首页> 外文会议>IFIP TC 11 International conference on information security and privacy >A Holistic Approach for Cyber Assurance of Critical Infrastructure with the Viable System Model
【24h】

A Holistic Approach for Cyber Assurance of Critical Infrastructure with the Viable System Model

机译:使用可行系统模型的关键基础设施网络保障的整体方法

获取原文

摘要

Industrial Control Systems (ICSs) are of the most important components of National Critical Infrastructure. They can provide control capabilities in complex systems of critical importance such as energy production and distribution, transportation, telecoms etc. Protection of such systems is the cornerstone of essential service provision with resilience and in timely manner. Effective risk management methods form the basis for the protection of an Industrial Control System. However, the nature of ICSs render traditional risk management methods insufficient. The proprietary character and the complex interrelationships of the various systems that form an ICS, the potential impacts outside its boundaries, along with emerging trends such as the exposure to the Internet, necessitate revisiting traditional risk management methods, in a way that treat an ICS as a system-of-systems rather than a single, one-off entity. Towards this direction, in this paper we present enhancements to the traditional risk management methods at the phase of risk assessment, by utilising the cybernetic construct of the Viable System Model (VSM) as a means towards a holistic view of the risks against Critical Infrastructure. For the purposes of our research, utilising VSM's recursive nature, we model the Supervisory Control and Data Acquisition (SCADA) system, a most commonly used ICS, as a VSM and identify the various assets, interactions with the internal and external environment, threats and vulnerabilities.
机译:工业控制系统(ICSs)是国家关键基础设施的最重要组成部分。它们可以在至关重要的复杂系统中提供控制功能,例如能源生产和分配,运输,电信等。对此类系统的保护是及时,灵活地提供基本服务的基石。有效的风险管理方法构成了保护工业控制系统的基础。但是,ICS的性质使传统的风险管理方法不足。构成ICS的各种系统的专有特性和复杂的相互关系,其边界之外的潜在影响以及新兴趋势(例如暴露于Internet)需要重新审视传统的风险管理方法,从而将ICS视为一个系统间的系统,而不是一个单一的实体。朝着这个方向发展,在本文中,我们通过利用可行系统模型(VSM)的控制论构建来全面了解针对关键基础设施的风险,从而在风险评估阶段对传统的风险管理方法进行了改进。为了我们的研究目的,利用VSM的递归性质,我们将最常用的ICS监督控制和数据采集(SCADA)系统建模为VSM,并识别各种资产,与内部和外部环境的交互,威胁和威胁。漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号