HLSS505Wk5
Research Article Comprehensive Risk Identification Model for SCADA Systems
Abdelghafar M. Elhady ,1,2 Hazem M. El-bakry,1 and Ahmed Abou Elfetouh1
1Faculty of Computers and Information, Mansoura University, Egypt 2Deanship of Scientific Research, Umm Al-Qura University, Saudi Arabia
Correspondence should be addressed to Abdelghafar M. Elhady; abdelghafar.elhady@gmail.com
Received 24 January 2019; Revised 19 April 2019; Accepted 11 June 2019; Published 6 August 2019
Academic Editor: Jesús Dı́az-Verdejo
Copyright © 2019 Abdelghafar M. Elhady et al. This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
The world is experiencing exponential growth in the use of SCADA systems in many industrial fields. The increased and considerable growth in information and communication technology has been forcing SCADA organizations to shift their SCADA systems from proprietary technology and protocol-based systems into internet-based ones. This paradigm shift has also increased the risks that target SCADA systems. To protect such systems, a risk management process is needed to identify all the risks. This study presents a detailed investigation on twenty-one scientific articles, guidelines, and databases related to SCADA risk identification parameters and provides a comparative study among them. The study next proposes a comprehensive risk identification model for SCADA systems. This model was built based on the risk identification parameters of ISO 31000 risk management principles and guidelines. The model states all risk identification parameters, identifies the relationships between those parameters, and uses a hierarchical-based method to draw complete risk scenarios. In addition, the proposed model defines the interdependency risk map among all risks stated in the model. This risk map can be used in understanding the evolution of the risks through time in SCADA systems. The proposed model is then transformed into a benchmark database containing 19,163 complete risk scenarios that can affect SCADA systems. Finally, a case study is presented to demonstrate one of the usages of the proposedmodel and its benchmark database.This case study provides 306 possible attack scenarios that Hacktivist can use to affect SCADA systems.
1. Introduction
SCADA refers to “Supervised Control andData Acquisition.” SCADA systems are one of the Industrial Control Systems (ICS) [1] that are used to automate and control all processes and operations. Nowadays, SCADA systems are used in various large-scale fields such as power, energy production, transmission, and distribution (oil and gas, transportation, and water and wastewater) [2, 3]. In these fields, the com- ponents of the system are distributed geographically over a very large distance, and they need to be centrally monitored and controlled [4]. To achieve themonitoring and controlling functions, SCADA systems consist of a set of field sites, which are located in different places [5]. Each field site consists of one or more of Remote Terminal Units (RTU), Programmable Logic Controllers (PLC), and Intelligent Elec- tronic Devices (IED). Those are connected directly to the plants’ sensors and/or actuators to capture data from the plant
operation, perform limited control commands to the field site, and send site data to central control stations known as Master Stations (MS) [6, 7]. The system also has one master station, which collects data from all field sites through a powerful communication network, analyzes these data, and displays results on a graphical terminal called a Human Machine Interface (HMI) [8].
Through time, the number of stockholders that need to connect with SCADA systems directly (system employees and third parity companies) or indirectly through enterprise systems connecting to SCADA systems (customers) has increased. This has pushed SCADA systems toward using open standard protocols, unified technologies, public hard- ware, well-known software, and connecting to the internet [9, 10]. This paradigm switch has improved the system’s support at any time and from any place, and the integration of SCADA systems with other information systems has become trivial. Consequently, the system’s vulnerability has also increased,
Hindawi Security and Communication Networks Volume 2019, Article ID 3914283, 24 pages https://doi.org/10.1155/2019/3914283
2 Security and Communication Networks
making it easier to attack systems from any place using different exploits and attacking tools [11, 12]. Through 2016, the research team at the Kaspersky lab found that there are 220,558 SCADA components that can be accessed through the Internet. These components have been distributed across 170 countries [13]. All these components represent entry points for human agents attacking SCADA systems.They can be exposed to different types of natural phenomena, such as flooding and lightning [14].
The need for a powerful and collaborative risk manage- ment framework for SCADA systems has become urgent to identify, evaluate, and treat various types of risks targeting SCADA systems. All possible scenarios that may happen and affect the system either directly or indirectly should be well- described according to a set of parameters [15, 16]. These parameters could be defined as:
(1) Risks that can happen to the system (what). (2) Agents who can do it (who). (3) Motivation for making the risk (why). (4) Penetration tools and methodologies used for per-
forming the risk (how). (5) System components that can be targeted (where). (6) Component vulnerabilities that can be exploited by
agents (when).
There is a shortage of accurate historical data on SCADA incidents that can be used in the risk management process because of the confidential nature of this field [17]. However, there are some sources that gave us indications on the growing risk to SCADA systems. One of these sources is the RISI database [18], which contains 242 incidents through 2015. Another source is the ICS-CERT database [19], which recorded a growing number of vulnerabilities detected in ICS components (from 2 in 1997 to 189 vulnerabilities in 2015). There is also Bompard et al. [20], who counted 133 blackouts in SCADA systems in the field of power only from 1965 to 2011.
According to state-of-the-art methods, there was a gap in providing complete risk identification scenarios that fulfill the risk identification scenarios related to the six parameters stated in ISO 31000 [15]. Zhu et al. [21] gave abstracted information about system components and system vulnera- bilities. Hewett et al. [22] focused on four types of attacks that target wireless sensor networks. ICS-CERT [19] linked system components and component vulnerabilities. Stouffer et al. [23], Bompard et al. [20], and Zhu et al. [21] provided two individual maps, one between the risk and agent and the other between the risk and affected components without trying to merge the twomaps and expanding them to include the other risk identification parameters. Miller et al. [24], Gabriel et al. [25], and Nan et al. [11] defined the relation among risk, system components, and vulnerabilities without providing the relationship between these parameters with the agent, his motivation, and the penetration tools used.
This paper proposes an extensive model for identifying the risks to SCADA systems, which can be used as a base for the automatic generation of many SCADA risk scenarios.
In building the model, six parameters determined in ISO 31000 [15] and a hierarchical-based method were used, in which all risk parameters were defined with themost possible values and organized in the first level of the model. Then, these parameters were synchronously organized by linking each parameter with the most related ones in the form of matrices. Consequently, seven 2D matrices were built at the second level, which were gathered into four 3D matrices in the next level. Finally, the four 3D matrices were merged to build the complete proposed model based on a 6D matrix. This resulting matrix connected all the parameters together. The risk interdependency map was defined to represent the relationships among all risks in the model. This map illus- trated the direct and indirect dependency among the risks. Also, thismodel was transformed into a benchmark database, which contains 19,163 risk scenarios for SCADA systems.This benchmark database can be used to generate a risk scenarios knowledgebase that might help risk managers and decision makers to analyze, evaluate, and resolve the expected risks with either a proactive or reactive riskmanagement approach. Another use for this model and its benchmark database is in risk management simulation software, such as in the SCADA Risk Identification & Classification Engine (SRICE), a component of the Generic Software Risk Management Framework for SCADA Systems designed by Elhady et al. [26].
This paper is structured as follows. In Section 2, a review on previous work is provided. This review focused on risk identification phases of SCADA and ICS systems. Section 3 shows a comparative study among the available previous sci- entific articles, guidelines, and databases as well as a statistical summary. Section 4 defines the problem statement of the study. Then, the proposed comprehensive risk identification model for SCADA systems is presented in Section 5. The transformation of the model into a benchmark database and the brief statistics are presented as a DB summary in Section 6. Section 7 presents two case studies of the scenarios that could be provided by the proposed model and its database. Section 8 presents the conclusion and future work.
2. Risk Identification Literature Review
The literature review is outlined in three main categories: ICS/SCADA Risk Scientific researches, ICS/SCADA Risk repositories, and ICS/SCAD Risk reports and guides. This review covers the last decade from 2009 till 2018 to make it up to date with the latest ICT expressions and principles.
The main set of scientific papers was formed from the searches run on SCOPUS, ACM, Web of Science, and IEEE Explore, as recommended in Kitchenham and Brereton [27]. The search keywordswere based on two groups ofwords, with each paper containing at least one word from each group. The first group includes the words “risk,” “security,” “threat,” and “vulnerability”; whereas, the second group contains “SCADA” and “Industrial control system (ICS).” After that, the collected papers were filtered by focus on those that had interest in more than two parameters of risk identification in SCADA and ICS.
Security and Communication Networks 3
The second and third categories concentrated on databases and reports that had been issued by accredited academic and research organizations in the field of risk in SCADA and ICS systems. These organizations, like the National Institute of Standards and Technology (NIST) [28], European Union Agency for Network and Information Security (ENISA) [29], and the United States Department of Homeland Security (DHS) [30].
Our search produced thirteen papers, two databases, and six reports and guides, which will be presented in the next section. Then, a comparative study between them and the proposed model will be made in the last section of this paper.
2.1. ICS/SCADA Risk Scientific Studies (Papers). Nasser et al. [36] investigated cyber threats targeting physical systems. Theyproposed a classification based onfive parameters (types of attack, target sector, intention, impact, and incident cate- gory).They provided a matrix of these threats in conjunction with simple statistical data.Moreover, Finogeev and Finogeev [37] focused on attacks that target the SCADAwireless sensor network and that have been initiated by external agents.They classified attacks based on innovative impacts on SCADA components. Furthermore, Eden et al. [38] presented a global taxonomy for SCADA incidents’ response. They classified system assets into five categories based on risk impact. Three categories were based on safety process, timing, and location, while the other two categories are mission critical and business critical. They distinguished attacks into three types: hardware, software, and communication attacks. Woo and Kim [39] also identified fifteen types of threads and four SCADA system components. First, they linked between each thread and target component, and then they determined the vulnerabilities for each system component based on historical data and the component’s characteristics.
Hewett et al. [22] defined four types of attacks that can target SCADA sensor networks: Sybil attack, node compromise, eavesdropping, and data injection. For each attack, the researchers specified themethodology the attacker used to achieve the attack and the system components they may target. Miller et al. [24] proposed a framework for classifying cyber physical systems incidents. This framework relies on four dimensions: seven different source types, methods used in the incident, direct and indirect impact of incident, and victim of incident. However, Bompard et al. [20] classified threat origins into four types: natural threats, accidental threats, malicious threats, and emerging threats. They provided detailed descriptions on each type of threat and displayed their possible impacts on the system.
