MUMBA: Multi-faceted Metrics for ICS Business Risk Analysis
MUMBA: Multi-faceted Metrics for ICS Business Risk Analysis
批准号:
EP/M002780/1
负责人:
Awais Rashid
金额:
$50.19万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2014
资助国家:
英国
项目状态:
已结题
起止时间:
2014 至 --
中文摘要
网络空间的发展正在改变我们管理基础设施的方式。工业控制系统,即那些管理关键公用事业基础设施(如能源、水和交通)的系统,正日益以复杂的方式与企业IT系统进行交互。这导致对这些关键基础设施的威胁程度增加。这一点从网络武器(比如以伊朗核设施离心机为目标的震网病毒)和最近有消息称,超过6万个暴露的控制系统可以在网上访问)中再明显不过了。美国国防部长利昂·帕内塔(Leon Panetta)将最近针对关键基础设施的一连串网络攻击描述为“前9/11时刻”。未来几代控制系统的网络攻击面可能会随着新技术和工作实践的发展而进一步增加,例如在操作中使用自主软件代理,在控制和维护中使用手持无线设备。鉴于工业控制系统对社会的重要性,决策者能够有效地阐明网络空间给他们带来的风险是很重要的。更重要的是,决策者应该能够从业务连续性和恢复的角度理解和应对此类风险,以便评估其缓解措施并确定其优先次序。然而,到目前为止,在这种情况下阐明网络风险的指标在很大程度上是由与信息安全或控制系统本身的弹性相关的技术措施驱动的。尽管这些指标很重要,但它们与业务风险分析中使用的典型因素(如业务连续性、灾难恢复、成本、声誉、对资源的影响等)几乎没有关系。MUMBA项目认为,将网络风险(在工业控制系统中)表述为商业风险的度量标准,只有在我们理解的更大系统的背景下才有意义,如果没有这个系统的模型,就无法合理地设计。将安全性和弹性度量映射到业务风险的事后映射无法解释当前和未来几代控制系统所处的复杂社会技术环境。将网络风险有效地表述为商业风险需要多方面的指标,这些指标首先是由商业风险概念驱动的。这些指标考虑了工业控制系统设置的各个方面的业务风险,即控制系统本身、企业系统、业务流程、人员、产品/服务供应链中的第三方组织和新/新兴技术(以及相关的工作实践)。此外,该项目还需要将这些指标与特定的关键基础设施领域联系起来,以确保对业务风险进行有意义的解释,并确定响应的优先级和实现(即,是否要减轻、转移、接受或避免特定的风险)。该项目涉及来自兰开斯特安全研究中心的网络安全、弹性工业控制系统、风险管理和社会人类学领域的世界领先的多学科研究团队。四个行业合作伙伴:空中客车公司、泰雷兹公司、阿特金斯全球公司和雷神公司提供的实践见解补充了这一学术专长。通过对当代工业控制系统设置中复杂的社会技术过程、新指标以及如何利用这些环境来收集相关数据以计算这些指标的研究,该项目旨在成为未来研究和实践的基石,将网络风险表述为商业风险。
英文摘要
The evolution of cyber space is transforming the way our infrastructure is managed. Industrial control systems, that is those systems that manage critical utility infrastructure such as Energy, Water and Transport are increasingly interacting with enterprise IT systems in intricate fashions. This leads to an increase in the level of threats to these critical infrastructures. This is only too evident from cyber weapons such as Stuxnet which targeted centrifuges in Iran's nuclear facilities and more recent news that over 60,000 exposed control systems were accessible online. The US Defence Secretary Leon Panetta described a recent spate of cyber attacks against critical infrastructures as a "pre-9/11 moment". The cyber attack surface of future generations of control systems is likely to increase further with new technologies and working practices such as the use of autonomous software agents in their operation and handheld wireless devices in control and maintenance.Given the importance of industrial control systems to society, it is important that decision-makers are able to effectively articulate the risks posed to them from cyber space. Even more importantly, decision-makers should be able to understand and respond to such risks from a business continuity and recovery perspective in order to evaluate and prioritise their mitigation responses. However, to date, metrics for articulating cyber risk in such settings have largely been driven by technical measures pertaining to security of information or resilience of the control system itself. Though important, these metrics bear little relationship to typical factors used in business risk analysis, such as business continuity, disaster recovery, cost, reputation, impact on resources, etc. The MUMBA project takes the perspective that metrics for articulating cyber risk (in industrial control systems) as business risk only make sense in the context of what we understand the larger system to be, and cannot sensibly be designed without a model of this system. Post-hoc mapping of security