Mission-Based Cybersecurity Test and Evaluation of Weapon Systems in Association with Risk Management Framework

Author:

Kim IkjaeORCID,Kim Sungjoong,Kim Hansung,Shin DongkyooORCID

Abstract

With the advancement of information technology (IT), the importance of cyber security is increasing because of the expansion of software utilization in the development of weapon systems. Civilian embedded systems and military weapon systems have cybersecurity-related symmetry that can increase vulnerabilities in the process of advanced information technology. Many countries, including the United States, are exploring ways to improve cybersecurity throughout the lifecycle of a weapon system. The South Korean military is applying the U.S. standard risk management framework (RMF) to some weapon systems to improve cybersecurity, but the need for a model that is more suitable for the South Korean military has been emphasized. This paper presents the results of a mission-based cybersecurity test, along with an evaluation model that can be applied to South Korean military weapon systems in parallel with the RMF. This study first examined the related international research trends, and proposed a test and evaluation method that could be utilized with the RMF throughout the entire life cycle of a weapon system. The weapon system was divided into asset, function, operational task, and mission layers based on the mission, and a mutually complementary model was proposed by linking the RMF and cybersecurity test and evaluation according to the domestic situation. In order to verify the proposed cybersecurity test and evaluation model, a simulation was developed and performed targeting the Close Air Support (CAS) mission support system, which is a virtual weapon system. In this simulation, the nodes performances by layer before and after a cyberattack were calculated, and the vulnerabilities and protection measures identified in the cyber security test and evaluation were quantified. This simulation made it possible to evaluate and derive protection measures in consideration of mission performance. It is believed that the proposed model could be used with some modifications, depending on the circumstances of each country developing weapon systems in the future.

Funder

the National Research Foundation of Korea (NRF) grant funded by the Korea government

Publisher

MDPI AG

Subject

Physics and Astronomy (miscellaneous),General Mathematics,Chemistry (miscellaneous),Computer Science (miscellaneous)

Reference17 articles.

1. Risk Management Framework for Information Systems and Organizations, 2018.

2. Available online: https://daytonaero.com/wp-content/uploads/DOD_Cybersecurity-Test-and-Evaluation-Guidebook-Version2-C1_10-Feb-2020.pdf. Cybersecurity Test and Evaluation Guidebook, 2022.

3. The direction of application of the RMF-based risk management system considering interoperability;Kwon;J. Internet Comput. Serv. (JICS),2021

4. Bryan, S. The Absence of Risk Management Framework in Small Defense Forces. Ph.D. Thesis, 2016.

5. Keith, F.J., Simon, R.A., and Elena, S. Cybersecurity Challenges and Processes for Australia’s Future Submarine. Proceedings of the 4th Submarine Science, Technology and Engineering Conference 2017 (SubSTEC4).

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3