Game-Theoretic and Probabilistic Cyber Risk Assessment
概率逻辑
计算机科学
博弈论
概率风险评估
计算机安全
人工智能
数理经济学
数学
作者
Yunfei Zhao
标识
DOI:10.1109/rams51492.2024.10457747
摘要
Digital technologies are being widely used in various industrial systems to support instrumentation, computation, communication, and control. While these digital technologies have brought numerous benefits in terms of improved efficiency and reliability, they have also posed great cyber risk to the industrial systems. The digital technologies have provided malicious attackers with opportunities to cause damage to physical processes via cyber means. Effective cyber risk management heavily depends on a systematic and comprehensive cyber risk assessment. Existing methods for cyber risk assessment are based on analyses of threats, vulnerabilities, and physical consequences, but these methods either lack in a technically solid basis of threat analysis, or lack in a systematic physical process risk analysis. This paper introduces a new method for cyber risk assessment to fill this gap. The new method integrates game theory for threat analysis and probabilistic risk assessment for systematic physical process risk analysis. This method not only supports cyber risk assessment, but also provides results that can be readily used for cyber risk management. A numerical case study is performed to illustrate the proposed method.