Gabriel et al. [25] proposed new approach for risk iden- tification and assessment in electricity infrastructure. They identified 21 main risks and 142 sub risks and classified them based on three criteria. The first criterion is the type of risk divided into technical and nontechnical risks. The second criterion is according to effect, in four categories: operational, environmental, financing, and quality compliance. The last criterion is according to risk severity, divided into critical, important, tolerable, and acceptance. Finally, they used a semi-quantitative methodology to rank these risks based on subjective assessment and specialist opinions. Nan et al. [11]
provided further investigation on the vulnerabilities resulting from the interdependency between the SCADA system and System Under Control (SUC). They displayed the negative impacts on each linking component: such as sensors, actua- tors, and RTU, due to attackers using these vulnerabilities and how tominimize these negative impacts. Guillermo et al. [40] distinguished the SCADA system into fivemain components: system, network, physical, employee, and information. They stated a very simplified set of vulnerabilities for each one of them. They also stated a few threats that can affect the system. Zhu et al. [21] outlined a general set of SCADA system vulnerabilities, such as insecure network, vulnerable oper- ating system, and misuse of encryption. They also classified threats based on target components like hardware, software, and communication stack and implemented protocols. Tsang [41] discussed SCADAnetwork attacks and incidents and dis- tinguished between accidental and intentional threats caused by threats agents and how they cause these threats. Further, they displayed a set of vulnerabilities in a SCADA network that can be used by threat agents.They summarized the set of actual attacks on a real-world SCADA network. Dong Kang et al. [42] presented thirty-two common computer system threats and spread themacross four parts of a SCADA system: control devices, communication links, control center, and communication with corporate network. This mapping was based on the probability of targeting these threats on those parts.
2.2. ICS/SCADA Risk Databases (Repositories). In 2001, Eric Byres and Mark Fabro developed a database for Indus- trial Control Systems (ICS). They called it the Repository of Industrial Security Incidents (RISI) [18]. This database focused on incidents, their caused agents, and which system’s components were affected. This database is flawed due to its small number of incidents recorded and the fact that it hasn’t been updated since January 2015.
The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) in the U.S. DHS developed a database that concentrates on the vulnerabilities of an ICS components’ platform rather than any other risk identification parameters like risk agents, their motivations, and the used penetration tools [19].
2.3. ISC/SCADA Risk Reports and Guides. Stouffer et al. [23] with NIST presented a guide for ICS security. This guide classified threats sources into four classes: adversarial, accidental, structural, and environmental. For each threat source, they described a sample of threats that can be caused by this class. Then they categorized the system into six categories: policy and procedure, architecture and design, configuration and maintenance, physical, software develop- ment, and communication and network. For each category, they listed its vulnerabilities.
The European Union Agency for Network and Infor- mation Security (ENISA) team presented report on com- munication network dependencies for ICS/SCADA Systems [32]. This report listed threats and vulnerabilities related to ICS/SCADA and showed eight attack scenarios. Each scenario targeted a main component of an ICS/SCADA
4 Security and Communication Networks
systemanddiscussed the steps that should be taken to prevent that attack scenario.
Brown andWylie [33] fromSANS Institute-InfoSec Read- ing Room team collected data from hundreds of specialists in the field of ICS security to produce an annual report on ICS’s most common risks. They provided statistics on the risks for each component in an ICS system and the threat agents that cause these risks.
The Trusted Information Sharing Network (TISN) for critical infrastructure reliance developed a generic SCADA risk management framework for Australian critical infras- tructure [34]. They classified threat agents into five classes based on scope, malicious intent, and nature. They also distinguished the system components into four main cate- gories: people, products, process, and reputation. Finally, they mapped each category of system components with all of their vulnerabilities and what class of threat agents can exploit these components.
DHS presented a report on CommonCyber Security Vul- nerabilities in ICS [35]. They classified these vulnerabilities into three categories: ICS software, ICS configuration, and ICS network security.
Schwab and Poujol from the Kaspersky lab team provided a report that summarized the state of ICS cybersecurity in 2018 in each geographical region all over the world [31]. They listed sixteen risks that could affect industrial systems’ operations. They also stated twelve vulnerabilities that can cause a negative impact on these systems.
3. Comparative Study
In this section, a comparative study among all previous studies is presented. The comparative study depends on two levels of comparison. The first level of comparison concentrates on individual risk identification parameters. Then these parameters are merged in two dimensions, three dimensions, and six dimensions parametermatrices and state the corresponding previous studies.
3.1. Single Parameter Mapping Comparison. In this compari- son, the previous works are distinguished based on number of risk identification parameters stated. As shown in Table 1, no single previous work had presented all parameters of risk identification.
The total number of parameters stated in each previous work is visualized in Figure 1. This figure shows that the biggest number of parameters stated in a previous work was five parameters, which was presented only one time in a scientific paper (Tsang [41]). There is one ICS report (ENISA [32]) and three scientific papers (Bompard et al. [20], Gabriel et al. [25], and Guillermo et al. [40]) that stated four parameters. The most parameters stated in a previous work were three parameters, which were stated in ten of the previous works. These ten works were classified as one database, three ICS reports and guides, and six scientific papers. Finally, the fewest parameters stated in a previous work was two, which was presented in six previous works, which are distributed as ICS-CERT database [19], two ICS reports and guides, and three scientific papers [11, 36, 37].
0
1
2
3
4
5
6
N o.
o f R
isk id
en tifi
ca tio
n' s
pa ra
m et
er s S
ta te
d
Pervious work Ref
IC S-C
ERT [1 9]
Byre s a
nd Fabro [1 8]
Schwab an d Poujol [3
1]
ENISA [3
2]
Brown an d W
yli e [
33 ]
Sto uffer
et al.
[23 ]
TISN [3
4]
DHS[3 5]
Nass er
et al.
[36 ]
Finogee v a
nd Finogee v [
37 ]
Eden et
al. [3
8]
Woo an d Kim
[3 9]
Hew ett
et al.
[2 2]
Mille r e
t a l. [
24 ]
Bompard et
al. [2
0]
Gabrie l et
al. [2
5]
Nan et
al. [1
1]
Guille rm
o et al.
[4 0]
Zhu et al.
[2 1]
Tsan g [
41 ]
Kan g e
t a l. [
42 ]
Figure 1: Total no. of risk identification parameters stated per previous works.
Another statistic is presented in Figure 2. This figure displays the total number of previous works stating each risk identification parameter. This shows that the most risk identification parameters stated in previous works were risk (What?) and system components (Where?), which were stated in sixteen previous works. Next parameter was com- ponent vulnerabilities (When?) in thirteen previous works, and then risk agent parameter in eleven previous works. Pen- etration technique (How?) was stated in six previous works. Finally, the risk identification parameter least presented in previous works was risk motivation (Why?), stated once in ENISA [32].
3.2. Multi-Parameters Mapping Comparison. In this section, all the previous works are compared based on mapping risk identification parameters into two, three, and six dimensional matrices. All the previous works were examined to discover if they stated these parameter mappings or if they provided another mapping. Finally, this examination is summarized in Table 2.
The comparative study data in Table 2 were collected based on the total number of mapping matrices stated in each previous work as shown in Figure 3. This figure shows that the maximum number of mapping matrices stated in the previous works were three mappingmatrices, which were presented in only three previous works: ENISA [32], Gabriel et al. [25], and Tsang [32].Then, there are five previous works thatmentioned only twomappingmatrices and nine previous works that mentioned only one mapping dimension. There are four previous works that didn’t mention any mappings between two or more of risk identification parameters.
Another statistic on the previous works was based on the total number of previous works mentioning each risk identification mapping matrix, as shown in Figure 4. This figure shows that the mapping between risk (What?) and system components (Where?) was the most-stated mapping in previous works, mentioned eight times. Then, the map- ping between system components (Where?) and component vulnerabilities (When?) was mentioned in several previous works.Themapping between risk agent (Who?) and penetra- tion techniques (How?) in a two-dimensional matrix was the
Security and Communication Networks 5
Table 1: Risk parameters stated in each work.
Paper Risk Agent
(WHO?)
Risk Motivations (WHY?)
Risk (WHAT?)
Penetration Technique (HOW?)
System Components (WHERE?)
Component Vulnerabilities (WHEN?)
Risk Interdependency
SCADA & ICS Risk Databases ICS-CERT [19] √ √
Byres and Fabro [18] √ √ √
SCADA & ICS Reports and guides Schwab and Poujol [31] √ √
ENISA [32] √ √ √ √ √
Brown and Wylie [33] √ √ √
Stouffer et al. [23] √ √ √
TISN [34] √ √
DHS [35] √ √
SCADA & ICS scientific research Nasser et al. [36] √ √
Finogeev and Finogeev [37] √ √
Eden et al. [38] √ √ √
Woo and Kim [39] √ √ √
Hewett et al. [22] √ √ √
Miller et al. [24] √ √ √
Bompard et al. [20] √ √ √ √
Gabriel et al. [25] √ √ √ √ √
Nan et al. [11] √ √ √
Guillermo et al. [40] √ √ √ √
Zhu et al. [21] √ √ √
Tsang [41] √ √ √ √ √
Kang et al. [42] √ √ √
Component Vulnerabilities (WHEN?)
System Components (WHERE?)
Penetration technique (HOW?)
Risk (What?)
Risk Motivations (WHY?)
Risk Agent (WHO?)
0 2 4 6 8 10 12 14 16 18
No. of papers
13
16
6
16
1
11
Figure 2: Total no. of previous works stated each risk identification parameter.
mappingmatrix least-mentioned, only appearing one time in a previouswork.There are fourmappingmatrices that weren’t mentioned at all in the previous works, as shown in the figure.
4. Risk Identification Problem in SCADA System
So far, many researchers have tried to study the risks in SCADA systems. Their trails are short and suffer from describing an efficient algorithm in identifying the risk class. Moreover, a correct definition for vulnerability in SCADA
is missed. This paper tries to map the relation between the effective parameters that identifying the SCADA risks and the whole scenario for specific risks.The whole scenario for risks is targeted through rebuilding a significant database collected from previous resources and then analysing the results. The problems that face other researches are assumed in the DB and summarized in the following points:
(1) Giving a detailed level of identifying the risks and classifying them based on the nature of the risk agents, their action’smotivation, and the penetration tools/techniques that can be used to cause a risk on a SCADA system.
6 Security and Communication Networks
Ta bl e 2: Ri sk
pa ra m et er sm
ap pi ng
sta te d in
ea ch
w or k.
