The construction sector is transitioning into a data-centric industry characterized by integrating sophisticated technologies such as digital twins, robotics, and cloud computing with traditional construction methods. This shift has resulted in construction firms generating and managing an unprecedented volume of data in a digital environment, thereby intensifying their vulnerability to cyber threats. Consequently, the imperative for cyber risk analysis, which encapsulates risk identification, estimation, and mitigation, has grown to protect data and prevent potential losses. While risk identification and estimation form the cornerstone for developing effective risk mitigation strategies, existing literature in the construction sector primarily focuses on methods that rely heavily on lengthy human involvement, which can result in subjective outcomes. To bridge this gap, this study explores Machine Learning (ML) techniques to refine and optimize these tasks, leveraging their inherent automation capabilities. Our exploration begins with an examination of the broader application of ML in general cyber risk analysis, identifying popular ML algorithms through a simplified bibliometric analysis. Following a standard ML system design approach, this study proposes four ML frameworks specifically designed for risk identification within the construction sector, ranging from multi-class classification methods to deep learning-driven generative models inspired by advancements in Natural Language Processing (NLP). For risk estimation, we also propose four distinct ML frameworks, each characterized by the specific format of the input threat-vulnerability pair pertinent to construction scenarios. The proposed frameworks serve as invaluable assets for construction stakeholders, enabling even those with limited cybersecurity expertise to enhance the cybersecurity robustness of their projects.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Integrating Machine Learning for Cyber Risk Analysis in Construction 4.0

  • Dongchi Yao,
  • Borja García de Soto

摘要

The construction sector is transitioning into a data-centric industry characterized by integrating sophisticated technologies such as digital twins, robotics, and cloud computing with traditional construction methods. This shift has resulted in construction firms generating and managing an unprecedented volume of data in a digital environment, thereby intensifying their vulnerability to cyber threats. Consequently, the imperative for cyber risk analysis, which encapsulates risk identification, estimation, and mitigation, has grown to protect data and prevent potential losses. While risk identification and estimation form the cornerstone for developing effective risk mitigation strategies, existing literature in the construction sector primarily focuses on methods that rely heavily on lengthy human involvement, which can result in subjective outcomes. To bridge this gap, this study explores Machine Learning (ML) techniques to refine and optimize these tasks, leveraging their inherent automation capabilities. Our exploration begins with an examination of the broader application of ML in general cyber risk analysis, identifying popular ML algorithms through a simplified bibliometric analysis. Following a standard ML system design approach, this study proposes four ML frameworks specifically designed for risk identification within the construction sector, ranging from multi-class classification methods to deep learning-driven generative models inspired by advancements in Natural Language Processing (NLP). For risk estimation, we also propose four distinct ML frameworks, each characterized by the specific format of the input threat-vulnerability pair pertinent to construction scenarios. The proposed frameworks serve as invaluable assets for construction stakeholders, enabling even those with limited cybersecurity expertise to enhance the cybersecurity robustness of their projects.