Risk-based safety scoping of adversary-centric security testing on Operational Technology

计算机安全 对手 工程类 风险分析(工程) 职业安全与健康 毒物控制 计算机科学 法律工程学 业务 医疗急救 医学 病理
作者
Alexander Staves,Antonios Gouglidis,Sam Maesschalck,David Hutchison
出处
期刊:Safety Science [Elsevier]
卷期号:174: 106481-106481
标识
DOI:10.1016/j.ssci.2024.106481
摘要

Due to the recent increase in cyber attacks targeting Critical National Infrastructure, governments and organisations alike have invested considerably into improving the security of their underlying infrastructure, commonly known as Operational Technology (OT). The use of adversary-centric security tests such as vulnerability assessments, penetration tests and red team engagements has gained significant traction due to these engagements' goal to emulate threat actors in preparation for genuine cyber attacks. Challenges arise, however, when performing security tests on these as the nature of OT requires additional safety and operation risks to be considered. This paper proposes a framework for incorporating the assessment of safety and operational risks within an overall scoping methodology for adversary-centric security testing in OT environments. Within this framework, we also propose a hybrid testing model derived from the Purdue Enterprise Reference Architecture and the Defense in Depth model to identify and quantify safety and operational risk at a per-layer level, separating high and low-risk layers and being subsequently used for defining the rules of engagement. As a result, this framework can aid vendors and clients in appropriately scoping adversary-centric security tests so that depth-of-testing is maximised while minimising the risk to safety and to the operational process. The framework is then evaluated through a qualitative study involving industry experts, confirming the framework's validity for implementation in practice.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
am0409完成签到,获得积分10
1秒前
1秒前
1秒前
酷波er应助遇见采纳,获得10
1秒前
徐不想搞科研完成签到,获得积分10
2秒前
小王完成签到,获得积分10
3秒前
小林子发布了新的文献求助10
3秒前
杜杨帆完成签到,获得积分10
3秒前
濯枝雨完成签到,获得积分10
4秒前
4秒前
4秒前
大胆的皮卡丘完成签到,获得积分20
5秒前
开朗的太阳花完成签到 ,获得积分20
5秒前
Keyl完成签到,获得积分10
5秒前
乐乐应助tengfei采纳,获得10
5秒前
Owen应助apong采纳,获得10
5秒前
5秒前
5秒前
木卜小白完成签到 ,获得积分10
6秒前
小婷发布了新的文献求助10
6秒前
之一完成签到 ,获得积分20
6秒前
屈屈完成签到,获得积分10
6秒前
7秒前
致幻完成签到,获得积分10
7秒前
7秒前
修仙团子完成签到,获得积分10
7秒前
7秒前
7秒前
学术菜鸟完成签到,获得积分20
8秒前
SciGPT应助落后雨真采纳,获得10
8秒前
小灰灰发布了新的文献求助10
8秒前
8秒前
方冰绿发布了新的文献求助20
8秒前
勤劳绮玉完成签到,获得积分10
9秒前
无聊的人发布了新的文献求助10
10秒前
小巧灯泡完成签到,获得积分10
10秒前
10秒前
秋风完成签到 ,获得积分10
10秒前
谢涛发布了新的文献求助10
11秒前
遇见完成签到,获得积分10
11秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Aerospace Standards Index - 2026 ASIN2026 3000
Polymorphism and polytypism in crystals 1000
Signals, Systems, and Signal Processing 610
Discrete-Time Signals and Systems 610
Research Methods for Business: A Skill Building Approach, 9th Edition 500
Social Work and Social Welfare: An Invitation(7th Edition) 410
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6052189
求助须知:如何正确求助?哪些是违规求助? 7865844
关于积分的说明 16273042
捐赠科研通 5197486
什么是DOI,文献DOI怎么找? 2781039
邀请新用户注册赠送积分活动 1763922
关于科研通互助平台的介绍 1645892