A Criminological Perspective on Power Grid Cyber attacks: Using Routine Activities Theory to Rational Choice Perspective to Explore Adversarial Decision-Making

A Criminological Perspective on Power Grid Cyber attacks: Using Routine Activities Theory to Rational Choice Perspective to Explore Adversarial Decision-Making
复制标题

DOI:
10.1515/jhsem-2013-0061
复制
发表时间:
2014-06
影响因子:
0.8
通讯作者:
Aunshul Rege
Aunshul Rege
中科院分区:
管理学4区
文献类型:
--
作者:
Aunshul Rege

文献摘要

被引文献

相似文献

摘要美国电网已被安全专家确定为恐怖分子和国家支持的网络攻击的主要目标。除了破坏电网,网络攻击还可以破坏和操纵数据系统,获取敏感的知识产权并窃取商业机密。现有的研究已经解决了导致网络攻击的技术因素,例如漏洞和糟糕的入侵检测系统。然而,它对网络攻击等式中的人为因素保持沉默。本研究使用犯罪学框架,特别是常规活动理论和理性选择的角度来捕捉智能对手谁计划和执行攻击的基础上,他们的目标适合性和监护效力的分析。它使用两步方法来确定共同影响决策过程的对手,目标和具体的因素。首先,对现有文献的文档分析揭示了影响对抗性决策的九个因素(帕雷风险):预防措施,攻击和联盟,结果,访问便利性,响应和恢复,互联性和相互依赖性,安全测试,评估和审计,知识,技能,研究和开发以及系统弱点。其次,2010年至2012年期间对各种黑客、渗透测试人员和电网代表进行的调查和访谈有助于验证和完善帕雷RISKS框架。这项研究确定了(i)具体的不利因素,如资源(技能、资金和时间)和研究(目标和技术);(ii)具体的目标因素,如可访问性(电子和物理)和弱点(过时的架构和不充分的测试/更新);(iii)具体的不利因素,如预防(预防和入侵检测措施的质量)。它认为,改变日常活动理论的这三个要素中的每一个都可以影响对抗性决策,这可能有助于降低电网网络攻击的可能性。
Abstract The US power grid has been identified by security experts as a prime target for terrorist-based and state-sponsored cyber attacks. In addition to downing the grid, cyber attacks can also destroy and manipulate data systems, obtain sensitive intellectual property and steal trade secrets. Existing research has addressed the technical factors, such as vulnerabilities and poor intrusion detection systems, which lead to cyber attacks. However, it remains silent on the human factors in the cyber attack equation. This study uses a criminological framework, specifically Routine Activities Theory and Rational Choice Perspective to capture intelligent adversaries who plan and execute attacks based on their analysis of target suitability and guardianship efficacy. It uses a two-step methodology to identify adversary-, target-, and guardianship-specific factors that collectively impact decision-making processes. First, a document analysis of existing literature reveals nine factors (PARE RISKS) that influence adversarial decision-making: Prevention measures, Attacks and Alliances, Results, Ease of Access, Response and Recovery, Interconnectedness and Interdependencies, Security Testing, Assessments and Audits, Knowledge, Skills, Research and Development, and System Weaknesses. Second, surveys and interviews conducted between 2010 and 2012 with various hackers, penetration testers, and power grid representatives helps validate and refine the PARE RISKS framework. This study identifies (i) adversary-specific factors as resources (skills, money, and time), and research (targets and techniques); (ii) target-specific factors as accessibility (electronic and physical) and weaknesses (outdated architecture and inadequate testing/updates); and (iii) guardian-specific factors as prevention (quality of prevention and intrusion detection measures). It argues that altering each of these three elements of Routine Activities Theory can impact adversarial decision-making, which may help reduce the likelihood of power grid cyber attacks.