DocumentCode :
1945941
Title :
Cyber/physical security vulnerability assessment integration
Author :
Macdonald, Daniel ; Clements, S.L. ; Patrick, S.W. ; Perkins, Colin ; Muller, Gunter ; Lancaster, Michael J. ; Hutton, W.
Author_Institution :
Pacific Northwest Nat. Lab. Richland, Richland, WA, USA
fYear :
2013
fDate :
24-27 Feb. 2013
Firstpage :
1
Lastpage :
6
Abstract :
Securing high value and critical assets is one of the biggest challenges facing this nation and others around the world. In modern integrated systems, there are four potential modes of attack available to an adversary: 1 physical only attack, 2 cyber only attack, 3 physical-enabled cyber attack, 4 cyber-enabled physical attack. Blended attacks involve an adversary working in one domain to reduce system effectiveness in another domain. This enables the attacker to penetrate further into the overall layered defenses. Existing vulnerability assessment (VA) processes and software tools which predict facility vulnerabilities typically evaluate the physical and cyber domains separately. Vulnerabilities which result from the integration of cyber-physical control systems are not well characterized and are often overlooked by existing assessment approaches. In this paper, we modified modification of the timely detection methodology, used for decades in physical security VAs, to include cyber components. The Physical and Cyber Risk Analysis Tool (PACRAT) prototype illustrates an integrated vulnerability assessment that includes cyber-physical interdependencies. Information about facility layout, network topology, and emplaced safeguards is used to evaluate how well suited a facility is to detect, delay, and respond to attacks, to identify the pathways most vulnerable to attack, and to evaluate how often safeguards are compromised for a given threat or adversary type. We have tested the PACRAT prototype on critical infrastructure facilities and the results are promising. Future work includes extending the model to prescribe the recommended security improvements via an automated cost-benefit analysis.
Keywords :
cost-benefit analysis; critical infrastructures; risk analysis; security of data; PACRAT; Physical and Cyber Risk Analysis Tool; attack delay; attack detection; attack response; automated cost-benefit analysis; blended attack; critical asset security; critical infrastructure facility; cyber components; cyber only attack; cyber-enabled physical attack; cyber-physical control system; cyber-physical interdependency; cyber-physical security vulnerability assessment integration; emplaced safeguard; facility layout; facility vulnerability prediction; high value asset security; layered defense; network topology; physical only attack; physical-enabled cyber attack; security improvement; software tool; system effectiveness reduction; Analytical models; Computational modeling; Computer security; Delays; Organizations; Software tools; Modeling; Power Industry; Risk analysis; Security; Simulation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Innovative Smart Grid Technologies (ISGT), 2013 IEEE PES
Conference_Location :
Washington, DC
Print_ISBN :
978-1-4673-4894-2
Electronic_ISBN :
978-1-4673-4895-9
Type :
conf
DOI :
10.1109/ISGT.2013.6497883
Filename :
6497883
Link To Document :
بازگشت