and resilience metrics to business risk fails to account for the complex socio-technical landscape in which current and future generations of control systems reside. Effective articulation of cyber risk as business risk requires multi-faceted metrics that are first and foremost driven by business risk concepts. Such metrics consider business risk both along and across various facets of an industrial control system setting i.e., the control system itself, enterprise systems, business processes, people, third party organisations in the product/service supply chain and new/emergent technologies (and associated working practices). Furthermore, the project addresses the need to contextualise these metrics to a particular critical infrastructure domain to ensure meaningful interpretation of business risks and prioritisation and implementation of responses (i.e., whether to mitigate, transfer, accept or avoid particular risks).The project involves a world-leading multi-disciplinary team of researchers in cyber security, resilient industrial control systems, risk management and social anthropology from the Security Lancaster research centre. This academic expertise is complemented by practical insights provided by four industry partners: Airbus, Thales, Atkins Global and Raytheon. Through its research into the complex socio-technical processes at play in contemporary industrial control system settings, new metrics and how to instrument such environments to gather relevant data to compute such metrics, the project aims to become a cornerstone for future research and practice on articulating cyber risk as business risk.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
The Good, the Bad and the Ugly: A Study of Security Decisions in a Cyber-Physical Systems Game
好、坏、丑:网络物理系统博弈中安全决策的研究
DOI:
10.1109/tse.2017.2782813
发表时间:
2019
期刊:
IEEE Transactions on Software Engineering
影响因子:
7.4
作者:
[Frey S]
通讯作者:
Frey S
Contextualising and aligning security metrics and business objectives: A GQM-based methodology
将安全指标与业务目标结合起来并加以调整:基于 GQM 的方法
DOI:
10.1016/j.cose.2019.101634
发表时间:
2020
期刊:
Computers & Security
影响因子:
5.6
作者:
[Philippou E]
通讯作者:
Philippou E
CPS-SPC 2018
CPS-SPC 2018
DOI:
10.1145/3243734.3243874
发表时间:
2018
期刊:
影响因子:
--
作者:
[Rashid A]
通讯作者:
Rashid A
On the role of latent design conditions in cyber-physical systems security
潜在设计条件在网络物理系统安全中的作用
DOI:
10.1145/2897035.2897036
发表时间:
2016
期刊:
影响因子:
--
作者:
[Frey S]
通讯作者:
Frey S
DOI:
10.1007/978-3-658-14698-6_10
发表时间:
2017
期刊:
影响因子:
--
作者:
[Hißnauer, Christian]
通讯作者:
Christian
共 7 条
Securing Convergent Ultra-large Scale Infrastructures
-
批准号:EP/Z531315/1
-
项目类别:Research Grant
-
资助金额:$864.03万
-
财政年份:2024
-
负责人:Awais Rashid
-
依托单位:
Equitable privacy
-
批准号:EP/W025361/1
-
项目类别:Research Grant
-
资助金额:$129.56万
-
财政年份:2022
-
负责人:Awais Rashid
-
依托单位:
REPHRAIN: Research centre on Privacy, Harm Reduction and Adversarial Influence online
-
批准号:EP/V011189/1
-
项目类别:Research Grant
-
资助金额:$888.45万
-
财政年份:2020
-
负责人:Awais Rashid
-
依托单位:
Why Johnny doesn't write secure software? Secure software development by the masses
-
批准号:EP/P011799/2
-
项目类别:Research Grant
-
资助金额:$108.77万
-
财政年份:2018
-
负责人:Awais Rashid
-
依托单位:
DYPOSIT: Dynamic Policies for Shared Cyber-Physical Infrastructures under Attack
-
批准号:EP/N021657/2
-
项目类别:Research Grant
-
资助金额:$24.93万
-
财政年份:2018
-
负责人:Awais Rashid
-
依托单位:
