Aller au contenu principal
2018 conference-paper

A Study on Quantitative Risk Assessment Methods in Security Design for Industrial Control Systems

6Citations signalées, ce qui n’est pas une note de qualité
2Institutions déclarées
1Pays d’affiliation déclarés

Rattachement africain : jp. Niveau de preuve : code pays fourni par la source.

Le résumé fourni par la source

In recent years, there has been progress in applying information technology to industrial control systems (ICS), which is expected to make the development cost of control devices and systems lower. On the other hand, the security threats are becoming important problems. In 2017, a command injection issue on a data logger was reported. In this paper, we focus on the risk assessment in security design for data loggers used in industrial control systems. Our aim is to provide a risk assessment method optimized for control devices and systems in such a way that one can prioritize threats more preciously, that would lead work resource (time and budget) can be assigned for more important threats than others. We discuss problems with application of the automotive-security guideline of JASO TP15002 to ICS risk assessment. Consequently, we propose a three-phase risk assessment method with a novel Risk Scoring Systems (RSS) for quantitative risk assessment, RSS-CWSS. The idea behind this method is to apply CWSS scoring systems to RSS by fixing values for some of CWSS metrics, considering what the designers can evaluate during the concept phase. Our case study with ICS employing a data logger clarifies that RSS-CWSS can offer an interesting property that it has better risk-score dispersion than the TP15002-specified RSS.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Le contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
A Study on Quantitative Risk Assessment Methods in Security Design for Industrial Control Systems
Date Crossref
01/08/2018
Éditeur
IEEE
Type
proceedings-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.

Où se fait cette recherche

  • National Institute of Advanced Industrial Science and Technology pays non établi dans la notice
    Organisme public
  • Sumitomo Electric Industries (Japan) pays non établi dans la notice
    Entreprise
  • SEI-AIST Cyber Security Cooperative Research Laboratory pays non établi dans la notice
    Structure de recherche
  • Ltd. Cyber-Security R&D Office Sumitomo Electric Industries pays non établi dans la notice
    Entreprise

National Institute of Advanced Industrial Science and Technology, Sumitomo Electric Industries (Japan) et SEI-AIST Cyber Security Cooperative Research Laboratory, avec 1 autre affiliation.

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Les sujets associés

Safety Systems Engineering in AutonomyInformation and Cyber SecuritySmart Grid Security and Resilience

BNTIC News n’est pas le producteur de ces données. Les publications sont interrogées à la demande dans Crossref, OpenAIRE, DOAJ, Europe PMC, HAL, DataCite, AfricArXiv, ROR et la Banque mondiale, sans clé d’accès. OpenAlex reste optionnel. Aucun service payant n’est nécessaire et aucune donnée externe n’est enregistrée en base. Consulter les sources et leurs limites.