Risk-based safety scoping of adversary-centric security testing on Operational Technology

计算机安全 对手 工程类 风险分析(工程) 职业安全与健康 毒物控制 计算机科学 法律工程学 业务 医疗急救 医学 病理
作者
Alexander Staves,Antonios Gouglidis,Sam Maesschalck,David Hutchison
出处
期刊:Safety Science [Elsevier]
卷期号:174: 106481-106481
标识
DOI:10.1016/j.ssci.2024.106481
摘要

Due to the recent increase in cyber attacks targeting Critical National Infrastructure, governments and organisations alike have invested considerably into improving the security of their underlying infrastructure, commonly known as Operational Technology (OT). The use of adversary-centric security tests such as vulnerability assessments, penetration tests and red team engagements has gained significant traction due to these engagements' goal to emulate threat actors in preparation for genuine cyber attacks. Challenges arise, however, when performing security tests on these as the nature of OT requires additional safety and operation risks to be considered. This paper proposes a framework for incorporating the assessment of safety and operational risks within an overall scoping methodology for adversary-centric security testing in OT environments. Within this framework, we also propose a hybrid testing model derived from the Purdue Enterprise Reference Architecture and the Defense in Depth model to identify and quantify safety and operational risk at a per-layer level, separating high and low-risk layers and being subsequently used for defining the rules of engagement. As a result, this framework can aid vendors and clients in appropriately scoping adversary-centric security tests so that depth-of-testing is maximised while minimising the risk to safety and to the operational process. The framework is then evaluated through a qualitative study involving industry experts, confirming the framework's validity for implementation in practice.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
3秒前
huangJP发布了新的文献求助10
4秒前
魏你大爷发布了新的文献求助10
5秒前
汤圆圆儿发布了新的文献求助30
5秒前
杨然完成签到 ,获得积分10
6秒前
7秒前
动听平露发布了新的文献求助10
7秒前
8秒前
leonzhou完成签到,获得积分20
8秒前
ppf完成签到,获得积分20
9秒前
李爱国应助吃猫的鱼采纳,获得10
9秒前
NexusExplorer应助研猫采纳,获得10
9秒前
11秒前
今晚打母驴应助单薄友易采纳,获得30
11秒前
小谢同学完成签到 ,获得积分10
12秒前
12秒前
王贺帅发布了新的文献求助10
14秒前
leonzhou发布了新的文献求助10
15秒前
漂亮幻莲发布了新的文献求助10
17秒前
爱听歌天德完成签到,获得积分20
19秒前
冷艳的孤晴完成签到,获得积分10
20秒前
英姑应助王雷采纳,获得10
20秒前
zho发布了新的文献求助30
21秒前
26秒前
GM完成签到,获得积分20
26秒前
26秒前
黑眼圈完成签到,获得积分10
27秒前
小马甲应助吉吉米米采纳,获得10
27秒前
Yihvan发布了新的文献求助30
28秒前
酷波er应助Zephyr采纳,获得10
28秒前
活泼酸奶发布了新的文献求助10
28秒前
陈腿毛完成签到,获得积分10
30秒前
0411345完成签到,获得积分10
31秒前
plumephoenix发布了新的文献求助10
31秒前
31秒前
杳鸢应助Blessing采纳,获得20
32秒前
34秒前
czyzyzy完成签到,获得积分10
35秒前
张zi发布了新的文献求助10
37秒前
高分求助中
歯科矯正学 第7版(或第5版) 1004
Smart but Scattered: The Revolutionary Executive Skills Approach to Helping Kids Reach Their Potential (第二版) 1000
Semiconductor Process Reliability in Practice 720
GROUP-THEORY AND POLARIZATION ALGEBRA 500
Mesopotamian divination texts : conversing with the gods : sources from the first millennium BCE 500
Days of Transition. The Parsi Death Rituals(2011) 500
The Heath Anthology of American Literature: Early Nineteenth Century 1800 - 1865 Vol. B 500
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3229292
求助须知:如何正确求助?哪些是违规求助? 2877020
关于积分的说明 8197467
捐赠科研通 2544342
什么是DOI,文献DOI怎么找? 1374310
科研通“疑难数据库(出版商)”最低求助积分说明 646923
邀请新用户注册赠送积分活动 621738