Cargando…

A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems

Critical infrastructures are increasingly reliant on information and communications technology (ICT) for more efficient operations, which, at the same time, exposes them to cyber threats. As the frequency and severity of cyberattacks are increasing, so are the costs of critical infrastructure securi...

Descripción completa

Detalles Bibliográficos
Autores principales: Żebrowski, Piotr, Couce‐Vieira, Aitor, Mancuso, Alessandro
Formato: Online Artículo Texto
Lenguaje:English
Publicado: John Wiley and Sons Inc. 2022
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9790388/
https://www.ncbi.nlm.nih.gov/pubmed/35229333
http://dx.doi.org/10.1111/risa.13900
_version_ 1784859165296951296
author Żebrowski, Piotr
Couce‐Vieira, Aitor
Mancuso, Alessandro
author_facet Żebrowski, Piotr
Couce‐Vieira, Aitor
Mancuso, Alessandro
author_sort Żebrowski, Piotr
collection PubMed
description Critical infrastructures are increasingly reliant on information and communications technology (ICT) for more efficient operations, which, at the same time, exposes them to cyber threats. As the frequency and severity of cyberattacks are increasing, so are the costs of critical infrastructure security. Efficient allocation of resources is thus a crucial issue for cybersecurity. A common practice in managing cyber threats is to conduct a qualitative analysis of individual attack scenarios through risk matrices, prioritizing the scenarios according to their perceived urgency and addressing them in order until all the resources available for cybersecurity are spent. Apart from methodological caveats, this approach may lead to suboptimal resource allocations, given that potential synergies between different attack scenarios and among available security measures are not taken into consideration. To overcome this shortcoming, we propose a quantitative framework that features: (1) a more holistic picture of the cybersecurity landscape, represented as a Bayesian network (BN) that encompasses multiple attack scenarios and thus allows for a better appreciation of vulnerabilities; and (2) a multiobjective optimization model built on top of the said BN that explicitly represents multiple dimensions of the potential impacts of successful cyberattacks. Our framework adopts a broader perspective than the standard cost–benefit analysis and allows the formulation of more nuanced security objectives. We also propose a computationally efficient algorithm that identifies the set of Pareto–optimal portfolios of security measures that simultaneously minimize various types of expected cyberattack impacts, while satisfying budgetary and other constraints. We illustrate our framework with a case study of electric power grids.
format Online
Article
Text
id pubmed-9790388
institution National Center for Biotechnology Information
language English
publishDate 2022
publisher John Wiley and Sons Inc.
record_format MEDLINE/PubMed
spelling pubmed-97903882022-12-28 A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems Żebrowski, Piotr Couce‐Vieira, Aitor Mancuso, Alessandro Risk Anal Original Articles Critical infrastructures are increasingly reliant on information and communications technology (ICT) for more efficient operations, which, at the same time, exposes them to cyber threats. As the frequency and severity of cyberattacks are increasing, so are the costs of critical infrastructure security. Efficient allocation of resources is thus a crucial issue for cybersecurity. A common practice in managing cyber threats is to conduct a qualitative analysis of individual attack scenarios through risk matrices, prioritizing the scenarios according to their perceived urgency and addressing them in order until all the resources available for cybersecurity are spent. Apart from methodological caveats, this approach may lead to suboptimal resource allocations, given that potential synergies between different attack scenarios and among available security measures are not taken into consideration. To overcome this shortcoming, we propose a quantitative framework that features: (1) a more holistic picture of the cybersecurity landscape, represented as a Bayesian network (BN) that encompasses multiple attack scenarios and thus allows for a better appreciation of vulnerabilities; and (2) a multiobjective optimization model built on top of the said BN that explicitly represents multiple dimensions of the potential impacts of successful cyberattacks. Our framework adopts a broader perspective than the standard cost–benefit analysis and allows the formulation of more nuanced security objectives. We also propose a computationally efficient algorithm that identifies the set of Pareto–optimal portfolios of security measures that simultaneously minimize various types of expected cyberattack impacts, while satisfying budgetary and other constraints. We illustrate our framework with a case study of electric power grids. John Wiley and Sons Inc. 2022-03-01 2022-10 /pmc/articles/PMC9790388/ /pubmed/35229333 http://dx.doi.org/10.1111/risa.13900 Text en © 2022 The Authors. Risk Analysis published by Wiley Periodicals LLC on behalf of Society for Risk Analysis. https://creativecommons.org/licenses/by/4.0/This is an open access article under the terms of the http://creativecommons.org/licenses/by/4.0/ (https://creativecommons.org/licenses/by/4.0/) License, which permits use, distribution and reproduction in any medium, provided the original work is properly cited.
spellingShingle Original Articles
Żebrowski, Piotr
Couce‐Vieira, Aitor
Mancuso, Alessandro
A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems
title A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems
title_full A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems
title_fullStr A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems
title_full_unstemmed A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems
title_short A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber‐Physical Systems
title_sort bayesian framework for the analysis and optimal mitigation of cyber threats to cyber‐physical systems
topic Original Articles
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9790388/
https://www.ncbi.nlm.nih.gov/pubmed/35229333
http://dx.doi.org/10.1111/risa.13900
work_keys_str_mv AT zebrowskipiotr abayesianframeworkfortheanalysisandoptimalmitigationofcyberthreatstocyberphysicalsystems
AT coucevieiraaitor abayesianframeworkfortheanalysisandoptimalmitigationofcyberthreatstocyberphysicalsystems
AT mancusoalessandro abayesianframeworkfortheanalysisandoptimalmitigationofcyberthreatstocyberphysicalsystems
AT zebrowskipiotr bayesianframeworkfortheanalysisandoptimalmitigationofcyberthreatstocyberphysicalsystems
AT coucevieiraaitor bayesianframeworkfortheanalysisandoptimalmitigationofcyberthreatstocyberphysicalsystems
AT mancusoalessandro bayesianframeworkfortheanalysisandoptimalmitigationofcyberthreatstocyberphysicalsystems