Pa pe r
2D M at rix
3D M at rix
6D M at rix
O th er
M ap pi ng
W ho
/W hy
W ha t
/W ho
W ho
/H ow
W ha t
/H ow
W ha t
/W he re
W he re
/W he n
H ow
/ W he n
W ha t
/W ho
/W hy
W ha t
/W ho
/H ow
W ha t/
W he re
/W he n
W ha t
/H ow
/W he n
W ha t/W
ho /
W hy /H
ow /
W he re /W
he n
SC AD
A & IC S Ri sk
D at ab as es
IC S- CE
RT [19
] √
By re sa
nd Fa br o [1 8]
√ √
SC AD
A & IC S Re po rt sa
nd gu id es
Sc hw
ab an d Po
uj ol [3 1]
EN IS A [3 2]
√ √
√ Br ow
n an d W yl ie [3 3]
√ St ou
ffe re
ta l. [2 3]
√ √
TI SN
[3 4]
√ w ho
, w he re ,
w he n
D H S[ 35 ]
√
SC AD
A & IC S sc ien
tifi cr es ea rc h
N as se re
ta l. [3 6]
√ Fi no
ge ev
an d Fi no
ge ev
[3 7]
√
Ed en
et al .[ 38 ]
√ W oo
an d Ki m
[3 9]
H ew
et te ta l. [2 2]
√ M ill er
et al .[ 24 ]
Bo m pa rd
et al .[ 20 ]
√ √
w ha t/
w ho
/ w he re
G ab rie
le ta l. [2 5]
√ N an
et al .[ 11 ]
√ √
G ui lle rm
o et al .[ 40
] √
√
Zh u et al .[ 21 ]
√ √
w ha t/
w he re /
ho w
Ts an g [4 1]
√ √
√
Ka ng
et al .[ 42 ]
w ha t/
w he re /
ho w
Security and Communication Networks 7
0
0.5
1
1.5
2
2.5
3
3.5
N o.
o f R
isk id
en tifi
ca tio
n' s
pr am
et er
s' m
ap pi
ng
Previous work
IC S-C
ERT [1 9]
Byre s a
nd Fabro [1 8]
Schwab an d Poujol [3
1]
ENISA [3
2]
Brown an d W
yli e [
33 ]
Sto uffer
et al.
[23 ]
TISN [3
4]
DHS[3 5]
Nass er
et al.
[36 ]
Finogee v a
nd Finogee v [
37 ]
Eden et
al. [3
8]
Woo an d Kim
[3 9]
Hew ett
et al.
[2 2]
Mille r e
t a l. [
24 ]
Bompard et
al. [2
0]
Gabrie l et
al. [2
5]
Nan et
al. [1
1]
Guille rm
o et al.
[4 0]
Zhu et al.
[2 1]
Tsan g [
41 ]
Kan g e
t a l. [
42 ]
Figure 3: Total no. of risk identification parameters per previous work.
What/Who/Why/How/Where/When What/How/When
What/Where/When What/Who/How What/Who/Why
How/When Where/When Where/When What/Where
What/How Who/How
What/WhoRi sk
id en
tifi ca
tio n
m ap
pi ng
m at
rix es
0 1 2 3 4 5 6 7 8 9
No. of previous works
Figure 4: Total no. of risk identification parameters mapping stated per previous work.
(2) Providing all possible components that formulate a SCADA system and state all known vulnerabilities that can be used by attackers to perform the attack.
(3) Mapping between risks, vulnerabilities, and system components by linking each risk with all possible vulnerabil- ities of system’s components that an attack agent can utilize to achieve the risk goals. A description of the estimated impact on that component as a result of an attack is also missing.
(4) Description of the interdependency among threats that can be used to present the possible attack path scenarios.
The main point in this work depends on the hierarchal- based method. The relation among related parameters is converted into matrices, which are linked synchronously to construct an augmented matrix with six dimensions, which is analyzed.
5. The Comprehensive Risk Identification Model for SCADA System
The risks that face SCADA were studied through a set of vulnerability resource databases, such as ICS-CERT [19], NVD [43], CVE [44], Bugtraq [45], OSVDB [46], Mitre [47], and exploit-DB; incidents repositories such as RISI [18]; and annual reports related to threats in the field of industrial
control systems and SCADA systems. These reports and guides were collected from NIST [28], and ENISA [29].
The collected information were organized and classified in the form of six main risk identification parameters, (What, Who, Why, How, Where, and When). Then, an analytical study that defines the relations among these parameters draws a complete view of the risk scenarios. Each scenario can define the risk affection on the SCADA system (What), the source of that risk (Who), the reasonable motivations behind performing specific actions (Why), penetration tools andmethodologies that cause the risk (How), possible system components wherever an attack can be targeted (Where), and the existing vulnerabilities in components when a threat source can execute his attack (When).
The hierarchical-based methodology was used to build the proposed model. The hierarchal tree consists of four levels. The first level aims to define each parameter’s val- ues. The consequent level is constructed by mapping each parameter with the most related parameters. Seven matrices are constructed in the second level. Hence, collections of matrices are similarly constructed based on reducing the number of neighbors and augmenting the relation among parameters in the next levels. By the third level, four matrices are constructed bymerging the sevenmatrices in the previous
8 Security and Communication Networks
Component Vulnerabilities
(When?)
System Components
(Where?)
Risks (What?)
Penetration Tools
(How?)
Risk Motivations
(Why?)
Risk Agents (Who?)
Where/WhenWhat/WhereHow/WhereWho/Howwhat/WhoWho/Why What/How
What/ Where/WhenWhat/ How/ WhereWhat/ Who/ HowWhat/ Who/ Why
What/ Who/ Why/ How/ Where/ When
Figure 5: The hierarchical methodology of the proposed model.
step. Finally, full-risk scenarios matrix is constructed by developing an algorithm used to relate all 3Dmatrices in level three and produces complete risk scenarios, as illustrated in Figure 5. The defined steps are stated as shown in the following steps:
5.1. Step 1. Define the six main parameters (risks, risk agents, agent motivation, system’s components, system’s vulnerabili- ties, risk’s penetration methodologies).
Risk (What?) defines the list of initial incidents that can threaten the SCADA system. These incidents cause a negative impact on a system’s availability, integrity, and/ or confidentiality, which leads to defects in achieving the system’s objectives and functionality. Risk agent (Who?) defines the list of themost possible risk agents [18, 23, 32] that represent the sources of any risk affecting the system either accidentally or intentionally.These agents are classified based on a set of features [14]:
(i) Nature: human agent and natural agent.
(ii) Scope: internal agent and external agent.
(iii) Intention: agent’s action that causes risk could be intentional and accidental.
(iv) Strength: for human agent, the strength feature expresses the overall characteristics to successfully execute risk. This feature has been calculated based on three characteristics (capability, knowledge, and skills) of a human agent [48]. For a natural agent, the strength feature represents the power of natural phenomena. This feature has been ranked into three levels: low, medium, and high.
This classification helps us understand the risk motivations for each agent. Risks can result from these motivations, as we will illustrate in the next sections. Any risk that occurs in a SCADA system has at least one reason. This reason incites the agent to carry out his attack on the system. The risk motivations (Why?) parameter defines these reasons. The system components (Where?) parameter defines the physical devices of a SCADA system that can be targeted for an attack. The most physical components of the SCADA system are categorized into eight main categories based on technical and functional characteristics of the component. The component vulnerabilities (When?) parameter illustrates the conditions when their existence could lead to or facilitate the risk agent from initiating his attack on the system. The penetration technique (How?) parameter defines the most common penetration methodologies, techniques, and tools that risk agents can use to exploit a system’s vulnerabilities and/or cause harm to one or more system components.
The six main parameters of the proposed model are listed in Table 3. This table lists 27 risks, 24 risk agents, 7 risk motivations, 14 penetration tools, 36 vulnerabilities, and 30 system components.
5.2. Step 2. In this step, the interdependency risk map, the cascading effect among all risks listed in step 1, is counted as shown in Figure 6. This map provides the common possible attack paths that can be used by risk agents to reach a specific risk. It also defines the direct and indirect effect of any risk.
For example, the data disclosure risk can conclude from this map where all possible attack paths that lead to data disclosure are declared, as shown in Figure 7. There are three paths leading to the data disclosure risk at the end. These paths are as follows:
Security and Communication Networks 9
Ta bl e 3: Ri sk
Id en tifi
ca tio
n Si x Pa ra m et er s.
Ri sk
(W ha t?) :
Ri sk
Ag en ts (W
ho ?) :
Ri sk
M ot iv at io ns
(W hy ?) :
Sy ste
m Co
m po ne nt s( W he re ?) :
Co m po ne nt
Vu ln er ab ili tie s( W he n? ):
Pe ne tra
tio n te ch ni qu e( H ow
?) :
(1 )H
um an
ris ks
(R 19 :In
ap pr op
ria te co nt ro l
co m m an ds )
(2 )P
hy sic al ris ks
(R 20 :S ite
pe ne tr at io n,
R1 :P hy sic
al th eft
of ha rd w ar e, R2
:D ev ic e
po w er
fa ilu
re ,
R3 :D es tr uc tio
n of
ha rd w ar e,
R6 :S ite -b
ui ld in g
de str
uc tio
n, R7
:N et w or k
w ire
ss te al in g, R8
:N et w or k
w ire
sd am
ag e, R1 5: Ph
ys ic al
th eft
of da ta ,R
22 :H ar dw
ar e
fa ilu
re ,R
24 :D
isa bl eD
ev ic e,
an d R2
7: Eq
ui pm
en tc ra sh )
(3 )S
o� wa
re ris ks
(R 4:
D ev ic ec
om pr om
ise ,R
5: D ev ic em
isc on
fig ur at io n,
R1 6: G ai n ph
ys ic al ac ce ss ,
R1 7: G ai n re m ot ea
cc es s,
R1 8: Id en tif y ne tw or k
de vi ce s, R2
1: G ai n de vi ce
ad m in ist ra to rp
as sw
or d,
R2 3: By
pa ss D ev ic ea
dm in
pa ss w or d, R2
5: N et w or k
ou ta ge ,R
26 :S oft
w ar e
fa ilu
re )
(4 )D
at a ris ks
(R 9: N et w or k
w ire
le ss sig
na ld
isr up
tio n,
R1 0: D at as
ni ffi ng
,R 11 :D
at a
in te rc ep tio
n, R1 2: D at a
di sto
rt io n,
R1 3: D at a
di sc lo se r, R1 4: Lo
sin g da ta )
(A 1) Cu
rr en tE
m pl oy ee
(A 2)
Fo rm
er Em
pl oy ee
(A 3)
Cu rr en tb
us in es sp
ar tn er .