Why Johnny doesn't write secure software? Secure software development by the masses
-
批准号:EP/P011799/1
-
项目类别:Research Grant
-
资助金额:$128.48万
-
财政年份:2017
-
负责人:Awais Rashid
-
依托单位:
DYPOSIT: Dynamic Policies for Shared Cyber-Physical Infrastructures under Attack
-
批准号:EP/N021657/1
-
项目类别:Research Grant
-
资助金额:$46.21万
-
财政年份:2015
-
负责人:Awais Rashid
-
依托单位:
Academic Centre of Excellence in Cyber Security Research - Lancaster University
-
批准号:EP/K003607/1
-
项目类别:Research Grant
-
资助金额:$6.3万
-
财政年份:2012
-
负责人:Awais Rashid
-
依托单位:
Industrial CASE Account - Lancaster 2010
-
批准号:EP/I501487/1
-
项目类别:Training Grant
-
资助金额:$25.55万
-
财政年份:2010
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P505585/1
-
项目类别:Training Grant
-
资助金额:$113.13万
-
财政年份:2010
-
负责人:Awais Rashid
-
依托单位:
Social Media, Social Good: Ultra-Large Scale Public Engagement Systems to Challenge Anti-Social Behaviour
-
批准号:EP/I016546/1
-
项目类别:Research Grant
-
资助金额:$25.53万
-
财政年份:2010
-
负责人:Awais Rashid
-
依托单位:
IDS - Lancaster University
-
批准号:EP/P505232/1
-
项目类别:Training Grant
-
资助金额:$8.41万
-
财政年份:2009
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P505194/1
-
项目类别:Training Grant
-
资助金额:$126.62万
-
财政年份:2009
-
负责人:Awais Rashid
-
依托单位:
Industrial CASE Account - Lancaster 2009
-
批准号:EP/H501347/1
-
项目类别:Training Grant
-
资助金额:$41.6万
-
财政年份:2009
-
负责人:Awais Rashid
-
依托单位:
ISIS: Protecting children in online social networks
-
批准号:EP/F035438/1
-
项目类别:Research Grant
-
资助金额:$54.85万
-
财政年份:2008
-
负责人:Awais Rashid
-
依托单位:
IDS - Lancaster University
-
批准号:EP/P504627/1
-
项目类别:Training Grant
-
资助金额:$1.78万
-
财政年份:2008
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P504708/1
-
项目类别:Training Grant
-
资助金额:$109.87万
-
财政年份:2008
-
负责人:Awais Rashid
-
依托单位:
IDS - Lancaster University
-
批准号:EP/P50368X/1
-
项目类别:Training Grant
-
资助金额:$3.82万
-
财政年份:2007
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P503825/1
-
项目类别:Training Grant
-
资助金额:$126.88万
-
财政年份:2007
-
负责人:Awais Rashid
-
依托单位:
VERA: Verifiable Aspect Models for Middleware Product Families (Visiting Fellowship)
-
批准号:EP/E005276/1
-
项目类别:Research Grant
-
资助金额:$2.48万
-
财政年份:2006
-
负责人:Awais Rashid
-
依托单位:
国内基金
海外基金
登录
查看更多内容
基于Multi-Pass Cell的高功率皮秒激光脉冲非线性压缩关键技术研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:宋贾俊
-
依托单位:
Multi-decadeurbansubsidencemonitoringwithmulti-temporaryPStechnique
-
批准号:--
-
项目类别:--
-
资助金额:80万元
-
批准年份:2022
-
负责人:Timo Balz
-
依托单位:
High-precision force-reflected bilateral teleoperation of multi-DOF hydraulic robotic manipulators
-
批准号:52111530069
-
项目类别:国际(地区)合作与交流项目
-
资助金额:10万元
-
批准年份:2021
-
负责人:徐兵
-
依托单位:
大地电磁强噪音压制的Multi-RRMC技术及其在青藏高原东南缘-印支块体地壳流追踪中的应用
-
批准号:--
-
项目类别:--
-
资助金额:15万元
-
批准年份:2021
-
负责人:白登海
-
依托单位:
基于8色荧光标记的Multi-InDel复合检测体系在降解混合检材鉴定的应用研究
-
批准号:82101976
-
项目类别:青年科学基金项目(C类)
-
资助金额:30.0万元
-
批准年份:2021
-
负责人:李介男
-
依托单位:
大规模非确定图数据分析及其Multi-Accelerator并行系统架构研究
-
批准号:62002350
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:张珩
-
依托单位:
3D multi-parameters CEST联合DKI对椎间盘退变机制中微环境微结构改变的定量研究
-
批准号:82001782
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:李丽
-
依托单位:
基于multi-SNP标记及不拆分策略的复杂混合样本身份溯源研究
-
批准号:--
-
项目类别:面上项目
-
资助金额:56万元
-
批准年份:2020
-
负责人:张素华
-
依托单位:
高速Multi-bit/cycle SAR ADC性能优化理论研究
-
批准号:62004023
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:庄浩宇
-
依托单位:
大地电磁强噪音压制的Multi-RRMC技术及其在青藏高原东南缘—印支块体地壳流追踪中的应用
-
批准号:--
-
项目类别:国际(地区)合作与交流项目
-
资助金额:--
-
批准年份:2020
-
负责人:白登海
-
依托单位: