Determining Risks from Advanced Multi-step Attacks to Critical Information Infrastructures

Determining Risks from Advanced Multi-step Attacks to Critical Information Infrastructures
复制标题

确定对关键信息基础设施的高级多步攻击的风险

DOI:
--
复制
发表时间:
2013
期刊:
Critical Information Infrastructures Security
影响因子:
--
通讯作者:
Paul Smith
Paul Smith
中科院分区:
--
文献类型:
--
作者:
Zhendong Ma;Paul Smith

文献摘要

被引文献

相似文献

工业控制系统(ICS)监控工业过程,并实现工业设施的自动化。这些设施中的许多设施被视为关键的可重构结构(CI)。由于商用现成(COTS)IT产品和连接产品的使用越来越多,CI已成为网络攻击的一个有吸引力的目标。一次成功的袭击可能会造成严重后果。保护关键信息基础设施(CII)免受网络攻击的重要一步是风险分析--基于对与目标系统相关的漏洞、网络威胁和影响的信息的系统分析,了解安全风险。现有的风险分析方法存在着可扩展性和实用性等问题。与以前的工作相比,我们提出了一种实用的和以能力为中心的风险分析方法,用于确定与高级多步骤网络攻击相关的安全风险。为了研究利用漏洞链的多步攻击,我们将漏洞映射到前提条件和效果,并使用基于规则的推理来识别高级攻击及其通过CII的路径。
Industrial Control Systems (ICS) monitor and control industrial processes, and enable automation in industry facilities. Many of these facilities are regarded as Critical Infrastructures (CIs). Due to the increasing use of Commercial-Off-The-Shelf (COTS) IT products and connectivity offerings, CIs have become an attractive target for cyber-attacks. A successful attack could have significant consequences. An important step in securing Critical Information Infrastructures (CIIs) against cyber-attacks is risk analysis – understanding security risks, based on a systematic analysis of information on vulnerabilities, cyber threats, and the impacts related to the targeted system. Existing risk analysis approaches have various limitations, such as scalability and practicability problems. In contrast to previous work, we propose a practical and vulnerability-centric risk analysis approach for determining security risks associated with advanced, multi-step cyber-attacks. In order to examine multi-step attacks that exploit chains of vulnerabilities, we map vulnerabilities into preconditions and effects, and use rule-based reasoning for identifying advanced attacks and their path through a CII.