(A 4)
Fo rm
er bu
sin es sp
ar tn er
(A 5)
Cu sto
m er
(A 6)
Sc rip
tK id ie s
(A 7)
In du
str ia ls pi es
(A 8)
O nl in es
oc ia lh
ac ke r
(A 9)
C or po
ra te /c om
pe tit or s
(A 10 )H
ac kt iv ist
(A 11 )C
yb er -c rim
in al gr ou
p (A
12 )C
yb er
te rr or ist
(A 13 )N
at io na ls ta te
(A 14 )E
ar th qu
ak es
(A 15 )F
lo od
s (A
16 )T
su na m is
(A 17 )L
an ds lid
es (A
18 )L
ig ht ni ng
(A 19 )H
ea vy
ra in s
(A 20 )H
ea vy
sn ow
fa lls
(A 21 )T
or na do
(A 22 )W
ild fir e
(A 23 )F
ire s
(A 24 )E
xp lo sio
ns
(M 1) C on
ve ni en ce .
(M 2)
M on
et iz at io n
(M 3)
Re ve ng
e. (M
4) So
ci al ly.
(M 5)
Id eo lo gi ca lly
(M 6)
N at io na lly .
(M 7)
En vi ro nm
en ta l
ch an ge s.
(1 )R
em ot es
ta tio
n (R T1 :s en so r,
RT 2: ac tu at or ,R
T3 :R
TU ,R
T4 :P
LC an d RT
5: IE D ).
(2 )C
om m un
ic at io n de vi ce
(C D 1:
sw itc h, CD
2: ro ut er ,C
D 3: re pe at er ,
CD 4: m od
em ,C
D 5: W LA
N ac ce ss
po in ta nd
CD 6: Fi re w al l).
(3 )W
ire m ed ia (W
M 1: co ax ia l
ca bl e, W M 2: tw ist ed
pa ir ca bl ea
nd W M 3: Fi be ro
pt ic ca bl e) .
(4 )W
ire le ss m ed ia (W
LM 1: ra di o
fre qu
en cy ,W
LM 2: m ic ro w av ea
nd W LM
3: sa te lli te ).
(5 )M
as te rs ta tio
n (M
S1 :
co m m un
ic at io n se rv er ,M
S2 :
SC A D A se rv er ,M
S3 :h ist or ia n
Se rv er
an d M S4 :H
M I)
(6 )C
or po
ra te ne tw or k (C
N 1:
Ap pl ic at io n se rv er ,C
N 2: w eb
se rv er ,C
N 3: m ob
ile se rv er ,T
R1 :
PC /la
pt op
an d TR
2: sm
ar t
ph on
e/ ta bl et ).
(7 )P
eo pl e( PE
1: sy ste
m em
pl oy ee s,
PE 2: sy ste
m cli en ts an d PE
3: 3r d
pa rt y stu
ff) .
(8 )B
S1 :B
ui ld in g & sit e.
(1 )H
um an
er ro rs (V
1: di sp la y in fo rm
at io n ab ou
tt he
sy ste
m an d w ho
op er at ei t, V 2: un
qu al ifi ed
em pl oy ee ,V
3: Le ak
of sk ill s, kn
ow le dg ea
nd tr ai ni ng
,V 4: Sh
ar in g pa ss w or d am
on g
us er s, V 5: pa ss w or d di sc lo su re ,V
6: Fo
rm er
em pl oy ee s/ co nt ac to re
xp os et he ir sy ste
m kn
ow le dg et o
ex te rn al pe rs on
s, V 7: Ac
co un
ts til la ct iv at ed
fo rf or m er
em pl oy ee
an d pa rt ne rs ,V
13 :U
sin g de fa ul tp
as sw
or d, V 14 :
N o pa ss w or d us ed ,V
15 :U
sin g w ea k pa ss w or d po
lic es ,V
27 :
In ap pr op
ria te or
un au th or iz ed
ac ce ss co nt ro ls,
V 36 :L
ac k of
re m ot ea
cc es sc
on tro
l) (2 )P
hy sic al vu ln er ab ili tie s( V 8: Is ol at ed
sit es ,V
9: Po
or m ai nt e n an ce ,V
10 :A
bs en ce
of al ar m
sy ste
m ,V
11 :W
ea k
w in do
w sa
nd do
or sc
on tro
lli ng
,V 12 :L
ac k or
w ea k of
ph ys ic al se cu rit y to ol s, V 24 :L
ac k of
di ve rs ity
in co m m un
ic at io n pa th sl ea d to
co m m un
ic at io n fa ilu
re ,V
28 :
Ab se nc eo
fu ps
an d po
w er
ge ne ra to rn
ot ex ist s, V 29 :
A ir- co nd
iti on
in g fa ilu
re ,V
30 :L
ac k of
re du
nd an th
ar dw
ar e,
V 33 :N
o w ar ra nt y ag re em
en t, V 34 :N
o sp ar es
m an ag em
en t)
(3 )S
o� wa
re vu ln er ab ili tie s( V 18 :C
rit ic al co nfi
gu ra tio
ns ar e
no ts to re d or
ba ck ed
up ,V
20 :O
pe n
co m m un
ic at io n/ un
pr ot ec te d pr ot oc ol sa
re us ed ,V
25 :P oo
r or
no n- ex ist en ts oft
w ar eu
pd at es ,V
21 :U
ns ec ur ed
w ire
le ss
ne tw or ks ,V
26 :U
ns ec ur ed
ph ys ic al po
rt s, V 31 :I nt ru sio
n de te ct io n/ pr ev en tio
n so ftw
ar en
ot us ed ,n
ot up
da te d, or
no t
te ste
d, V 32 :A
nt i-v
iru s/ an ti- m al w ar en
ot us ed ,n
ot up
da te d,
or no
tt es te d, V 33 :N
o w ar ra nt y ag re em
en t, V 35 :M
em or y
ov er flo
w )
(4 )D
at a vu ln er ab ili tie s( V 16 :S en sit iv ed
at au
np ro te ct ed
w ith
en cr yp tio
n an d pa ss w or d pr ot ec tio
n, V 17 :U
np ro te ct ed
da ta
tr an sfe
rr ed ,V
19 :A
bs en ce
or un
te ste
d ba ck up
pr oc ed ur e,
V 22 :S ys te m
lo g no
tm ai nt ai ne d or
re vi se d pe rio
di ca lly ,V
23 :
Se ns iti ve
da ta ar en
ot en cr yp te d in
tr an sit )
(P T1 )S
oc ia le ng
in ee rin
g/ ph
ish in g.
(P T2
)I nt er ce pt io n/ ea ve sd ro pp
in g/ es pi on
ag e.
(P T3
)E xp lo it ki ts.
(P T4
)M al ic io us
co de .
(P T5
)S pa m m in g.
(P T6
)W eb -b as ed
at ta ck s.
(P T7
)W eb
ap pl ic at io n at ta ck s.
(P T8
)B ot ne ts.
(P T9
)S po
ofi ng
. (P T1 0)
Ph ys ic al at ta ck .
(P T1 1) D isa
ste r
(g eo lo gi ca l/h
yd ro lo gi ca l/m
et eo ro lo gi ca l).
(P T1 2)
H um
an er ro r/ m isu
se of
re so ur ce s.
(P T1 3)
M al fu nc tio
n of
eq ui pm
en t.
(P T1 4)
D at am
an ip ul at io n or
fro gi ng
.
10 Security and Communication Networks
Site penetration
Site- building destruction
Gain physical access
Physical the� of hardware
Device power failureDestruction of
hardware
Equipment crach
Hardware failure
Network wires damage
Network wires stealing
Physical the� of data
Data sniffing Gain remote access
Data interception
Bypass Device admin passwordIdentify network
devices
Gain device admin
password
Data disclosure
Device Disabled
Network outage
Losing data Network
wireless signal disruption
So�ware failure
Device mis- configuration
Inappropriate control
commands
Device compremise
Data distortion
Figure 6: Interdependency risk map for the proposed model.
Gain physical access Data sniffing
Data discloserPhysical the� of data
Physical the� of hardware
site penetration
1,2
1
12
2,3
3 3
Figure 7: Interdependency risk map for data discloser risk.
(1) Site penetration -> Gain physical access -> Data sniffing Data discloser.
(2) Site penetration -> Gain physical access -> Physical theft of data - >Data discloser
(3) Site penetration -> Physical theft of hardware -> Physical theft of data - >Data discloser
5.3. Step 3. In this step, each parameter is linked to the most related parameters of the risk identification in a 2D matrices form in which all values of one parameter are organized in horizontal direction (row headers) and all values of the related parameter are organized in the vertical direction (col- umn headers). Each intersection between one column and one row represents the existing relation between the values of
Security and Communication Networks 11
the intersected row and column.This relation has two values, true (√) and false (null). Consequently, 2D matrices are built based on the collected information from the works in the literature review. The constructed seven 2D matrices present a complete view of the relation among all risk identification parameters.
The first 2D matrix, labeled (who/why), describes the relations between risk agents (who) and risk motivations (why). All risk agents are listed as row headers, and all risk motivations are listed in column headers, as shown in Figure 8. The risk motivation for each agent is classified based on agent intention feature. For example, the current employee agent has a convenience motivation only for acci- dental intention. On the other hand, the current employee has monetization and revenge motivations for intentional intention. The competitor has monetization, revenge, and social motivations.
Similarly, the other six matrices have been built. The matrix (what/who) describes the relation between risk agents (who) and risks (what) that were caused by each agent. All risk agents represent the row headers and all risks represent the column headers, as shown in Figure 9. The matrix (who/how) defines the relation between the risk agents (who) and penetration techniques (how) to illustrate the agent’s penetration tools that cause system risks. In this matrix, all risk agents represent row headers and all penetration tech- niques represent the column headers, as shown in Figure 10 The matrix (what/how) defines the relation between risks (what), which represent the column headers, and the pene- tration techniques (how), which represent the row headers, as shown in Figure 11.The (what/where) matrix defines the rela- tion between risks (what) and system components (where) in which these risks can occur. The risks list represents the columnheaders and all system components represent the row headers, as shown in Figure 12. The (where/when) matrix defines the relation between system components (where) and their vulnerabilities (when), in which their existence could result in a risk, as shown in Figure 13. Finally, the (when/how) matrix defines the relation between component vulnerabilities (where) and penetration techniques (how), which can cause these vulnerabilities to create risk, as shown in Figure 14.
