Towards an automated and dynamic risk management response system

  • Gustavo Gonzalez-Granadillo
  • , Ender Alvarez
  • , Alexander Motzek
  • , Matteo Merialdo
  • , Joaquin Garcia-Alfaro
  • , Hervé Debar

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Achieving a fully automated and dynamic system in critical infrastructure scenarios is an open issue in ongoing research. Generally, decisions in SCADA systems require a manual intervention, that in most of the cases is performed by highly experienced operators. In this paper we propose a framework consisting of a proactive management software that aims at anticipating the occurrence of potential attacks. It conducts an initial evaluation of reported proactive evidences based on a quantitative metric of monetary return on response investment. The framework evaluates and selects mitigation actions from a pool of candidates, by ranking them in terms of financial and operational impacts. The purpose of this process is to select an optimal set of mitigation actions from financial and operational perspectives and propose them to reduce the risk of threats against the monitored system, without sacrificing an organization’s missions in favor of security. A real world case study of a SCADA environment shows the applicability of the model, from the analysis of the input data to the selection of the response plan.

Original languageEnglish
Title of host publicationSecure IT Systems - 21st Nordic Conference, NordSec 2016, Proceedings
EditorsJuha Roning, Billy Bob Brumley
PublisherSpringer Verlag
Pages37-53
Number of pages17
ISBN (Print)9783319475592
DOIs
Publication statusPublished - 1 Jan 2016
Externally publishedYes
Event21st Nordic Conference on Secure IT Systems, NordSec 2016 - Oulu, Finland
Duration: 2 Nov 20164 Nov 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10014 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st Nordic Conference on Secure IT Systems, NordSec 2016
Country/TerritoryFinland
CityOulu
Period2/11/164/11/16

Keywords

  • Automatic response
  • Critical infrastructures
  • Dynamic response system
  • Operational impact
  • RORI

Fingerprint

Dive into the research topics of 'Towards an automated and dynamic risk management response system'. Together they form a unique fingerprint.

Cite this