首页> 外文期刊>Computers & Security >A safety/security risk analysis approach of Industrial Control Systems: A cyber bowtie -combining new version of attack tree with bowtie analysis
【24h】

A safety/security risk analysis approach of Industrial Control Systems: A cyber bowtie -combining new version of attack tree with bowtie analysis

机译:工业控制系统的安全风险分析方法:网络领结-将攻击树的新版本与领结分析相结合

获取原文
获取原文并翻译 | 示例

摘要

The introduction of connected systems and digital technology in process industries creates new cyber-security vulnerabilities that can be exploited by sophisticated threats and lead to undesirable safety accidents. Thus, identifying these vulnerabilities during risk analysis becomes an important part for effective industrial risk evaluation. However, nowadays, safety and security are analyzed separately when they should not be. This is because a security threat can lead to the same dangerous phenomenon as a safety incident. In this paper, a new method that considers safety and security together during industrial risk analysis is proposed. This approach combines bowtie analysis, commonly used for safety analysis, with a new extended version of attack tree analysis, introduced for security analysis of industrial control systems. The combined use of bowtie and attack tree provides an exhaustive representation of risk scenarios in terms of safety and security. We then propose an approach for evaluating the risk level based on two-term likelihood parts, one for safety and one for security. The application of this approach is demonstrated using the case study of a risk scenario in a chemical facility.
机译:流程行业中将连接的系统和数字技术引入会产生新的网络安全漏洞,这些漏洞可以被复杂的威胁利用并导致不良的安全事故。因此,在风险分析过程中识别这些漏洞成为有效的工业风险评估的重要组成部分。但是,如今,安全性和安全性在不应该进行单独分析时会进行分析。这是因为安全威胁可能导致与安全事件相同的危险现象。本文提出了一种在工业风险分析中同时考虑安全性的新方法。这种方法将通常用于安全性分析的领结分析与为工业控制系统的安全性分析引入的攻击树分析的新扩展版本相结合。领结和攻击树的组合使用在安全性方面全面描述了风险情况。然后,我们提出了一种基于两个可能性部分的风险评估方法,一个是安全性,另一个是安全性。通过对某化工设施中的风险情景进行案例研究,证明了该方法的应用。

著录项

  • 来源
    《Computers & Security》 |2018年第1期|175-195|共21页
  • 作者单位

    Univ. Grenoble Alpes, CNRS, Grenoble INP. G-SCOP, F-38000 Grenoble, France;

    Univ. Grenoble Alpes, CNRS, Grenoble INP. G-SCOP, F-38000 Grenoble, France;

    Univ. Grenoble Alpes, CNRS, Grenoble INP. G-SCOP, F-38000 Grenoble, France;

    INERIS, Parc technologique Alata BP 2, F-60 550 Verneuil-en-Halatte, France;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Risk analysis; Safety; Cyber-security; Bowtie analysis; Attack-Tree analysis; SCADA;

    机译:风险分析;安全;网络安全;领结分析;攻击树分析;SCADA;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号