5.4. Step 4. Another merge step is represented where both 2D matrices from step 3 are joined to form a 3D matrix to build a partial risk scenario. Each matrix is organized as two related columns and a single row. The first column rep- resents the most significant parameter. The second column represents all correlated values of the second parameter. A many–many corresponding relationship is defined between the first parameter and the second parameter values. The other columns’ headers represent the values of the third parameter. The mapping of these three parameters defines all values of the third parameter related to the other two parameters. Each intersection between each column and each row represents the relation between the values of the intersected row and column. Also, this relation has two values, true (√) and false (null).
The first 3D matrix joins the related two 2D matrices (Who/Why and What/Who), where risk agent (who) joins the two matrices. This matrix answers the question of what risk can be caused by an agent and his motivation. In this matrix, all risk agents have been listed in the first column. For each risk agent value, the risk motivations are presented using (who/why) matrix. On the other hand, all risks are represented as columns header. Using the (what/who)matrix, the first row of each risk agent displays all risks that can be caused by that agent. The following rows for that agent are constructed in conjunction with the risk motivation, where each row defines a specific agent and certain motivation. All checked risks from the first row of that agent are oriented on the agent/motivation rows based on each agent and motivation nature for that risk, as shown in Figure 15.
For example, the current employee agent has the first four rows. The first one represents all risks that can be done by the current employee. The next three rows represent all risks that can be done by the current employee for a specific risk motivation (convenience, monetization and revenge).
The second 3D matrix combined three 2D matrices from step 3 (what/who, what/how, and who/how) into one 3D matrix of (what/who/how). This 3D matrix answers the question of what risk can happen (what) from which agent (who) and which penetration tool (how). In this matrix, the first column represents all risk agents and the second column represents all penetration techniques for each agent using the (who/how) matrix. All risks are displayed from the third column up to the end of the risk. The first row of each risk agent displays all risks that can be caused by that agent using the (what/who) matrix. The following rows for that agent are made in conjunction with penetration techniques where each row defines a specific agent and certain penetration technique. All checked risks from the first row of that agent are oriented on the agent/penetration technique rows based on each agent and penetration technique he can use to cause that risk using the (who/how) matrix, as shown in Figure 16.
The third 3D matrix joined the two 2D matrices from step 3 (what/where and where/when) into one 3D matrix (what/where/when). This matrix answers the question of what risks exist (what) in what system components (where) that have specific vulnerabilities (when). In this matrix, all system components are listed in the first column. For each system component value, risks that can occur for that component are presented using the (what/where) matrix. All vulnerabilities are organized from the third column up till the end of the vulnerabilities. The first row of each component displays all vulnerabilities that can exist for that component using the (where/when) matrix. The following rows for that component are made in conjunction with risk where each row defines specific component and certain risk. All checked vulnerabilities from the first row of that component are oriented on the component/risk rows based on each component and risk that can exploit that vulnerability to successfully achieve that risk. This 3D matrix has two types of mappings between risk and vulnerabilities. The first one defines the risks directly occurring due to the existence of a specific vulnerability. This type is presented as the yellow color cells. The other type defines the risks that indirectly
12 Security and Communication Networks
Figure 8: Snapshot of who/why matrix.
current Employee
Risk Incident
Physi cal
th e�
of
hard ware
Devi ce
power fai
lure
dest ructi
on of
hard ware
devi ce
comprem ise
devi ce
misc onfigura
tio n
site - b
uil ding
dest ructi
on
netw ork wire
s
ste alin
g
netw ork wire
s
dam age
netw ork wire
les s
sig nal d
isr upti
on
data sn
iffi ng
data in
ter cep
tio n
data disto
rtio n
data disc
loser
losin g d
ata
Physi cal
th e�
of d ata
gai n physi
cal ac
ces s
gai n re
mote a cce
ss
iden tify
netw ork
devi ces
inapp rop
rat e c
ontro l
comman ds
site penetr
ati on
gai n devi
ce
ad minist
rat or
pass word
hard ware
fai lure
byp ass
pass word
val idati
on
Devi ce
Disa bled
netw ork outag
e
so�ware fai
lure
equipment c rac
h
Former Employee Current business partner (Contractor-provider-suppliers) Former business partner (Contractor-provider-suppliers) Customer Script Kidies industrial spies Online social hacker Coroperate / Competitors Hacktivist Cyber Criminal group Cyber Terrorist National state Earthquakes Floods Tsunamis Landslides Lightning Heavy rains Heavy snowfalls Tornado Wildfire Fires Explosions
Agent
Figure 9: Snapshot of who/what matrix.
exist due to that vulnerability. This type is presented as red color cells, as shown in Figure 17. This mapping used the interconnected risk map shown in Figure 6 to determine the indirect risks from a specific vulnerability.
The final 3D matrix merged the (what/how) matrix with the (when/how)matrix to generate a new 3Dmatrix of (what/ how/when). This matrix defines the vulnerabilities (when) and which penetration tools (how) can use them to cause certain risks (what). In thismatrix, the first column represents all risks, and the second column represents all penetration techniques for each risk using the (what/how) matrix. All vulnerabilities are displayed from the third column up to the end of the vulnerabilities, as shown in Figure 18.
5.5. Step 5. The consequent step aims to generate the com- plete scenarios by combining the four 3D matrices. The complete risk identification scenarios for SCADA systems are defined by Algorithm 1.
6. A Benchmark Database for the Proposed Model
A benchmark database was developed using the proposed model. This database uses MySQL DB version 5.7.19 MySQL [49] as the database engine. As shown in Figure 19, the Entity Relationship Diagram (ERD) of the database contains 11 tables: one table for coding each risk parameter and
Security and Communication Networks 13
Agent social engineering / phishing
interception/ eavesdropping / espionage
Exploit kits
malicious code Spamming
Web-based attacks
Web application attacks Botnets spoofing
physical attack Disaster
human error /misuse of resources
malfunction of equipement
data manipulation or froging
current Employee
Former Employee Current business partner Former business partner Customer Script Kidies industrial spies Online social hacker Coroperate / Competitors Hacktivist Cyber Criminal group Cyber Terrorist National state Earthquakes Floods Tsunamis Landslides Lightning Heavy rains Heavy snowfalls Tornado Wildfire Fires Explosions
Penetration Techniques
Figure 10: Snapshot of who/how matrix.
Risk Penetration technique
Physi cal
th e�
of
hard ware
Devi ce
power fai
lure
dest ructi
on of
hard ware
devi ce
comprem ise
devi ce
misc onfigura
tio n
site - b
uil ding
dest ructi
on
netw ork wire
s
ste alin
g
netw ork wire
s
dam age
netw ork wire
les s
sig nal d
isr upti
on
data sn
iffi ng
data in
ter cep
tio n
data disto
rtio n
data disc
loser
losin g d
ata
Physi cal
th e�
of d ata
gai n physi
cal ac
ces s
gai n re
mote a cce
ss
iden tify
netw ork
devi ces
inapp rop
rat e c
ontro l
comman ds
site penetr
ati on
gai n devi
ce
ad minist
rat or
pass word
hard ware
fai lure
byp ass
pass word
val idati
on
Devi ce
Disa bled
netw ork outag
e
so�ware fai
lure
equipment c rac
h
social engineering / phishing interception/ eavesdropping / espionage Exploit kits(sw / fw) malicious code Spamming Web-based attacks Web application attacks Botnets spoofing physical attack Disaster ( heat/ water / wind/ land sliding) human error /misuse of resources malfunction of equipement data manipulation or froging
Figure 11: Snapshot of what/how matrix.
four tables for mapping the 3D matrices (agent mot risk, agent tool risk, comp risk vuln and risk vuln tool). The last table (Risk scenarios) contains the full risk scenarios matrix for the SCADA system,whichwas generated usingAlgorithm 1.
The risk scenario table resulting from Algorithm 1 con- tains 19,163 scenarios. Figures 20, 21, 22, and 23 show the total number of risk scenarios for each risk, risk agent, risk motivation, and penetration tool, respectively.
7. Case Study
In this section, a case study of the proposed model and the resulted database is presented. This case study shows a short sample of the detailed data about the possible risks scenarios that could occur in a SCADA system and that could be used further by decision makers and risk managers. This data can
help managers to determine the weak points in the system, the possible risk agents, causes that make them attack the system, and the tools and methodologies agents can use to perform these attacks. Also, the benchmark database that was produced by this model could be used to generate a SCADA risk knowledgebase for SCADA Risk Management simulation tools. To the best of our knowledge, this level of detailed information presented by the proposed model and resulted database hasn’t been provided by any type of related research work or database.
7.1. Case Study 1. One of the questions that can be answered by the proposed model is what are the possible risks that risk agents can use to attack a SCADA system and what are the risk scenarios for these attacks?
To answer this question, the proposed model will be applied on Hacktivist as an example of risk agents. The
14 Security and Communication Networks
System Components
Risk
Physi cal
th e�
of
hard ware
Devi ce
power fai
lure
dest ructi
on of
hard ware
devi ce
comprem ise
devi ce
misc onfigura
tio n
site - b
uil ding
dest ructi
on
netw ork wire
s
ste alin
g
netw ork wire
s
dam age
netw ork wire
les s
sig nal d
isr upti
on
data sn
iffi ng
data in
ter cep
tio n
data disto
rtio n
data disc
loser
losin g d
ata
Physi cal
th e�
of d ata
gai n physi
cal ac
ces s
gai n re
mote a cce
ss
iden tify
netw ork
devi ces
inapp rop
rat e c
ontro l
comman ds
site penetr
ati on
gai n devi
ce
ad minist
rat or
pass word
hard ware
fai lure
byp ass
ad min
pass word
Disa ble D
evi ce
netw ork outag
e
so�ware fai
lure
equipem ent c
ras h
Sensor c1
Actuator c2
RTU c3
PLC c4
IED c5
Switch
Router
Repeater
Modem
WLAN access point
Firewall
Coaxial cable
Twisted pair cable
Fiber optic cable
Radio frequency
Microwave
satellite
Communication server
SCADA Server
Historian Server
HMI
Application server
Web server
Mobile server
PC / labtop
Smart phone/ tablet
System employees
System Clients
3rd party stuff
Building & site
Figure 12: Snapshot of what/where matrix.
