the operational environment of the APS. Accordingly, the article presents a new risk assessment approach based on a Failure Modes Effects and Criticality Analysis (FMECA) that is enriched with selected semantics and components of the MITRE ATT&CK framework, in order to utilize the encoded common knowledge and facilitate the expression of attacks. Then, the proposed approach is demonstrated through conducting a risk assessment for a communication architecture tailored to the requirements of APSs that were proposed in earlier work. Moreover, we propose a group of graph theory-based metrics for estimating the impact of the identified risks. The use of this method has resulted in the identification of risks and their corresponding countermeasures, in addition to identifying risks with limited existing mitigation mechanisms. The benefits of the proposed approach are the comprehensive, atomic, and descriptive nature of the identified threats, which reduce the need for expert judgment, and the granular impact estimation metrics that reduce the impact of bias. All these features are provided in a semi-automated approach to reduce the required effort and collectively are argued to enrich the design-level risk assessment processes with an updatable industry threat model standard, namely ATT&CK.

Publisher

Association for Computing Machinery (ACM)

Subject

Safety, Risk, Reliability and Quality,General Computer Science

Reference63 articles.

1. https://github.com/ahmed-amro/APS-Communication_Architecture.git APS communication architecture AADL model

2. 2018. COSCO Shipping Lines Falls Victim to Cyber Attack. https://bit.ly/COSCOAttack.

3. 2018. Iranian hackers suspected in cyber breach and extortion attempt on Navy shipbuilder Austal. https://bit.ly/AustalAttack.

4. Identifying Critical Components in Large Scale Cyber Physical Systems

5. Otis Alexander Misha Belisle and Jacob Steele. 2020. MITRE ATT&CK® for industrial control systems: Design and philosophy. (2020).

Cited by 21 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Dude, Where’s That Ship? Stealthy Radio Attacks Against AIS Broadcasts;2024 IEEE 49th Conference on Local Computer Networks (LCN);2024-10-08

2. Cyber risk assessment of cyber-enabled autonomous cargo vessel;International Journal of Critical Infrastructure Protection;2024-09

3. Systematic literature review of threat modeling and risk assessment in ship cybersecurity;Ocean Engineering;2024-08

4. Cybersecurity risk assessment of a marine dual-fuel engine on inland waterways ship;Proceedings of the Institution of Mechanical Engineers, Part M: Journal of Engineering for the Maritime Environment;2024-07-28

5. Research on neural networks in computer network security evaluation and prediction methods;International Journal of Knowledge-based and Intelligent Engineering Systems;2024-03-03

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3