Continuous Quantitative Risk Management in Smart Grids Using Attack Defense Trees.

information security risk assessment security management

Journal

Sensors (Basel, Switzerland)
ISSN: 1424-8220
Titre abrégé: Sensors (Basel)
Pays: Switzerland
ID NLM: 101204366

Informations de publication

Date de publication:
07 Aug 2020
Historique:
received: 05 07 2020
revised: 24 07 2020
accepted: 27 07 2020
entrez: 14 8 2020
pubmed: 14 8 2020
medline: 14 8 2020
Statut: epublish

Résumé

Although the risk assessment discipline has been studied from long ago as a means to support security investment decision-making, no holistic approach exists to continuously and quantitatively analyze cyber risks in scenarios where attacks and defenses may target different parts of Internet of Things (IoT)-based smart grid systems. In this paper, we propose a comprehensive methodology that enables informed decisions on security protection for smart grid systems by the continuous assessment of cyber risks. The solution is based on the use of attack defense trees modelled on the system and computation of the proposed risk attributes that enables an assessment of the system risks by propagating the risk attributes in the tree nodes. The method allows system risk sensitivity analyses to be performed with respect to different attack and defense scenarios, and optimizes security strategies with respect to risk minimization. The methodology proposes the use of standard security and privacy defense taxonomies from internationally recognized security control families, such as the NIST SP 800-53, which facilitates security certifications. Finally, the paper describes the validation of the methodology carried out in a real smart building energy efficiency application that combines multiple components deployed in cloud and IoT resources. The scenario demonstrates the feasibility of the method to not only perform initial quantitative estimations of system risks but also to continuously keep the risk assessment up to date according to the system conditions during operation.

Identifiants

pubmed: 32784568
pii: s20164404
doi: 10.3390/s20164404
pmc: PMC7472492
pii:
doi:

Types de publication

Journal Article

Langues

eng

Sous-ensembles de citation

IM

Subventions

Organisme : Horizon 2020 Framework Programme
ID : 787011
Organisme : Horizon 2020 Framework Programme
ID : 780351

Auteurs

Erkuden Rios (E)

Tecnalia, Basque Research and Technology Alliance (BRTA), 48170 Derio, Spain.

Angel Rego (A)

Tecnalia, Basque Research and Technology Alliance (BRTA), 48170 Derio, Spain.

Eider Iturbe (E)

Tecnalia, Basque Research and Technology Alliance (BRTA), 48170 Derio, Spain.

Marivi Higuero (M)

Ingeniería de Comunicaciones, Universidad del País Vasco/Euskal Herriko Unibertsitatea, 48004 Bilbao, Spain.

Xabier Larrucea (X)

Tecnalia, Basque Research and Technology Alliance (BRTA), 48170 Derio, Spain.

Classifications MeSH