计算机科学
风险分析(工程)
过程(计算)
计算机安全
控制(管理)
工业控制系统
业务
人工智能
操作系统
作者
Shaymaa Mamdouh Khalil,Hayretdin Bahşi,Tarmo Korõtko
标识
DOI:10.1016/j.cose.2023.103543
摘要
Threat modeling is the process of identifying and mitigating potential threats to a system. It was originally developed to enhance software security during the design phase but has since been adapted for Industrial Control Systems (ICSs). ICSs are complex and interconnected systems that control critical infrastructure, such as power plants, water treatment facilities, and manufacturing plants. As such, they are major targets for cyberattacks, which may lead to human casualties, severe national security impacts, and financial instability. This systematic literature review explores the existing threat modeling methodologies for ICSs and emphasizes the importance of employing methodical frameworks that cover safety, security, and privacy aspects with clear procedural guidelines. The review reveals that ICSs threat modeling often lacks validation to ensure that the used methodologies are effective in identifying and mitigating threats. This study emphasizes the need to develop and apply better validation metrics in case studies. The main goal of this review is to help cyber security researchers and practitioners in selecting a suitable threat modeling approach that facilitates the creation of ICSs with an acceptable level of security.
科研通智能强力驱动
Strongly Powered by AbleSci AI