Exploring Ontologies for Mitigation Selection of Industrial Control System Vulnerabilities

Exploring Ontologies for Mitigation Selection of Industrial Control System Vulnerabilities
复制标题

DOI:
10.34190/iccws.17.1.32
复制
发表时间:
2022-03
期刊:
International Conference on Cyber Warfare and Security
影响因子:
--
通讯作者:
T. Heverin;Michael Cordano;Andy Zeyher;Matthew Lashner;Sanjana Suresh
T. Heverin;Michael Cordano;Andy Zeyher;Matthew Lashner;Sanjana Suresh
中科院分区:
其他
文献类型:
--
作者:
T. Heverin;Michael Cordano;Andy Zeyher;Matthew Lashner;Sanjana Suresh

文献摘要

相似文献

减轻工业控制系统(ICS)中的漏洞是一项非常复杂的任务。ICS可能包含大量的设备类型,所有这些设备都具有独特的软件和硬件组件。在发现ICS设备上的漏洞后,网络防御者必须确定要实施哪些缓解措施,以及哪些缓解措施可以应用于多个漏洞。网络防御者需要优化缓解选择的技术。这篇探索性研究论文展示了本体(也称为链接数据模型)如何潜在地用于对ICS设备、漏洞和缓解措施进行建模,以及如何识别可以修复或缓解多个漏洞的缓解措施。本体可以用来降低网络防御者的角色的复杂性,通过允许洞察被绘制,特别是在ICS域。数据模型来自通用平台枚举(CPE),国家漏洞数据库(NVD),国家标准与技术研究所(NIST)的标准化控制列表以及ICS网络应急响应小组(CERT)。语义查询提供了缓解优先级的技术。一个案例研究描述了选定的可编程逻辑控制器(PLC),其已知的漏洞从NVD,并建议缓解ICS CERT。总的来说,这项研究显示了本体如何可以用来链接现有的数据源,运行查询的链接数据,并允许新的见解,以减轻选择绘制。
Mitigating vulnerabilities in industrial control systems (ICSs) represents a highly complex task. ICSs may contain an abundance of device types, all with unique software and hardware components. Upon discovering vulnerabilities on ICS devices, cyber defenders must determine which mitigations to implement, and which mitigations can apply across multiple vulnerabilities. Cyber defenders need techniques to optimize mitigation selection. This exploratory research paper shows how ontologies, also known as linked-data models, can potentially be used to model ICS devices, vulnerabilities, and mitigations, as well as to identify mitigations that can remediate or mitigate multiple vulnerabilities. Ontologies can be used to reduce the complexity of a cyber defender’s role by allowing for insights to be drawn, especially in the ICS domain. Data are modelled from the Common Platform Enumeration (CPE), the National Vulnerability Database (NVD), standardized list of controls from the National Institute of Standards and Technology (NIST), and ICS Cyber Emergency Response Team (CERT) advisories. Semantic queries provide the techniques for mitigation prioritization. A case study is described for a selected programmable logic controller (PLC), its known vulnerabilities from the NVD, and recommended mitigations from ICS CERT. Overall, this research shows how ontologies can be used to link together existing data sources, to run queries over the linked data, and to allow for new insights to be drawn for mitigation selection.