TY - GEN
T1 - Risk assessment method for cybersecurity of cyber-physical systems based on inter-dependency of vulnerabilities
AU - Wu, Wenbo
AU - Kang, Rui
AU - Li, Zi
N1 - Publisher Copyright:
© 2015 IEEE.
PY - 2016/1/18
Y1 - 2016/1/18
N2 - As cyber physical systems are used more extensively and thoroughly, cyber-attacks have become one of the utmost threats to the cybersecurity of cyber physical systems (CPS). It is possible that an adversary can damage a physical component with cyber-attacks (eg. The Stuxnet). Although many research has been done on risk assessment method, limited work has been published to quantify cybersecurity risk of CPS. This paper suggests a method to quantify the cybersecurity risk of CPS caused by cyber-attacks in terms of numeric value. To help quantitatively measure the risk, we present two indices, the successful-attack-probability index and the attack-impact index, based on vulnerability dependency graph. Furthermore, the successful-attack-probability index is calculated considering the interdependent relationship between vulnerabilities and the calculation of attack-impact index takes the impact on the physical domain resulting from cyber-attacks into account. Numerical example shows that the potential risk of system and the optimal attack target can be obtained. The proposed method can be extended to security investment analysis as well.
AB - As cyber physical systems are used more extensively and thoroughly, cyber-attacks have become one of the utmost threats to the cybersecurity of cyber physical systems (CPS). It is possible that an adversary can damage a physical component with cyber-attacks (eg. The Stuxnet). Although many research has been done on risk assessment method, limited work has been published to quantify cybersecurity risk of CPS. This paper suggests a method to quantify the cybersecurity risk of CPS caused by cyber-attacks in terms of numeric value. To help quantitatively measure the risk, we present two indices, the successful-attack-probability index and the attack-impact index, based on vulnerability dependency graph. Furthermore, the successful-attack-probability index is calculated considering the interdependent relationship between vulnerabilities and the calculation of attack-impact index takes the impact on the physical domain resulting from cyber-attacks into account. Numerical example shows that the potential risk of system and the optimal attack target can be obtained. The proposed method can be extended to security investment analysis as well.
KW - cyber-physical system
KW - cybersecurity
KW - risk assessment
KW - vulnerability inter-dependency graph
UR - https://www.scopus.com/pages/publications/84962032602
U2 - 10.1109/IEEM.2015.7385921
DO - 10.1109/IEEM.2015.7385921
M3 - 会议稿件
AN - SCOPUS:84962032602
T3 - IEEE International Conference on Industrial Engineering and Engineering Management
SP - 1618
EP - 1622
BT - IEEM 2015 - 2015 IEEE International Conference on Industrial Engineering and Engineering Management
PB - IEEE Computer Society
T2 - IEEE International Conference on Industrial Engineering and Engineering Management, IEEM 2015
Y2 - 6 December 2015 through 9 December 2015
ER -