Building & site
Sensor c1
Actuator c2
RTU c3 PLC c4 IED c5 Switch Router Repeater Modem WLAN access point
Firewall Coaxial cable
Twisted pair
cable
Fiber optic cable
Radio frequency
Microwave satellite Communication
server SCADA Server
Historian Server
HMI Application
server Web
server Mobile server
PC / labtop
Smart phone/ tablet
System employe
es
System Clients
3rd party stuff
Building & site
display information about the system and who operate it unqualified employee
leak of skills, knowledge and training sharing password among users password disclosure former employees / contactor expose their system knowledge to external persons account still activated for former employee and partners isolated sites Poor maintenance apsence of Alarm system weak Windows and Doors controlling Lack or weak of Physical Security Tools
using default password No password used using weak password polices sensitve data unprotected with encryption and password protection unprotected data transefered Critical configurations are not stored or backed up apsence or untested backup procedure Open communication / unprotected protocols are used Unsecured wireless networks system log not maintained or revised periodicaly
Passwords are not encrypted in transit Lack of diversity in communication paths lead to communication failure Poor or non-existent so�ware updates magement Unsecured physical ports Inappropriate or unauthorized access controls absence of UpS and power generator not exists airconditioning failure lack of reduendent hardware introsion detection / prevention so�ware not used, not updated, or not tested anti-virus / anti-mulware not used , not updated, or not tested no warranty agreement No spares management Memory overflow lack of remote access control
Master station corporate network People
Vulnerability
Remote station Communication device wire media Wireless media
√ √
√ √ √ √ √ √ √ √ √ √
√ √ √
√ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √
√ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
Figure 13: Snapshot of where/when matrix.
steps of the proposed model will be followed to reach the full description of risk scenarios that can exist because of the Hacktivist risk agent. Given the predefined lists of six risk identification parameters, as stated in step 1 of the proposed model, in the upper level the following steps will be performed:
(1) Build the following seven 2D matrices that define the relation between Hacktivist and other risk identifica- tion parameters.
(a) Themotivation ofHacktivist is ideologically and socially (Who/Why matrix).
(b) Risks Hacktivist can cause are destruction of hardware, device compromise, and device mis- configuration (What/Who matrix).
(c) Penetration tools Hacktivist can use are physical attack, malicious code, Web-based attacks and Web application attacks (Who/How matrix).
(d) The relation between each risk Hacktivist can cause and one of his penetration tools he can use is defined in the What/How matrix, such as compromising a device using malicious code or a web-based attack.
Security and Communication Networks 15
Figure 14: Snapshot of when/how matrix.
Risk Agent Risk Motivations
Risk
Physi cal
th e�
of
hard ware
Devi ce
power fai
lure
dest ructi
on of
hard ware
devi ce
comprem ise
devi ce
misc onfigu
rat ion
site - b
uild ing
dest ructi
on
netw ork wire
s
ste ali
ng
netw ork wire
s
dam age
netw ork wire
les s
sig nal d
isr uptio
n
data sn
iffi ng
data in
ter cep
tio n
data disto
rti on
data disc
loser
losin g d
ata
Physi cal
th e�
of d ata
gai n physi
cal ac
ces s
gai n re
mote a cce
ss
identify netw
ork
devi ces
inapproprat e c
ontro l
comman ds
Risk Agent Risk Motivations
current Employee √ √ √ √ √ √ √ √ √ √ √ current Employee Convenience √ √ √ √ √ √ √ √ √ √ current Employee Monetization √ √ √ current Employee Revenge √ √ √ √ √ √ √ √ Former Employee √ √ √ √ √ √ √ √ √ √ √ √ √ √ Former Employee Convenience √ √ √ Former Employee Monetization √ √ √ √ √ √ √ √ √ Former Employee Revenge √ √ √ √ √ √ √ √ √ √ √ Former Employee Socially √ √ √ Current business partner √ √ √ √ √ √ √ √ Current business partner Convenience √ √ √ √ √ √ Current business partner Monetization √ √ √ √ √ √ √ √ Former business partner √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ Former business partner Convenience √ √ √ √ √ Former business partner Monetization √ √ √ √ √ √ √ √ √ √ Former business partner Revenge √ √ √ √ √ √ √ √ √ √ √ √ Customer √ √ √ √ Customer Convenience √ √ Customer Monetization √ √
Figure 15: Snapshot of what/who/why matrix.
Agent Penetration Tools Risk
Physi cal
th e�
of
hard ware
Devi ce
power fai
lure
dest ructi
on of
hard ware
devi ce
comprem ise
devi ce
misc onfigu
rat ion
site - b
uild ing
dest ructi
on
netw ork wire
s
ste ali
ng
netw ork wire
s
dam age
netw ork wire
les s
sig nal d
isr uptio
n
data sn
iffi ng
data in
ter cep
tio n
data disto
rti on
data disc
loser
losin g d
ata
Physi cal
th e�
of d ata
gai n physi
cal ac
ces s
gai n re
mote a cce
ss
identify netw
ork
devi ces
inapproprat e c
ontro l
comman ds
site pen
etr ati
on
gai n devi
ce
ad ministr
ato r
pass word
hard ware
fai lure
data manipulation or froging √ √ Cyber Criminal group √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
social engineering / phishing √ Exploit kits(sw / fw) √ √ √ √ √ √ malicious code(worm / trojan/ virus) √ √ √ √ √ √ √ √ √ Spamming √ √ √ √ Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)
√ √ √ √ √ √
Web application attacks(SQL injection / Code Injection / cross-site scripting/ DDoS attacks)
√ √ √ √ √ √ √
Botnets spoofing (E-mail/ IP Address / identity) √ √ √
physical attack (sabotage /vandalism/ the� /terrorism)
√ √ √ √ √ √ √ √ √ √
data manipulation or froging √ √ Cyber Terrorist √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √
malicious code(worm / trojan/ virus) √ √ √ √ √ √ √ √ √ Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)
√ √ √ √ √ √
Figure 16: Snapshot of what/who/how matrix.
16 Security and Communication Networks
Poor or non-existent so�ware updates management – vulnerabilities to communications equipment routers, switches, firewalls
Unsecured physical ports
Inappropriate or unauthorized access controls
absence of UpS and power generator not exists
airconditioni ng failure
lack of reduendent hardware
introsion detection / prevention so�ware not used, not updated, or not tested
anti-virus / anti- mulware not used , not updated, or not tested
no warranty agreement
No spares manage ment
Memory overflow
lack of remote access control
so�ware failure equipement crash
SCADA Server Physical the� of hardware Device power failure destruction of hardware device compremise device misconfiguration data sniffing data interception data distortion data discloser losing data Physical the� of data gain physical access gain remote access inapproprate control commands identify network devices gain device administrator password hardware failure bypass admin password Disable Device network outage so�ware failure equipement crash
Historian Server Physical the� of hardware Device power failure destruction of hardware device compremise
Component Risk
Vulnerabilities
Figure 17: Snapshot of what/where/when matrix.
Risk Peneteration Tool
Unsecured wireless networks
system log not maintained or revised periodicaly
Sensitive data are not encrypted in transit
Lack of diversity in communication paths lead to communication failure
Poor or non-existent so�ware updates management – vulnerabilities to communications equipment routers, switches, firewalls
Unsecured physical ports
Inappropri ate or unauthori zed access controls
absence of UpS and power generator not exists
aircondit ioning failure
lack of reduenden t hardware
introsion detection / prevention so�ware not used, not updated, or not tested
anti-virus / anti-mulware not used , not updated, or not tested
Physical the� of hardware physical attack (sabotage /vandalism/ the� /terrorism)
Device power failure physical attack (sabotage /vandalism/ the� /terrorism)
Device power failure Disaster ( heat/ water / wind/ land sliding)
Device power failure human error /misuse of resources destruction of hardware physical attack (sabotage/vandalism/ the� /terrorism)
destruction of hardware Disaster ( heat/ water / wind/ land sliding)
destruction of hardware human error /misuse of resources
device compremise malicious code(worm / trojan/ virus)
device compremise Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)
device compremise Web application attacks(SQL injection / Code Injection / cross- site scripting/ DDoS attacks)
device misconfiguration malicious code(worm / trojan/ virus)
device misconfiguration Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)
device misconfiguration Web application attacks(SQL injection / Code Injection / cross- site scripting/ DDoS attacks)
site- building destruction physical attack (sabotage /vandalism/ the� /terrorism)
site- building destruction Disaster ( heat/ water / wind/ land sliding)
site- building destruction human error /misuse of resources
network wires stealing physical attack (sabotage /vandalism/ the� /terrorism)
Vulnerability
Figure 18: Snapshot of what/ when/ how matrix.
(e) For each risk a Hacktivist can cause, define all system components that can be affected by this risk in the What/Where matrix, such as device misconfiguration that can affect components like the PLC, actuator, Communication server, etc.
(f) For each component that could be attacked by Hacktivist, determine the component’s vul- nerabilities in the Where/When matrix, such
as open communication/unprotected protocols and poor or non-existent software updates management vulnerabilities for communication server.
(g) The relations among system components Hack- tivist can attack and penetration tools he can use are defined in the How/Where matrix, such as physical attacks on a SCADA server component.
Security and Communication Networks 17
Risk Vulnerability ComponentPenetration toolMotivationAgent
agent_mot_risk agent_tool_risk comp_risk_vuln risk_vuln_tool
Risk Scenario
Figure 19: The entity relationship diagram of the proposed model’s database.
0 500
1000 1500 2000 2500 3000 3500
132
2464
1672
658
1294
200 225
1384
228
1583
28
890 387
698
1421
76
712 674 514 75 24 180 180 45 36
3383
Ri sk
S ce
na tr
io s
Total No. of Risk Scenarios Per Risk
byp ass
ad min pass
word
data disc
loser
data disto
rti on
data in
ter cep
tio n
data sn
iffi ng
dest ructi
on of h ard
ware
devi ce
compromise
devi ce
misc onfigu
rat ion
Devi ce
power fai
lure
Disa ble D
evi ce
equipem ent c
ras h
gai n devi
ce ad
ministr ato
r p ass
word
gai n physi
cal ac
ces s
gai n re
mote a cce
ss
hard ware
fai lure
identify netw
ork devi ces
inapproprat e c
ontro l co
mman ds
losin g d
ata
netw ork outag
e
netw ork wire
s d am
age
netw ork wire
s s tea
lin g
Physi cal
th e�
of d ata
Physi cal
th e�
of h ard
ware
site pen
etr ati
on
site - b
uild ing d
est ructi
on
so�ware fai
lure
Figure 20: Total number of risk scenarios per risk.
