Prabhu, V., Oyekan, J., Eng, S. et al. (2 more authors) (2018) Towards data-driven cyber attack damage and vulnerability estimation for manufacturing enterprises. In: Auer, M.E. and Langmann, R., (eds.) Smart Industry & Smart Education : Proceedings of the 15th International Conference on Remote Engineering and Virtual Instrumentation. 15th International Conference on Remote Engineering and Virtual Instrumentation, 21-23 Mar 2018, Duesseldorf, Germany. Springer International Publishing , pp. 333-343. ISBN 9783319956770
Abstract
Defending networks against cyber attacks is often reactive rather than proactive. Attacks against enterprises are often monetary driven and are targeted to compromise data. While the best practices in enterprise-level cyber security of IT infrastructures are well established, the same cannot be said for critical infrastructures that exist in the manufacturing industry. Often guided by these best practices, manufacturing enterprises apply blanket cyber security in order to protect their networks, resulting in either under or over protection. In addition, these networks comprise heterogeneous entities such as machinery, control systems, digital twins and interfaces to the external supply chain making them susceptible to cyber attacks that cripple the manufacturing enterprise. Therefore, it is necessary to analyse, comprehend and quantify the essential metrics of providing targeted and optimised cyber security for manufacturing enterprises. This paper presents a novel data-driven approach to develop the essential metrics, namely, Damage Index (DI) and Vulnerability Index (VI) that quantify the extent of damage a manufacturing enterprise could suffer due to a cyber attack and the vulnerabilities of the heterogeneous entities within the enterprise respectively. A use case for computing the metrics is also demonstrated. This work builds a strong foundation for development of an adaptive cyber security architecture with optimal use of IT resources for manufacturing enterprises.
Metadata
Item Type: | Proceedings Paper |
---|---|
Authors/Creators: |
|
Editors: |
|
Copyright, Publisher and Additional Information: | © 2019 Springer International Publishing AG. This is an author-produced version of a paper subsequently published in Auer M., Langmann R. (eds) Smart Industry & Smart Education. REV 2018. Lecture Notes in Networks and Systems, vol 47. Uploaded in accordance with the publisher's self-archiving policy. |
Keywords: | Data driven; Cyber security; Manufacturing enterprises; Cyber attack damage; Cyber attack vulnerability; Metrics |
Dates: |
|
Institution: | The University of Sheffield |
Academic Units: | The University of Sheffield > Faculty of Engineering (Sheffield) > Department of Automatic Control and Systems Engineering (Sheffield) |
Depositing User: | Symplectic Sheffield |
Date Deposited: | 13 Aug 2021 10:11 |
Last Modified: | 18 Aug 2021 12:08 |
Status: | Published |
Publisher: | Springer International Publishing |
Refereed: | Yes |
Identification Number: | 10.1007/978-3-319-95678-7_38 |
Related URLs: | |
Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:177056 |