The convergence of Information Technology (IT) and Operational Technology (OT) in Industrial Control System (ICS) comes with severe cybersecurity challenges that increasingly pose threats to critical infrastructures. In this challenging environment, numerous standards and data sources exist that aim to facilitate the exchange of information and guide security assessment, detection, and mitigation. Despite this wealth of information, the relevant data is currently fragmented and not available as an integrated knowledge base. Existing approaches to link and integrate Cyber Threat Intelligence (CTI) across sources and represent them in a machine interpretable and interoperable manner mainly focus on IT security in general, leaving the ICS domain largely unexplored. To fill this critical gap, we present an integrated ICS-SEC Knowledge Graph (ICS-SEC KG) to support analyzing and managing the security of ICSs. We describe the conceptualization and pipeline to construct the KG from a broad range of ICS cybersecurity data sources as well as the underlying processes and infrastructure to continually update it. To ensure quality and consistency, we apply ontology validation and a set of SHACL constraints. We validate our approach in two application scenarios derived from real-world security incidents in the industrial domain and demonstrate its usefulness for threat intelligence exploration and vulnerability assessment. All materials and links for this paper are available at https://github.com/sepses/ics-sec-kg .

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

The ICS-SEC KG: An Integrated Cybersecurity Resource for Industrial Control Systems

  • Kabul Kurniawan,
  • Elmar Kiesling,
  • Dietmar Winkler,
  • Andreas Ekelhart

摘要

The convergence of Information Technology (IT) and Operational Technology (OT) in Industrial Control System (ICS) comes with severe cybersecurity challenges that increasingly pose threats to critical infrastructures. In this challenging environment, numerous standards and data sources exist that aim to facilitate the exchange of information and guide security assessment, detection, and mitigation. Despite this wealth of information, the relevant data is currently fragmented and not available as an integrated knowledge base. Existing approaches to link and integrate Cyber Threat Intelligence (CTI) across sources and represent them in a machine interpretable and interoperable manner mainly focus on IT security in general, leaving the ICS domain largely unexplored. To fill this critical gap, we present an integrated ICS-SEC Knowledge Graph (ICS-SEC KG) to support analyzing and managing the security of ICSs. We describe the conceptualization and pipeline to construct the KG from a broad range of ICS cybersecurity data sources as well as the underlying processes and infrastructure to continually update it. To ensure quality and consistency, we apply ontology validation and a set of SHACL constraints. We validate our approach in two application scenarios derived from real-world security incidents in the industrial domain and demonstrate its usefulness for threat intelligence exploration and vulnerability assessment. All materials and links for this paper are available at https://github.com/sepses/ics-sec-kg .