Estimating Time-To-Compromise for Industrial Control System Attack Techniques Through Vulnerability Data


연구 분야: Strategies



학회: SN Computer Science


초록

When protecting the Industrial Control Systems against cyber attacks, it is important to have as much information as possible to allocate defensive resources properly. In this paper we estimate the Time-To-Compromise of different Industrial Control Systems attack techniques by MITRE ATT&CK. The Time-To-Compromise is estimated using an equation that takes into consideration the vulnerability data that exists for a specific asset and category of vulnerability. The vulnerability data is derived from an Industrial Control Systems specific vulnerability dataset. As a result, we present the mapping of the attack techniques to assets and categories of vulnerability, which makes it possible to apply specific vulnerabilities to the technique. We also present the method of how to estimate the Time-To-Compromise of the techniques and finally the values of Time-To-Compromise. After mapping the attack techniques to assets and category of vulnerability we are able to estimate the Time-To-Compromise and discuss its trustworthiness.


Author Profile
Engla Rencelj Ling

Division of Network and Systems Engineering KTH Royal Institute of Technology Teknikringen 33 100 44 Stockholm Sweden

Andorra
Author Profile
Mathias Ekstedt

Division of Network and Systems Engineering KTH Royal Institute of Technology Teknikringen 33 100 44 Stockholm Sweden

Andorra

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Andorra
사이트 Springer
좋아요 수 0

연관 논문 목록 (162건)