首页> 外文会议>International Conference on Cyber Conflict >Call to Action: Mobilizing Community Discussion to Improve Information-Sharing About Vulnerabilities in Industrial Control Systems and Critical Infrastructure
【24h】

Call to Action: Mobilizing Community Discussion to Improve Information-Sharing About Vulnerabilities in Industrial Control Systems and Critical Infrastructure

机译:致电行动:调动社区讨论,以改善关于工业控制系统和关键基础设施的漏洞的信息共享

获取原文

摘要

Vulnerability management remains a significant challenge for organizations that handle critical infrastructure worldwide. Hallmark cyber-physical incidents with disruptive and destructive capabilities like Stuxnet (2010) and Triton (2017) have exploited known vulnerabilities in information technology (IT) and operational technology (OT) assets throughout the attack lifecycle. However, the global critical infrastructure security community is still nascent in the field of industrial control systems (ICS) vulnerability management, especially in information-sharing. While their counterparts in IT security have spent years elaborating multiple resources to track and disseminate information about known vulnerabilities, the ICS community lacks specialized mechanisms for knowledge-sharing. Multiple challenges exist when addressing this issue: a general lack of awareness about ICS cybersecurity, the need to consider multiple industry sectors and unique network architectures, and the need to find a balance between protecting and releasing sensitive information regarding critical infrastructure organizations or proprietary vendor knowledge. Through a multiphase research initiative based on the user-centered design process, we intend to test and evaluate the feasibility and effectiveness of various information-sharing platform designs for streamlining the discussion of ICS vulnerabilities. In the first phase of this research, we surveyed ICS and critical infrastructure security stakeholders to gain insight into the range of cogent, shared, and divergent views of the community relating to the need for specialized resources to share information about ICS vulnerabilities. We then evaluated what these different perspectives imply for the adoption and success of certain information-sharing platform frameworks. Finally, utilizing these insights, we demonstrated possible alternative paths forward for addressing the challenge of sharing information about ICS vulnerabilities to keep critical infrastructure safe.
机译:漏洞管理仍然是在全球范围内处理关键基础设施的组织的重大挑战。具有破坏性和破坏性能力的标志性网络与STUXNET(2010)和TRITON(2017年)在整个攻击生命周期中利用信息技术(IT)和操作技术(OT)资产的已知漏洞。然而,全球关键基础设施安全社区仍然是工业控制系统(ICS)漏洞管理领域的新生,特别是在信息共享中。虽然其在IT安全中的同行符合多年的时间来阐述多个资源来跟踪和传播有关已知漏洞的信息,但IC社区缺乏知识共享的专业机制。解决此问题时存在多种挑战:对IC网络安全的一般缺乏意识,需要考虑多个行业和独特的网络架构,以及在保护和释放关于关键基础设施组织或专有供应商知识之间的保护和释放敏感信息之间的平衡。通过基于用户中心设计过程的多相研究计划,我们打算测试和评估各种信息共享平台设计的可行性和有效性,以简化IC漏洞的讨论。在本研究的第一阶段,我们调查了ICS和关键基础设施安全利益相关者,深入了解社区的社区的竞争,共享和不同意见的洞察,这是有关专业资源来分享ICS漏洞的信息。然后,我们评估了这些不同的观点暗示了某些信息共享平台框架的采用和成功。最后,利用这些洞察力,我们展示了解决有关分享有关IC漏洞信息以保持关键基础设施安全的挑战的可能替代路径。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号