Continuous Quantitative Risk Management in Smart Grids Using Attack Defense Trees

Author:

Rios Erkuden,Rego Angel,Iturbe Eider,Higuero MariviORCID,Larrucea XabierORCID

Abstract

Although the risk assessment discipline has been studied from long ago as a means to support security investment decision-making, no holistic approach exists to continuously and quantitatively analyze cyber risks in scenarios where attacks and defenses may target different parts of Internet of Things (IoT)-based smart grid systems. In this paper, we propose a comprehensive methodology that enables informed decisions on security protection for smart grid systems by the continuous assessment of cyber risks. The solution is based on the use of attack defense trees modelled on the system and computation of the proposed risk attributes that enables an assessment of the system risks by propagating the risk attributes in the tree nodes. The method allows system risk sensitivity analyses to be performed with respect to different attack and defense scenarios, and optimizes security strategies with respect to risk minimization. The methodology proposes the use of standard security and privacy defense taxonomies from internationally recognized security control families, such as the NIST SP 800-53, which facilitates security certifications. Finally, the paper describes the validation of the methodology carried out in a real smart building energy efficiency application that combines multiple components deployed in cloud and IoT resources. The scenario demonstrates the feasibility of the method to not only perform initial quantitative estimations of system risks but also to continuously keep the risk assessment up to date according to the system conditions during operation.

Funder

Horizon 2020 Framework Programme

Publisher

MDPI AG

Subject

Electrical and Electronic Engineering,Biochemistry,Instrumentation,Atomic and Molecular Physics, and Optics,Analytical Chemistry

Reference43 articles.

1. Gartner 2019 Debate: Quantitative vs. Qualitative Cyber Risk Analysis. FAIR Institute https://www.risklens.com/blog/gartner-2019-debate-quantitative-vs-qualitative-cyber-risk-analysis/

2. DAG-based attack and defense modeling: Don’t miss the forest for the attack trees

3. Dynamic Security Risk Management Using Bayesian Attack Graphs

Cited by 21 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Attack–defense tree-based analysis and optimal defense synthesis for system design;Innovations in Systems and Software Engineering;2024-03-23

2. A Systematic Literature Review on Cybersecurity Risk Management in Smart Cities;2024 International Conference on Artificial Intelligence in Information and Communication (ICAIIC);2024-02-19

3. Risk analysis of cyber networks: a quantitative approach based on attack-defense trees;Journal of Innovative Engineering and Natural Science;2023-12-14

4. A taxonomy for decision making in IoT systems;Internet of Things;2023-12

5. A Review on Information Security Risk Assessment of Smart Systems: Risk Landscape, Challenges, and Prospective Methods;2023 10th International Conference on ICT for Smart Society (ICISS);2023-09-06

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3