首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >Cyber Risk Propagation and Optimal Selection of Cybersecurity Controls for Complex Cyberphysical Systems
【2h】

Cyber Risk Propagation and Optimal Selection of Cybersecurity Controls for Complex Cyberphysical Systems

机译:网络风险传播和复杂环形物理系统的网络安全控制的最佳选择

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The increasingly witnessed integration of information technology with operational technology leads to the formation of Cyber-Physical Systems (CPSs) that intertwine physical and cyber components and connect to each other to form systems-of-systems. This interconnection enables the offering of functionality beyond the combined offering of each individual component, but at the same time increases the cyber risk of the overall system, as such risk propagates between and aggregates at component systems. The complexity of the resulting systems-of-systems in many cases leads to difficulty in analyzing cyber risk. Additionally, the selection of cybersecurity controls that will effectively and efficiently treat the cyber risk is commonly performed manually, or at best with limited automated decision support. In this work, we propose a method for analyzing risk propagation and aggregation in complex CPSs utilizing the results of risk assessments of their individual constituents. Additionally, we propose a method employing evolutionary programming for automating the selection of an optimal set of cybersecurity controls out of a list of available controls, that will minimize the residual risk and the cost associated with the implementation of these measures. We illustrate the workings of the proposed methods by applying them to the navigational systems of two variants of the Cyber-Enabled Ship (C-ES), namely the autonomous ship and the remotely controlled ship. The results are sets of cybersecurity controls applied to those components of the overall system that have been identified in previous studies as the most vulnerable ones; such controls minimize the residual risk, while also minimizing the cost of implementation.
机译:具有操作技术的信息技术的日益目睹了信息技术的集成导致网络 - 物理系统(CPSS),其互动地互相连接并彼此连接以形成系统系统。该互连使得能够提供超出每个单独组件的组合产品的功能,但同时增加整个系统的网络风险,因为这种风险在组件系统之间传播和聚集在一起。在许多情况下产生的系统系统的复杂性导致分析网络风险的困难。另外,通常可以手动地和有效地治疗网络风险的网络安全控制的选择,或者最适合使用有限的自动决策支持。在这项工作中,我们提出了一种利用其个体成分的风险评估的结果分析复杂CPS中的风险传播和聚集方法。此外,我们提出了一种采用进化编程的方法,用于自动化选择最佳的网络安全集合从可用控制列表中的控制,这将最大限度地减少残余风险和与实现这些措施的实现相关的成本。我们通过将它们应用于网络发货(C-ES)的两个变体的导航系统,即自主船和远程控制的船舶来说明所提出的方法的运作。结果是应用于以前研究的整个系统的那些组件作为最脆弱的人的组件的网络安全控制;这种控制最小化残余风险,同时还最小化实现成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号