Back to Search
Start Over
Continuous Quantitative Risk Management in Smart Grids Using Attack Defense Trees
- Source :
- Addi. Archivo Digital para la Docencia y la Investigación, instname, TECNALIA Publications, Fundación Tecnalia Research & Innovation, Sensors, Volume 20, Issue 16, Sensors (Basel, Switzerland), Sensors, Vol 20, Iss 4404, p 4404 (2020), Addi: Archivo Digital para la Docencia y la Investigación, Universidad del País Vasco
- Publication Year :
- 2020
- Publisher :
- MDPI, 2020.
-
Abstract
- Although the risk assessment discipline has been studied from long ago as a means to support security investment decision-making, no holistic approach exists to continuously and quantitatively analyze cyber risks in scenarios where attacks and defenses may target different parts of Internet of Things (IoT)-based smart grid systems. In this paper, we propose a comprehensive methodology that enables informed decisions on security protection for smart grid systems by the continuous assessment of cyber risks. The solution is based on the use of attack defense trees modelled on the system and computation of the proposed risk attributes that enables an assessment of the system risks by propagating the risk attributes in the tree nodes. The method allows system risk sensitivity analyses to be performed with respect to different attack and defense scenarios, and optimizes security strategies with respect to risk minimization. The methodology proposes the use of standard security and privacy defense taxonomies from internationally recognized security control families, such as the NIST SP 800-53, which facilitates security certifications. Finally, the paper describes the validation of the methodology carried out in a real smart building energy efficiency application that combines multiple components deployed in cloud and IoT resources. The scenario demonstrates the feasibility of the method to not only perform initial quantitative estimations of system risks but also to continuously keep the risk assessment up to date according to the system conditions during operation. This research leading to these results was funded by the EUROPEAN COMMISSION, grant number 787011 (SPEAR Horizon 2020 project) and 780351 (ENACT Horizon 2020 project).
- Subjects :
- Computer science
information security
0211 other engineering and technologies
Cloud computing
02 engineering and technology
Certification
lcsh:Chemical technology
7. Clean energy
Biochemistry
Article
Analytical Chemistry
0202 electrical engineering, electronic engineering, information engineering
lcsh:TP1-1185
Security management
security management
Electrical and Electronic Engineering
Instrumentation
Building automation
021110 strategic, defence & security studies
business.industry
risk assessment
020206 networking & telecommunications
Information security
security management risk assessment
Atomic and Molecular Physics, and Optics
Security controls
Smart grid
Risk analysis (engineering)
Risk assessment
business
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- Addi. Archivo Digital para la Docencia y la Investigación, instname, TECNALIA Publications, Fundación Tecnalia Research & Innovation, Sensors, Volume 20, Issue 16, Sensors (Basel, Switzerland), Sensors, Vol 20, Iss 4404, p 4404 (2020), Addi: Archivo Digital para la Docencia y la Investigación, Universidad del País Vasco
- Accession number :
- edsair.doi.dedup.....9d4498a0450bc9dc36b8f317014fc89d