...
首页> 外文期刊>Journal of Universal Computer Science >Cyber Threat Intelligence for Improving Cybersecurity and Risk Management in Critical Infrastructure
【24h】

Cyber Threat Intelligence for Improving Cybersecurity and Risk Management in Critical Infrastructure

机译:网络威胁情报,用于改善关键基础设施中的网络安全和风险管理

获取原文
           

摘要

Cyber-attack is one of the significant threats affecting to any organisation specifically to the Critical Infrastructure (CI) organisation. These attacks are nowadays more sophisticated, multi-vectored and less predictable, which make the Cyber Security Risk Management (CSRM) task more challenging. Critical Infrastructure needs a new line of security defence to control these threats and minimise risks. Cyber Threat Intelligence (CTI) provides evidence-based information about the threats aiming to prevent threats. There are existing works and industry practice that emphasise the necessity of CTI and provides methods for threat intelligence and sharing. However, despite these significant efforts, there is a lack of focus on how CTI information can support the CSRM activities so that the organisation can undertake appropriate controls to mitigate the risk proactively. This paper aims to fill this gap by integrating CTI for improving cybersecurity risks management practice specifically focusing on the critical infrastructure. In particular, the proposed approach contributes beyond state of the art practice by incorporating CTI information for the risk management activities. This helps the organisation to provide adequate and appropriate controls from strategic, tactical and operational perspectives. We have integrated concepts relating to CTI and CSRM so that threat actor's profile, attack detailed can support calculating the risk. We consider smart grid system as a Critical Infrastructure to demonstrate the applicability of the work. The result shows that cyber risks in critical infrastructures can be minimised if CTI information is gathered and used as part of CSRM activities. CTI not only supports understanding of threat for accurate risk estimation but also evaluates the effectiveness of existing controls and recommend necessity controls to improve overall cybersecurity. Also, the result shows that our approach provides early warning about issues that need immediate attention.
机译:网络攻击是对任何专门针对关键基础设施(CI)组织的任何组织影响的重要威胁之一。现在,这些攻击更复杂,多矢量,更不可预测的,这使得网络安全风险管理(CSRM)任务更具挑战性。关键基础架构需要新的安全防御线来控制这些威胁并尽量减少风险。网络威胁情报(CTI)提供了有关旨在防止威胁的威胁的基于威胁的信息。有现有的工程和行业实践,强调CTI的必要性,并为威胁情报和共享提供了方法。但是,尽管有这些重大努力,但缺乏关注CTI信息如何支持CSRM活动,以便本组织可以进行适当的控制,以积极地减轻风险。本文旨在通过整合CTI来填补这种差距来改善网络安全风险管理实践,专门关注关键基础设施。特别是,通过将CTI信息纳入风险管理活动,拟议的方法贡献了最新的技术实践。这有助于本组织从战略,战术和操作角度提供充分和适当的控制。我们有与CTI和CSRM相关的集成概念,以便威胁演员的配置文件,攻击详细可以支持计算风险。我们将智能电网系统视为展示工作适用性的关键基础架构。结果表明,如果收集CTI信息并将其作为CSRM活动的一部分,则可以最大限度地减少关键基础设施中的网络风险。 CTI不仅支持对准确风险估算的威胁的理解,而且还评估了现有控制的有效性,并推荐必要的控制来改善整体网络安全。此外,结果表明,我们的方法提供了关于需要立即关注的问题的预警。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号