Vis enkel innførsel

dc.contributor.authorSpathoulas, Georgios
dc.contributor.authorKavallieratos, Georgios
dc.contributor.authorKatsikas, Sokratis
dc.contributor.authorBaiocco, Alessio
dc.date.accessioned2023-03-31T08:33:32Z
dc.date.available2023-03-31T08:33:32Z
dc.date.created2022-02-10T18:42:32Z
dc.date.issued2022
dc.identifier.isbn978-3-030-95483-3
dc.identifier.urihttps://hdl.handle.net/11250/3061338
dc.description.abstractThe increasing integration of information technology with operational technology leads to the formation of Cyber-Physical Systems (CPSs) that intertwine physical and cyber components and connect to each other. This interconnection enables the offering of functionality beyond the combined offering of each individual component, but at the same time increases the cyber risk of the overall system, as such risk propagates between and aggregates at component systems. The complexity of the resulting systems in many cases leads to difficulty in analyzing cyber risk. Additionally, the selection of cybersecurity controls that will effectively and efficiently treat the cyber risk is commonly performed manually, or at best with limited automated decision support. In this paper, we extend our previous work in [1] to analyze attack paths between CPSs on one hand, and we improve the method proposed therein for selecting a set of security controls that minimizes both the residual risk and the cost of implementation. We use the DELTA demand-response management platform for the energy market stakeholders such as Aggregators and Retailers [2] as a use case to illustrate the workings of the proposed approaches. The results are sets of cybersecurity controls applied to those components of the overall system that have been identified to lie in those attack paths that have been identified as most critical among all the identified attack paths.en_US
dc.language.isoengen_US
dc.publisherSpringeren_US
dc.relation.ispartofComputer Security. ESORICS 2021 International Workshops CyberICPS, SECPRE, ADIoT, SPOSE, CPS4CIP, and CDT&SECOMANE, Darmstadt, Germany, October 4–8, 2021, Revised Selected Papers
dc.titleAttack Path Analysis and Cost-Efficient Selection of Cybersecurity Controls for Complex Cyberphysical Systemsen_US
dc.title.alternativeAttack Path Analysis and Cost-Efficient Selection of Cybersecurity Controls for Complex Cyberphysical Systemsen_US
dc.typeChapteren_US
dc.description.versionacceptedVersionen_US
dc.source.pagenumber74-90en_US
dc.identifier.doi10.1007/978-3-030-95484-0_5
dc.identifier.cristin2000212
dc.relation.projectNorges forskningsråd: 310105en_US
cristin.ispublishedtrue
cristin.fulltextpostprint
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel