Vis enkel innførsel

dc.contributor.advisorGkioulos, Vasileios
dc.contributor.advisorKatsikas, Sokratis
dc.contributor.advisorSokolova, Nadezda
dc.contributor.advisorKansanen, Kimmo
dc.contributor.authorAmro, Ahmed
dc.date.accessioned2023-04-20T11:06:07Z
dc.date.available2023-04-20T11:06:07Z
dc.date.issued2023
dc.identifier.isbn978-82-326-5701-8
dc.identifier.issn2703-8084
dc.identifier.urihttps://hdl.handle.net/11250/3064022
dc.description.abstractRecent innovations in the smart city and the maritime domains have led to the proposition of a new mode of transportation utilizing Autonomous Passenger Ships (APS) or ferries in inland waterways. The novelty of the APS concept has raised a wide range of challenges regarding the interconnection of various components for the provisioning of navigational tasks. Additionally, the new mode of operation has influenced the cyber risk paradigm and led to different considerations regarding attack objectives, techniques as well as risk management approaches. Due to the fact that the APS technology is recent, defining the technical scope is the first challenge this thesis is addressing. This is sought through the identification of the APS expected operational context, relevant stakeholders, standards, guidelines, and functions. In addition to that, this thesis addresses the technical challenges related to interconnecting the APS components with their operational context in a secure and safe manner. This is sought through the definition of a suitable communication architecture for the APS and a cyber risk management process to develop a cybersecurity architecture capable of identifying and managing the cyber risks against the APS. To realize that, the design science research methodology (DSRM) is followed with a group of relevant system engineering standards and processes. At each phase of the research, the academic and industrial perspectives are gathered to design, develop, demonstrate and evaluate the artifacts that are needed for achieving the research objectives. The work in this thesis has resulted in the design, implementation, and evaluation of a suitable communication architecture for the APS technology supporting the current technology posture and includes flexible, modular, and resilient principles that designate it as candidate architecture for future iterations of the technology. Additionally, a suitable cyber risk management approach has been proposed and evaluated to measure its suitability for the APS technology. The cyber risk management approach named Threat Informed Defense in Depth (TIDiD) combines two cybersecurity strategies, namely, Threat Informed Defense and Defense in Depth. TIDiD includes a cyber risk assessment approach which is another result of this thesis. The approach is named FMECA-ATT&CK as it is based on the Failure mode, effects, and criticality analysis (FMECA) that is enhanced with the knowledge and semantics in the Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework. FMECA-ATT&CK supports the efforts for comprehensive and continuous cyber risk assessment and management through the identification of cyber risks in the APS components and proposes suitable risk mitigation measures. Then, later steps of TIDiD process aim to integrate the proposed risk mitigation measures into a cybersecurity architecture for risk analysis, monitoring, and treatment. Some areas were further explored including navigation data anomaly analysis and detection and the utility of the Automatic Identification System (AIS) in establishing covert channels for command and control activities during the development of cyber attacks. Each produced artifact was demonstrated and evaluated through a combination of evaluation methods including simulation, checklists, adversary emulation, and engagement of experts. Trials involving existing communication technologies have shown success for the APS as a novel maritime transportation technology. By using existing solutions and processes, including those in this thesis, the security of the system has been enhanced. There are still many areas that require additional attention in order to improve the capabilities of remote monitoring and the cybersecurity posture of the APS. Therefore, APS technology and similar maritime technologies are worthy of exploration in the future.en_US
dc.language.isoengen_US
dc.publisherNTNUen_US
dc.relation.ispartofseriesDoctoral theses at NTNU;2023:137
dc.relation.haspartPaper 1: Amro, Ahmed Walid; Gkioulos, Vasileios; Katsikas, Sokratis. Connect and Protect: Requirements for Maritime Autonomous Surface Ship in Urban Passenger Transportation. I: Computer Security ESORICS 2019 International Workshops, CyberICPS, SECPRE, SPOSE, and ADIoT, Lecture Notes in Computer Science(), vol 11980. s. 69-85 Springer, Cham. https://doi.org/10.1007/978-3-030-42048-2_5en_US
dc.relation.haspartPaper 2: Amro, Ahmed Walid; Gkioulos, Vasileios; Katsikas, Sokratis. Communication architecture for autonomous passenger ship. Proceedings of the Institution of Mechanical Engineers. Part O, Journal of risk and reliability 2021 https://doi.org/10.1177/1748006X211002546en_US
dc.relation.haspartPaper 3: Amro, Ahmed Walid; Kavallieratos, Georgios; Louzis, Konstantinos; Thieme, Christoph Alexander. Impact of cyber risk on the safety of the MilliAmpere2 Autonomous Passenger Ship. IOP Conference Series: Materials Science and Engineering 2020 ;Volum 929. https://doi.org/10.1088/1757-899X/929/1/012018 This article is licensed under a Creative Commons Attribution 4.0 International License (CC BY)en_US
dc.relation.haspartPaper 4: Amro, Ahmed Walid; Gkioulos, Vasileios; Katsikas, Sokratis. Assessing Cyber Risk in Cyber-Physical Systems Using the ATT&CK Framework. ACM Transactions on Privacy and Security (TOPS) 2022 https://doi.org/10.1145/3571733en_US
dc.relation.haspartPaper 5: Amro, Ahmed Walid; Gkioulos, Vasileios. Cyber risk management for autonomous passenger ships using threat-informed defense-in-depth. International Journal of Information Security 2022 s. 249-288 https://doi.org/10.1007/s10207-022-00638-y This article is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0)en_US
dc.relation.haspartPaper 6: Amro, Ahmed Walid; Oruc, Aybars; Gkioulos, Vasileios; Katsikas, Sokratis. Navigation Data Anomaly Analysis and Detection. Information 2022 ;Volum 13.(3) https://doi.org/10.3390/info13030104 This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) licenseen_US
dc.relation.haspartPaper 7: Amro, Ahmed Walid; Gkioulos, Vasileios. From Click to Sink: Utilizing AIS for Command and Control in Maritime Cyber Attacks. I: Computer Security – ESORICS 2022. Springer 2022 ISBN 978-3-031-17143-7. s. 535-553 Lecture Notes in Computer Science, vol 13556. https://doi.org/10.1007/978-3-031-17143-7_26en_US
dc.relation.haspartPaper 8: Amro, Ahmed Walid; Gkioulos, Vasileios. Communication and Cybersecurity Testbed for Autonomous Passenger Ship. I: Computer Security. ESORICS 2021 International Workshops. Springer 2022 s. 5-22 Lecture Notes in Computer Science book series (LNSC,volume 13106) https://doi.org/10.1007/978-3-030-95484-0_1en_US
dc.relation.haspartPaper 9: A. Amro and V. Gkioulos, ‘Evaluation of a cyber risk assessment approach for cyber-physical systems: Maritime- and energy-use cases,’ Journal of Marine Science and Engineering, vol. 11, no. 4, 2023, https://doi.org/ 10.3390/jmse11040744 This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) licenseen_US
dc.relation.haspartPaper 10: Oruc, Aybars; Amro, Ahmed Walid; Gkioulos, Vasileios. Assessing Cyber Risks of an INS Using the MITRE ATT&CK Framework. Sensors 2022 ;Volum 22.(22) s. 1-24 https://doi.org/10.3390/s22228745 This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) licenseen_US
dc.titleCommunication and cybersecurity for autonomous passenger ferryen_US
dc.typeDoctoral thesisen_US
dc.subject.nsiVDP::Technology: 500::Information and communication technology: 550en_US


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel