ICS environments are vital to the operation of critical infrastructure, such as power grids, water treatment facilities, and manufacturing plants. However, these systems are vulnerable to cyber attacks due to their reliance on interconnected devices and networks, which could lead to catastrophic failures. Therefore, securing these systems from cyber threats becomes paramount. In this context, threat modeling plays an essential role. Despite advances in threat modeling, the fundamental gap in the state-of-the-art is the lack of a comprehensive threat enumeration (i.e., identification) in the ICS domain. Most threat models in the literature (i) rely on expert knowledge, (ii) only include generic threats such as spoofing, tampering, etc., and (iii) these threats may not be comprehensive enough, namely, can overlook some threats for the systems in question. This highlights the need for systematic threat enumeration in threat modeling practices. To overcome these limitations, we propose a novel threat enumeration methodology to systematically enumerate threats. Our proposed threat enumeration methodology is based on historical CVE entries of components and their associated fundamental weaknesses in the form of CVE-CWE pairs. Although our methodology is generally applicable, we specifically target ICS in our work. Furthermore, we have implemented our methodology as a ready-to-use tool and demonstrated its applicability in multiple ICS scenarios and architectures.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Novel Evidence-Based Threat Enumeration Methodology for ICS

  • Can Özkan,
  • Dave Singelée

摘要

ICS environments are vital to the operation of critical infrastructure, such as power grids, water treatment facilities, and manufacturing plants. However, these systems are vulnerable to cyber attacks due to their reliance on interconnected devices and networks, which could lead to catastrophic failures. Therefore, securing these systems from cyber threats becomes paramount. In this context, threat modeling plays an essential role. Despite advances in threat modeling, the fundamental gap in the state-of-the-art is the lack of a comprehensive threat enumeration (i.e., identification) in the ICS domain. Most threat models in the literature (i) rely on expert knowledge, (ii) only include generic threats such as spoofing, tampering, etc., and (iii) these threats may not be comprehensive enough, namely, can overlook some threats for the systems in question. This highlights the need for systematic threat enumeration in threat modeling practices. To overcome these limitations, we propose a novel threat enumeration methodology to systematically enumerate threats. Our proposed threat enumeration methodology is based on historical CVE entries of components and their associated fundamental weaknesses in the form of CVE-CWE pairs. Although our methodology is generally applicable, we specifically target ICS in our work. Furthermore, we have implemented our methodology as a ready-to-use tool and demonstrated its applicability in multiple ICS scenarios and architectures.