Achieving Cyber-Informed Engineering Through Bayesian Belief Network and Sensitivity Analysis

Achieving Cyber-Informed Engineering Through Bayesian Belief Network and Sensitivity Analysis
复制标题

DOI:
10.1109/dsa59317.2023.00039
复制
发表时间:
2023-08
期刊:
2023 10th International Conference on Dependable Systems and Their Applications (DSA)
影响因子:
--
通讯作者:
C. Agbo;Hoda Mehrpouyan
C. Agbo;Hoda Mehrpouyan
中科院分区:
其他
文献类型:
--
作者:
C. Agbo;Hoda Mehrpouyan

文献摘要

相似文献

关键基础设施的安全是当今国家和国家面临的一项挑战,因为这些系统及其远程控制的复杂性和互连性增加。确保关键系统的安全需要设计与网络安全相关的风险,攻击者可以利用这些风险来造成严重后果,如设备损坏、环境/水污染、金钱损失,甚至生命损失。重要的是要确定可能导致严重后果事件(HCE)的行动或攻击并确定其优先顺序,这些事件可能会削弱任何组织的关键职能。在这项工作中,我们提出了一种新的网络安全风险评估方法,提出了后果驱动的网络信息工程(CCE)方法和带有敏感度分析的贝叶斯信念网络(BBN)。为了验证概念,我们在田纳西州伊士曼化工厂测试了建议的方法,并能够发现关键基础设施上的干扰或噪声导致的攻击所造成的连锁反应,并确定其优先顺序。
The security of critical infrastructures is a challenge facing nations and states today as a result of the increased complexity and interconnectivity of these systems and their control from remote locations. Ensuring the security of critical systems requires engineering cybersecurity-related risks that attackers can exploit to cause severe consequences, such as equipment damage, environmental/water pollution, monetary loss, or even loss of life. It is important to identify and prioritize actions or attacks that can lead to high-consequence events (HCEs) capable of crippling critical functions of any organization. In this work, we proposed a new approach to cybersecurity risk assessment by proposing the Consequence-Driven Cyber-Informed Engineering (CCE) approach and the Bayesian Belief Network (BBN) with Sensitivity Analysis (SA). For proof of concept, we tested the proposed approach at the Tennessee Eastman chemical plant and were able to uncover and prioritize ripple effects caused by disturbance or noise-induced attacks on critical infrastructure.