Published May 12, 2020 | Version v1
Journal article Open

Measuring cyber-physical security in industrial control systems via minimum-effort attack strategies

Description

In recent years, Industrial Control Systems (ICS) have become increasingly exposed to a wide range of cyber-physical attacks, having massive destructive consequences. Security metrics are therefore essential to assess and improve their security posture. In this paper, we present a novel ICS security metric based on AND/OR graphs and hypergraphs which is able to efficiently identify the set of critical ICS components and security measures that should be compromised, with minimum cost (effort) for an attacker, in order to disrupt the operation of vital ICS assets. Our tool, META4ICS (pronounced as metaphorics), leverages state-of-the-art methods from the field of logical satisfiability optimisation and MAX-SAT techniques in order to achieve efficient computation times. In addition, we present a case study where we have used our system to analyse the security posture of a realistic Water Transport Network (WTN).

Notes

2020 Elsevier Ltd. copyrights. The final publication is available at www.sciencedirect.com via https://doi.org/10.1016/j.jisa.2020.102471. M. Barrère, C. Hankin, N. Nicolaou, D. G. Eliades, and T. Parisini, Measuring cyber-physical security in industrial control systems via minimum-effort attack strategies, Journal of Information Security and Applications, Volume 52, 2020, doi: 10.1016/j.jisa.2020.102471.

Files

10.1016j.jisa.2020.102471.pdf

Files (1.6 MB)

Name Size Download all
md5:7b0581e9cbe83b7457f60668871ba786
1.6 MB Preview Download

Additional details

Funding

European Commission
KIOS CoE – KIOS Research and Innovation Centre of Excellence 739551