(2) After that, the previous 2Dmatrices will be combined to form four 3Dmatrices, which provide a description of risks caused by a Hacktivist agent as follows:
(a) Who/Why and What/Who matrices will be combined to define the relation among Hack- tivist, his motivation, and risks he can cause (What/Who/Why matrix), such as a Hacktivist can cause device compromise because of his ideological motivation.
(b) Who/How andWhat/Howmatrices are merged to show risks a Hacktivist can cause and by which penetration tools (What/Who/How matrix) such as a Hacktivist can cause device misconfiguration risk by using web-based attacks.
(c) What/How and How/Where matrices are com- bined to specify risks that can be caused by Hacktivist using which tool and in what com- ponents (What/How/Where matrix), such as
18 Security and Communication Networks
0
500
1000
1500
2000
2500
3000
2579
1137
1701
660
1960
1201
41 41 39 41
2211
1936
306
39 39
1116
41 41
1735
506
1870
41 41 41
Ri sk
S ce
na rio
s
Total No. of Scenarios Per Risk Agent
Coropera te /
Competi tors
Curre nt b
usin ess
part ner
cu rre
nt E mployee
Custo mer
Cyb er
Crim inal g
roup
Cyb er
Terr oris
t
Eart hquakes
Exp losio
ns Fire
s Floods
Form er
busin ess
part ner
Form er
Employee
Hack tiv
ist
Heav y r
ain s
Heav y s
nowfal ls
industr ial
sp ies
Lan dslid
es
Ligh tning
Nati onal s
tat e
Onlin e s
ocia l h
ack er
Scri pt K
idies
Tornad o
Tsunam is
Wild fire
Figure 21: Total number of risk scenarios per risk agent.
0
1000
2000
3000
4000
5000
6000
7000
2872
6565
3447 2935
1735 1364
445
Total No. of Scenarios Per Risk Motivation
Conven ien
ce
Moneti zat
ion
Reve nge
Socia lly
nati onally
Ideol og
ica lly
Envir onmental
ch an
ges
Figure 22: Total number of risk scenarios per risk motivation.
using a physical attack to cause destruction of hardware in HMI.
(d) What/Where and Where/When matrices are combined to determine in what system com- ponent risks can be caused by a Hacktivist and because of what vulnerabilities (What/ Where/When matric), such as destruction of hardware to a PLC due to a lack of or weak physical security tools vulnerability.
(3) Finally, Algorithm 1 will be used to combine the four 3D matrices of the Hacktivist agent to generate the comprehensive description of possible risk scenarios he can cause. The output of running Algorithm 1 is 306 comprehensive scenarios for risks that can be caused by a Hacktivist agent against the SCADA system.
The 306 risk scenarios the risk agent (Hacktivist) can cause are represented in a graphical representation, as shown in Figure 24. All risk identification parameters are coded to be
Security and Communication Networks 19
0 500
1000 1500 2000 2500 3000 3500 4000 4500 5000
132 1395 957
4685
1074 1676
3402
554 68
2896
445 381 978 720
Total No. of Scenarios Per Penetration Tools
socia l en
gin eer
ing / phish
ing
eav esd
ropping / es
pionage
Exp loit k
its
mali cio
us c ode
Sp am
ming
Web-base d att
ack s
Web ap plica
tio n att
ack s
Botnets
spoofing
physi cal
att ack
Disa ste
r
human er
ror
malf uncti
on of eq uipem
ent
data m
an ipulat
ion or fr ogin
g
Figure 23: Total number of risk scenarios per penetration tool.
used in the graphical representation in a readable manner. All parameters’ values and codes are summarized in Table 1. Every path from the Hacktivist Risk agent (A10) at the most left-hand side until Risk (R3, R4, and R5) at the most right-hand side represents an individual comprehensive risk scenario caused by a Hacktivist agent. The path starts from a Hacktivist node (A10) passing through motivations (M), penetration tools (PT), vulnerabilities (V), and components until it reaches the Risk (R) caused by this attack scenario. In Figure 24, three examples of 306 Hacktivist scenarios have been distinguished based on color into green, blue, and red as follows:
(i) In the green scenario, Hacktivist (A10), because of his social motivation (MO4), can use malicious code (PT4) to cause a device compromise (R4) to any router (CD2) when sensitive data are not encrypted in transit vulnerability (V23) occurs.
(ii) In the red scenario, Hacktivist (A10), because of his social motivation (MO4), can use Web-based attacks (PT6) to cause a device misconfiguration risk (R5) to any Communication server (MS1) in the SCADA system when the open communication/unprotected protocols vulnerability (V20) are used.
(iii) In the blue scenario, Hacktivist (A10), because of his ideological motivation (MO5), can use a physical attack (PT10) to destroy the hardware (R3) of any SCADA server (MS2) when a lack of or weak Physical Security Tools vulnerability (V12) occurs.
The other risk scenarios that affect the SCADA system by a Hacktivist can be traced using the graphical representa- tion in Figure 24 and the risk parameters value codes in Table 1. Figure 21 shows the total number of risk scenarios that can be affected in the SCADA system for each risk agent.
7.2. Case Study 2. Another question from SCADA and security managers the proposed model and benchmark DB
can answer is who are the risk agents that can cause a specific risk to the system, and what are the scenarios for that risk? To answer this type of question, the proposed model will be applied to gaining physical access as an example of a risk that can affect the system. Starting from the gaining physical access risk, the seven 2D matrices related to this risk will be built. These 2D matrices will then be combined to form the four 3D matrices for the gaining physical access risk. Finally, Algorithm 1 will be run to generate the possible scenarios for this risk. There are 387 scenarios that can result from gaining physical access to a system. These resulting scenarios for this risk are graphically represented in Figure 25, which shows that there are eight agents that can cause the gaining physical access risk on 23 system components. The total possible risk scenarios for each risk are summarized in Figure 20.
8. Conclusion and Future Work
SCADA systems are one of the most critical industrial systems because of their functionality in supervising and controlling large and worldwide industrial networks, such as electricity and gas distribution networks. Their criticality nature exposes them to a large set of risks from either natural or human sources. To manage these risks, a powerful risk management framework is needed to predict the most significant risks and handle them correctly. This framework should be based on a comprehensive risk identification step. In this paper, the most important parameters that are needed to define SCADA risks were outlined. Then, previous works in the field of risk identification phases of SCADA systems were discussed. A comparative study was provided based on a number of risk identification parameters and the level of mapping between these parameters. Then, a comprehen- sive model for risk identification of SCADA systems was proposed. This model used the hierarchical representation methodology to build themodel, which started fromdefining all risk parameters and mapping them gradually into 2D
20 Security and Communication Networks
A10
M4
M5
PT4
PT6
PT7
PT10
CD3
CD4
CD5
CD6
MS1
RS1
RS2
RS3
CD1
CD2
RS4
RS5
MS2
MS3
CN1
CN2
CN3
TR1
TR2
MS4
V31
V32
V18
V25
V20
V27
V36
V12
V17
V23
R4
R5
R3
Figure 24: Possible Risk scenarios on SCADA system by Hacktivist attacker.
Security and Communication Networks 21
R16
A2
A3
A4
A1
A9
A11
A12
M2
M3
M4
M5
M6
M1
A13
PT6
V12
V26
CD3
CD4
CD5
CD6
MS1
RS1
RS2
RS3
CD1
CD2
RS4
RS5
MS2
MS3
WM1
WM2
WM3
TR1
TR2
CN1
MS4
CN2
CN3
Risk
Component
Vulnerability
Penetration tool
Motivation
Agent
Figure 25: Possible Risk scenarios on SCADA system cause gain physical access.
matrices and on to a 6D matrix. This 6D matrix represented the relations among six risk parameters that were defined to draw complete risk scenarios. Finally, this model was used to build a benchmark database containing 19,163 risk scenarios that could be applied to SCADA systems.
In the future, a classification model should be built using this database to generate a set of rules that could be used further in analyzing and assessing the risks affecting any SCADA system. Then, a simulation for managing SCADA system risks should be developed.
22 Security and Communication Networks
Input: amr is the agent motivation risk matrix, atr is agent tool risk matrix, rvt is the risk vulnerability tool matrix and crv is the component risk vulnerability matrix
Output: RSM is Risk Scenarios Matrix which maps (agent, motivation, risk, tool, vulnerability, component). Begin
1 Fetch all data from amr. 2 for all amri E amr do 3 current agent = amri .agent 4 current motivation = amri .motivation 5 current risk = amri .risk 6 Fetch all tools from atr matrix as amr tools where atr.agent = current agent and atr.risk = current risk 7 for all amr toolsj E amr tools do 8 current tool = amr toolsj .tool 9 Fetch all vulnerabilities from rvt matrix as amrt-vulnerabilities where rvt.risk = current risk and rvt.tool =
current tool 10 for all amrt-vulnerabilitiesk E amrt-vulnerabilities do 11 current-vulnerability = amrt-vulnerabilities k .vulnerability 12 Fetch all components from crv matrix as amrtv-components where crv.risk = current risk and
crv.vulnerability = current-vulnerability 13 for all amrtv-componentsi E amrtv-components do 14 current component = amrtv-components i .component 15 Insert into RSM (currenta gent, current-motivation, current risk, current tool, current vulnerability,
current- component). 16 end for 17 end for 18 end for 19 end for
End
Algorithm 1: Generate 6-dimension SCADA risk matrix.
Data Availability
The data used to support the findings of this study are included within the supplementary information file(s) (avail- able here).
Conflicts of Interest
The authors declare that they have no conflicts of interest.
Supplementary Materials
Supplementary material file is a compressed file that con- tains two files: a. The first file “SCADA Risk identifica- tion data.xlsx” is a spreadsheet file that contains the full mapping of the risk identification parameters stated in the paper as 2D and 3D matrices. The snapshots of these matrices were presented in the paper. b. The second file “scada risk secnarios.sql” is sql script of our proposedmodel database. This database contains the six tables for coding the six risk identification parameters and four tables for four 3D matrices demonstrated in the model. The last table “risk scenarios” is the 6D matrix that was produced by Algorithm 1 to present the full mapping of risk identification scenarios.This table contains 19163 scenarios that can be used as risk scenario for using in the risk assessment purpose of SCADA systems. (Supplementary Materials)
References
[1] T.Macaulay andB. L. Singer,Cybersecurity for Industrial Control Systems, CRC Press, Boca Raton, Fla, USA, 2012.
