Cargando…

A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites

Cyber threats and vulnerabilities present an increasing risk to the safe and frictionless execution of business operations. Bad actors (“hackers”), including state actors, are increasingly targeting the operational technologies (OTs) and industrial control systems (ICSs) used to protect critical nat...

Descripción completa

Detalles Bibliográficos
Autores principales: Mehmood, Amjad, Epiphaniou, Gregory, Maple, Carsten, Ersotelos, Nikolaos, Wiseman, Richard
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10647391/
https://www.ncbi.nlm.nih.gov/pubmed/37960419
http://dx.doi.org/10.3390/s23218720
_version_ 1785135096095834112
author Mehmood, Amjad
Epiphaniou, Gregory
Maple, Carsten
Ersotelos, Nikolaos
Wiseman, Richard
author_facet Mehmood, Amjad
Epiphaniou, Gregory
Maple, Carsten
Ersotelos, Nikolaos
Wiseman, Richard
author_sort Mehmood, Amjad
collection PubMed
description Cyber threats and vulnerabilities present an increasing risk to the safe and frictionless execution of business operations. Bad actors (“hackers”), including state actors, are increasingly targeting the operational technologies (OTs) and industrial control systems (ICSs) used to protect critical national infrastructure (CNI). Minimisations of cyber risk, attack surfaces, data immutability, and interoperability of IoT are some of the main challenges of today’s CNI. Cyber security risk assessment is one of the basic and most important activities to identify and quantify cyber security threats and vulnerabilities. This research presents a novel i-TRACE security-by-design CNI methodology that encompasses CNI key performance indicators (KPIs) and metrics to combat the growing vicarious nature of remote, well-planned, and well-executed cyber-attacks against CNI, as recently exemplified in the current Ukraine conflict (2014–present) on both sides. The proposed methodology offers a hybrid method that specifically identifies the steps required (typically undertaken by those responsible for detecting, deterring, and disrupting cyber attacks on CNI). Furthermore, we present a novel, advanced, and resilient approach that leverages digital twins and distributed ledger technologies for our chosen i-TRACE use cases of energy management and connected sites. The key steps required to achieve the desired level of interoperability and immutability of data are identified, thereby reducing the risk of CNI-specific cyber attacks and minimising the attack vectors and surfaces. Hence, this research aims to provide an extra level of safety for CNI and OT human operatives, i.e., those tasked with and responsible for detecting, deterring, disrupting, and mitigating these cyber-attacks. Our evaluations and comparisons clearly demonstrate that i-TRACE has significant intrinsic advantages compared to existing “state-of-the-art” mechanisms.
format Online
Article
Text
id pubmed-10647391
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-106473912023-10-25 A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites Mehmood, Amjad Epiphaniou, Gregory Maple, Carsten Ersotelos, Nikolaos Wiseman, Richard Sensors (Basel) Article Cyber threats and vulnerabilities present an increasing risk to the safe and frictionless execution of business operations. Bad actors (“hackers”), including state actors, are increasingly targeting the operational technologies (OTs) and industrial control systems (ICSs) used to protect critical national infrastructure (CNI). Minimisations of cyber risk, attack surfaces, data immutability, and interoperability of IoT are some of the main challenges of today’s CNI. Cyber security risk assessment is one of the basic and most important activities to identify and quantify cyber security threats and vulnerabilities. This research presents a novel i-TRACE security-by-design CNI methodology that encompasses CNI key performance indicators (KPIs) and metrics to combat the growing vicarious nature of remote, well-planned, and well-executed cyber-attacks against CNI, as recently exemplified in the current Ukraine conflict (2014–present) on both sides. The proposed methodology offers a hybrid method that specifically identifies the steps required (typically undertaken by those responsible for detecting, deterring, and disrupting cyber attacks on CNI). Furthermore, we present a novel, advanced, and resilient approach that leverages digital twins and distributed ledger technologies for our chosen i-TRACE use cases of energy management and connected sites. The key steps required to achieve the desired level of interoperability and immutability of data are identified, thereby reducing the risk of CNI-specific cyber attacks and minimising the attack vectors and surfaces. Hence, this research aims to provide an extra level of safety for CNI and OT human operatives, i.e., those tasked with and responsible for detecting, deterring, disrupting, and mitigating these cyber-attacks. Our evaluations and comparisons clearly demonstrate that i-TRACE has significant intrinsic advantages compared to existing “state-of-the-art” mechanisms. MDPI 2023-10-25 /pmc/articles/PMC10647391/ /pubmed/37960419 http://dx.doi.org/10.3390/s23218720 Text en © 2023 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Mehmood, Amjad
Epiphaniou, Gregory
Maple, Carsten
Ersotelos, Nikolaos
Wiseman, Richard
A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites
title A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites
title_full A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites
title_fullStr A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites
title_full_unstemmed A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites
title_short A Hybrid Methodology to Assess Cyber Resilience of IoT in Energy Management and Connected Sites
title_sort hybrid methodology to assess cyber resilience of iot in energy management and connected sites
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10647391/
https://www.ncbi.nlm.nih.gov/pubmed/37960419
http://dx.doi.org/10.3390/s23218720
work_keys_str_mv AT mehmoodamjad ahybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT epiphaniougregory ahybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT maplecarsten ahybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT ersotelosnikolaos ahybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT wisemanrichard ahybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT mehmoodamjad hybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT epiphaniougregory hybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT maplecarsten hybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT ersotelosnikolaos hybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites
AT wisemanrichard hybridmethodologytoassesscyberresilienceofiotinenergymanagementandconnectedsites