A Novel Evidence-Based Threat Enumeration Methodology for ICS
摘要
ICS environments are vital to the operation of critical infrastructure, such as power grids, water treatment facilities, and manufacturing plants. However, these systems are vulnerable to cyber attacks due to their reliance on interconnected devices and networks, which could lead to catastrophic failures. Therefore, securing these systems from cyber threats becomes paramount. In this context, threat modeling plays an essential role. Despite advances in threat modeling, the fundamental gap in the state-of-the-art is the lack of a comprehensive threat enumeration (i.e., identification) in the ICS domain. Most threat models in the literature (i) rely on expert knowledge, (ii) only include generic threats such as spoofing, tampering, etc., and (iii) these threats may not be comprehensive enough, namely, can overlook some threats for the systems in question. This highlights the need for systematic threat enumeration in threat modeling practices. To overcome these limitations, we propose a novel threat enumeration methodology to systematically enumerate threats. Our proposed threat enumeration methodology is based on historical CVE entries of components and their associated fundamental weaknesses in the form of CVE-CWE pairs. Although our methodology is generally applicable, we specifically target ICS in our work. Furthermore, we have implemented our methodology as a ready-to-use tool and demonstrated its applicability in multiple ICS scenarios and architectures.