[2] K. Markantonakis and K. Mayes, Secure Smart Embedded Devices, Platforms and Applications, Springer New York, New York, NY, USA, 2014.
[3] J. Gao, J. Liu, B. Rajan et al., “SCADA communication and security issues,” Security and Communication Networks, vol. 7, no. 1, pp. 175–194, 2014.
[4] A. Nicholson, S. Webber, S. Dyer, T. Patel, and H. Janicke, “SCADA security in the light of cyber-warfare,” Computers & Security, vol. 31, no. 4, pp. 418–436, 2012.
[5] M. Riis and T. Sjomoem, Integration between SCADA Systems and Hydraulic Network Simulation Models, 2016, http://hdl.handle.net/11250/2433613.
[6] A. Rezai, P. Keshavarzi, and Z. Moravej, “Secure SCADA communication by using a modified key management scheme,” ISA Transactions, vol. 52, no. 4, pp. 517–524, 2013.
[7] S. Huda, J. Yearwood, M. M. Hassan, and A. Almogren, “Secur- ing the operations in SCADA-IoT platform based industrial control system using ensemble of deep belief networks,”Applied So� Computing, vol. 71, pp. 66–77, 2018.
[8] A. Rezai, P. Keshavarzi, and Z. Moravej, “Key management issue in SCADA networks: a review,” Engineering Science and Technology, an International Journal, vol. 20, no. 1, pp. 354–363, 2017.
[9] E. Luiijf, “SCADAsecurity good practices for the drinkingwater sector,” 2008, http://publications.tno.nl/publication//KpvRNU/ TNO-DV2008C096 web.pdf.
Security and Communication Networks 23
[10] S. Karnouskos and A. W. Colombo, “Architecting the next generation of service-based SCADA/DCS system of systems,” in Proceedings of the the 37th Annual Conference of the IEEE Industrial Electronics Society, 2011.
[11] C. Nan, I. Eusgeld, and W. Kröger, “Analyzing vulnerabilities between SCADA system and SUC due to interdependencies,” Reliability Engineering & System Safety, vol. 113, no. 1, pp. 76–93, 2013.
[12] A. Rezai, P. Keshavarzi, and Z. Moravej, “Advance hybrid key management architecture for SCADA network security,” Security and Communication Networks, vol. 9, no. 17, pp. 4358– 4368, 2016.
[13] O. Andreeva, S. Gordeychik, G. Gritsai et al., “Indus- trial control systems and their online availability,” 2016, https://kas.pr/KL ICS Availability Statistics.
[14] M. Jouini, L. B. A. Rabai, and A. B. Aissa, “Classification of security threats in information systems,” Procedia Computer Science, vol. 32, pp. 489–496, 2014.
[15] International Organization for Standardization, “Risk management Principles and guidelines,” ISO 31000, 2018, https://www.iso.org/obp/ui#iso:std:iso:31000:ed-2:v1:en.
[16] D.Kasap andM.Kaymak, “Risk identification step of the project risk management,” in Proceedings of the Portland International Conference on Management of Engineering and Technolog, pp. 2116–2120, 2007.
[17] Y. Cherdantseva, P. Burnap, and A. Blyth, “A review of cyber security risk assessment methods for SCADA systems,” Com- puters & Security, vol. 56, pp. 1–27, 2016.
[18] E. Byres and M. Fabro, “RISI - The Repository of Industrial Security Incidents,” 2015, http://www.risidata.com/Database.
[19] Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), 2018, https://ics-cert.us-cert.gov/.
[20] E. Bompard, T. Huang, Y. Wu, and M. Cremenescu, “Classi- fication and trend analysis of threats origins to the security of power systems,” International Journal of Electrical Power & Energy Systems, vol. 50, no. 1, pp. 50–64, 2013.
[21] B. Zhu, A. Joseph, and S. Sastry, “A taxonomy of cyber attacks on SCADA systems,” in Proceedings of the 2011 International Con- ference on Internet of �ings and 4th International Conference on Cyber, Physical and Social Computing, pp. 380–388, Dalian, China, 2011.
[22] R. Hewett, S. Rudrapattana, and P. Kijsanayothin, “Cyber- security analysis of smart grid SCADA systems with game models,” in Proceedings of the 9th Annual Cyber and Information Security Research Conference, pp. 109–112, Tennessee, Tenn, USA, 2014.
[23] K. Stouffer, V. Pillitteri, S. Lightman et al., “Guide to industrial control systems security (NIST SP 80082),” 2015, http://dx.doi .org/10.6028/NIST.SP.800-82r2.
[24] W. B. Miller, D. C. Rowe, R. Helps et al., “A comprehensive and open framework for classifying incidents involving cyber- physical systems,” in Proceedings of the 2014 IAJC/ISAM Joint International Conference, 2014.
[25] J. C. H. Gabriel, M. Y. Jose, and L. A. Roberto, “Using inter- connected risk maps to assess the threats faced by electricity infrastructures,” International Journal of Critical Infrastructure Protection, vol. 6, no. 3, pp. 197–216, 2013.
[26] A. M. Elhady, A. Abou Elfetouh, H. M. El-bakry et al., “Generic Software risk management framework for SCADA system,” International Journal of Computer Applications, vol. 70, no. 3, pp. 45–52, 2013.
[27] B. Kitchenham and P. Brereton, “A systematic review of systematic review process research in software engineering,” Information and So�ware Technology, vol. 55, no. 12, pp. 2049– 2075, 2013.
[28] National Institute of Standards and Technology (NIST), 2018, https://www.nist.gov/.
[29] EuropeanUnionAgency for Network and Information Security (ENISA), 2019, https://www.enisa.europa.eu/.
[30] United State Department of Homeland Security (US. DHS), 2018, https://www.dhs.gov/.
[31] W. Schwab andM. Poujol, “The state of industrial cybersecurity 2018,” 2018, https://ics.kaspersky.com/media/2018-Kaspersky- ICS-Whitepaper.pdf.
[32] Communication network dependencies for ICS/SCADA Systems, 2016, https://www.enisa.europa.eu/publications/ics- scada-dependencies.
[33] B. G. Brown and D. Wylie, “Securing Industrial Control Systems,” 2017, https://www.tripwire.com/solutions/industrial- control-systems/sans-state-of-ics-report-register/.
[34] Generic SCADA Risk Management Framework for Australian Critical Infrastructure, 2012, https://www.tisn.gov.au/Documents/ SCADA-Generic-Risk-Management-Framework.pdf.
[35] Common cyber security vulnerabilities in industrial control systems, 2009, https://www.hsdl.org/?view&did=7970.
[36] M. Nasser, R. Ahmad, W. Yassin et al., “Cyber-security inci- dents: a review cases in cyber-physical systems,” International Journal of Advanced Computer Science and Applications, vol. 9, no. 1, 2018.
[37] A. G. Finogeev and A. A. Finogeev, “Information attacks and security in wireless sensor networks of industrial SCADA systems,” Journal of Industrial Information Integration, vol. 5, pp. 6–16, 2017.
[38] P. Eden, P. Burnap, A. Blyth et al., “A forensic taxonomy of SCADA systems and approach to incident response,” in Proceedings of the 3rd International Symposium for ICS and SCADA Cyber Security Research, pp. 27–39, 2015.
[39] P. S. Woo and B. H. Kim, “A study on quantitative methodology to assess cyber security risk of SCADA systems,” Advanced Materials Research, vol. 960-961, pp. 1602–1611, 2014.
[40] A. F. Guillermo, T. David, and D. Joshua, “Security Best Prac- tices and Risk Assessment of SCADA and Industrial Control Systems,” in Proceedings of the 2012 world congress in computer science, computer engineering, and applied computing, 2012.
[41] R. Tsang, Cyberthreats, Vulnerabilities and Attacks on SCADA Networks, Goldman School of Public Policy. University of California, 2010.
[42] D. Kang, J. Lee, S. Kim et al., “Analysis on cyber threats to SCADA systems,” in Proceedings of the 2009 Transmission and Distribution Conference and Exposition: Asia and Pacific, 2009.
[43] National Vulnerability Database (NVD), 2019, https://nvd.nist .gov/.
[44] Common Vulnerabilities and Exposures (CVE), 2019, https:// cve.mitre.org/.
[45] Bugtraq Team, 2016, http://bugtraq-team.com/. [46] Open Sourced Vulnerability Database (OSVDB), 2017, https://
blog.osvdb.org/.
24 Security and Communication Networks
[47] Open Vulnerability and Assessment Language (OVAL), 2016, http://oval.mitre.org/.
[48] L. Marinos, A. Belmonte, and E. Rekleitis, “enisa threat landscape 2015,” 2016, https://www.enisa.europa.eu/publications/ etl2015/at download/fullReport.
[49] Mysql.com, 2018, https://www.mysql.com/.
International Journal of
Aerospace Engineering Hindawi www.hindawi.com Volume 2018
Robotics Journal of
Hindawi www.hindawi.com Volume 2018
Hindawi www.hindawi.com Volume 2018
Active and Passive Electronic Components
VLSI Design
Hindawi www.hindawi.com Volume 2018
Hindawi www.hindawi.com Volume 2018
Shock and Vibration
Hindawi www.hindawi.com Volume 2018
Civil Engineering Advances in
Acoustics and Vibration Advances in
Hindawi www.hindawi.com Volume 2018
Hindawi www.hindawi.com Volume 2018
Electrical and Computer Engineering
Journal of
Advances in OptoElectronics
Hindawi www.hindawi.com
Volume 2018
Hindawi Publishing Corporation http://www.hindawi.com Volume 2013 Hindawi www.hindawi.com
The Scientific World Journal
Volume 2018
Control Science and Engineering
Journal of
Hindawi www.hindawi.com Volume 2018
Hindawi www.hindawi.com
Journal ofEngineering Volume 2018
Sensors Journal of
Hindawi www.hindawi.com Volume 2018
International Journal of
Rotating Machinery
Hindawi www.hindawi.com Volume 2018
Modelling & Simulation in Engineering Hindawi www.hindawi.com Volume 2018
Hindawi www.hindawi.com Volume 2018
Chemical Engineering International Journal of Antennas and
Propagation
International Journal of
Hindawi www.hindawi.com Volume 2018
Hindawi www.hindawi.com Volume 2018
Navigation and Observation
International Journal of
Hindawi
www.hindawi.com Volume 2018
Advances in
Multimedia
Submit your manuscripts at www.hindawi.com