Risk analysis of cyber vulnerabilities in water distribution industrial control systems
نویسندگان
چکیده
Cyber attacks are an emerging threat to critical infrastructure systems worldwide. We focus on water, recognizing that water is vital for human health and to the function of other critical infrastructures. A cyber attack targets control and monitoring systems of a water utility, known as supervisory control and data acquisition (SCADA) systems, and disrupts water operations. Current research is inadequate in developing critical risk assessments using scenario based risk metrics to characterize vulnerabilities in the SCADA networks. Such work forms the basis for a risk-informed management process. This research constructs a scenario-based risk assessment of water treatment and distribution system cybervulnerabilities. We identify vulnerable elements of the network, conduct a failure analysis, and create fault trees for a selected set of cyber intrusion scenarios. Future research will focus on expert elicitation of probabilities of failure of selected events, with the goal of informing decision makers about risk management and mitigation strategies. cating value of cyber protection to water industry leaders.
منابع مشابه
Determining Risks from Advanced Multi-step Attacks to Critical Information Infrastructures
Industrial Control Systems (ICS) monitor and control industrial processes, and enable automation in industry facilities. Many of these facilities are regarded as Critical Infrastructures (CIs). Due to the increasing use of Commercial-Off-The-Shelf (COTS) IT products and connectivity offerings, CIs have become an attractive target for cyberattacks. A successful attack could have significant cons...
متن کاملControl-Theoretic Methods for Cyber-Physical Security
Cyber-physical systems integrate physical processes, computational resources, and communication capabilities. Cyber-physical systems have permeated modern society becoming prevalent in many domains including energy production, health care, and telecommunications. Examples of cyber-physical systems include sensor networks, industrial automation systems , and critical infrastructures such as tran...
متن کاملCritical review of cybersecurity protection procedures and practice in water distribution systems
The objective of this paper is to conduct a critical review of cybersecurity procedures and practices in the water distribution sector. Specifically, this paper provides a characterization of the current state of cybersecurity practice and risk management in drinking water systems. This characterization is critically important due to the number of cyber attacks that have occurred against water ...
متن کاملForensic Attacks Analysis and the Cyber Security of Safety-Critical Industrial Control Systems
Industrial Control Systems (ICS) and SCADA (Supervisory Control And Data Acquisition) applications monitor and control a wide range of safety-related functions. These include energy generation where failures could have significant, irreversible consequences. They also include the control systems that are used in the manufacture of safety-related products. In this case bugs in an ICS/SCADA syste...
متن کاملCyber-Physical Control Systems: Vulnerabilities, Threats, and Mitigations
Cyber-Physical Systems (CPS) are yielding novel problems and solutions for security researchers. CPSs connect computerized controllers and human supervisors with physical systems used in the energy, transportation, water, manufacturing, and other sectors. A recent and well-known attack is the Stuxnet computer worm [1], which targeted Siemens industrial software used to control nuclear fuel proc...
متن کامل