HLSS505Wk5

profileRawono1
3914283.pdf

Research Article Comprehensive Risk Identification Model for SCADA Systems

Abdelghafar M. Elhady ,1,2 Hazem M. El-bakry,1 and Ahmed Abou Elfetouh1

1Faculty of Computers and Information, Mansoura University, Egypt 2Deanship of Scientific Research, Umm Al-Qura University, Saudi Arabia

Correspondence should be addressed to Abdelghafar M. Elhady; [email protected]

Received 24 January 2019; Revised 19 April 2019; Accepted 11 June 2019; Published 6 August 2019

Academic Editor: Jesús Dı́az-Verdejo

Copyright © 2019 Abdelghafar M. Elhady et al. This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

The world is experiencing exponential growth in the use of SCADA systems in many industrial fields. The increased and considerable growth in information and communication technology has been forcing SCADA organizations to shift their SCADA systems from proprietary technology and protocol-based systems into internet-based ones. This paradigm shift has also increased the risks that target SCADA systems. To protect such systems, a risk management process is needed to identify all the risks. This study presents a detailed investigation on twenty-one scientific articles, guidelines, and databases related to SCADA risk identification parameters and provides a comparative study among them. The study next proposes a comprehensive risk identification model for SCADA systems. This model was built based on the risk identification parameters of ISO 31000 risk management principles and guidelines. The model states all risk identification parameters, identifies the relationships between those parameters, and uses a hierarchical-based method to draw complete risk scenarios. In addition, the proposed model defines the interdependency risk map among all risks stated in the model. This risk map can be used in understanding the evolution of the risks through time in SCADA systems. The proposed model is then transformed into a benchmark database containing 19,163 complete risk scenarios that can affect SCADA systems. Finally, a case study is presented to demonstrate one of the usages of the proposedmodel and its benchmark database.This case study provides 306 possible attack scenarios that Hacktivist can use to affect SCADA systems.

1. Introduction

SCADA refers to “Supervised Control andData Acquisition.” SCADA systems are one of the Industrial Control Systems (ICS) [1] that are used to automate and control all processes and operations. Nowadays, SCADA systems are used in various large-scale fields such as power, energy production, transmission, and distribution (oil and gas, transportation, and water and wastewater) [2, 3]. In these fields, the com- ponents of the system are distributed geographically over a very large distance, and they need to be centrally monitored and controlled [4]. To achieve themonitoring and controlling functions, SCADA systems consist of a set of field sites, which are located in different places [5]. Each field site consists of one or more of Remote Terminal Units (RTU), Programmable Logic Controllers (PLC), and Intelligent Elec- tronic Devices (IED). Those are connected directly to the plants’ sensors and/or actuators to capture data from the plant

operation, perform limited control commands to the field site, and send site data to central control stations known as Master Stations (MS) [6, 7]. The system also has one master station, which collects data from all field sites through a powerful communication network, analyzes these data, and displays results on a graphical terminal called a Human Machine Interface (HMI) [8].

Through time, the number of stockholders that need to connect with SCADA systems directly (system employees and third parity companies) or indirectly through enterprise systems connecting to SCADA systems (customers) has increased. This has pushed SCADA systems toward using open standard protocols, unified technologies, public hard- ware, well-known software, and connecting to the internet [9, 10]. This paradigm switch has improved the system’s support at any time and from any place, and the integration of SCADA systems with other information systems has become trivial. Consequently, the system’s vulnerability has also increased,

Hindawi Security and Communication Networks Volume 2019, Article ID 3914283, 24 pages https://doi.org/10.1155/2019/3914283

2 Security and Communication Networks

making it easier to attack systems from any place using different exploits and attacking tools [11, 12]. Through 2016, the research team at the Kaspersky lab found that there are 220,558 SCADA components that can be accessed through the Internet. These components have been distributed across 170 countries [13]. All these components represent entry points for human agents attacking SCADA systems.They can be exposed to different types of natural phenomena, such as flooding and lightning [14].

The need for a powerful and collaborative risk manage- ment framework for SCADA systems has become urgent to identify, evaluate, and treat various types of risks targeting SCADA systems. All possible scenarios that may happen and affect the system either directly or indirectly should be well- described according to a set of parameters [15, 16]. These parameters could be defined as:

(1) Risks that can happen to the system (what). (2) Agents who can do it (who). (3) Motivation for making the risk (why). (4) Penetration tools and methodologies used for per-

forming the risk (how). (5) System components that can be targeted (where). (6) Component vulnerabilities that can be exploited by

agents (when).

There is a shortage of accurate historical data on SCADA incidents that can be used in the risk management process because of the confidential nature of this field [17]. However, there are some sources that gave us indications on the growing risk to SCADA systems. One of these sources is the RISI database [18], which contains 242 incidents through 2015. Another source is the ICS-CERT database [19], which recorded a growing number of vulnerabilities detected in ICS components (from 2 in 1997 to 189 vulnerabilities in 2015). There is also Bompard et al. [20], who counted 133 blackouts in SCADA systems in the field of power only from 1965 to 2011.

According to state-of-the-art methods, there was a gap in providing complete risk identification scenarios that fulfill the risk identification scenarios related to the six parameters stated in ISO 31000 [15]. Zhu et al. [21] gave abstracted information about system components and system vulnera- bilities. Hewett et al. [22] focused on four types of attacks that target wireless sensor networks. ICS-CERT [19] linked system components and component vulnerabilities. Stouffer et al. [23], Bompard et al. [20], and Zhu et al. [21] provided two individual maps, one between the risk and agent and the other between the risk and affected components without trying to merge the twomaps and expanding them to include the other risk identification parameters. Miller et al. [24], Gabriel et al. [25], and Nan et al. [11] defined the relation among risk, system components, and vulnerabilities without providing the relationship between these parameters with the agent, his motivation, and the penetration tools used.

This paper proposes an extensive model for identifying the risks to SCADA systems, which can be used as a base for the automatic generation of many SCADA risk scenarios.

In building the model, six parameters determined in ISO 31000 [15] and a hierarchical-based method were used, in which all risk parameters were defined with themost possible values and organized in the first level of the model. Then, these parameters were synchronously organized by linking each parameter with the most related ones in the form of matrices. Consequently, seven 2D matrices were built at the second level, which were gathered into four 3D matrices in the next level. Finally, the four 3D matrices were merged to build the complete proposed model based on a 6D matrix. This resulting matrix connected all the parameters together. The risk interdependency map was defined to represent the relationships among all risks in the model. This map illus- trated the direct and indirect dependency among the risks. Also, thismodel was transformed into a benchmark database, which contains 19,163 risk scenarios for SCADA systems.This benchmark database can be used to generate a risk scenarios knowledgebase that might help risk managers and decision makers to analyze, evaluate, and resolve the expected risks with either a proactive or reactive riskmanagement approach. Another use for this model and its benchmark database is in risk management simulation software, such as in the SCADA Risk Identification & Classification Engine (SRICE), a component of the Generic Software Risk Management Framework for SCADA Systems designed by Elhady et al. [26].

This paper is structured as follows. In Section 2, a review on previous work is provided. This review focused on risk identification phases of SCADA and ICS systems. Section 3 shows a comparative study among the available previous sci- entific articles, guidelines, and databases as well as a statistical summary. Section 4 defines the problem statement of the study. Then, the proposed comprehensive risk identification model for SCADA systems is presented in Section 5. The transformation of the model into a benchmark database and the brief statistics are presented as a DB summary in Section 6. Section 7 presents two case studies of the scenarios that could be provided by the proposed model and its database. Section 8 presents the conclusion and future work.

2. Risk Identification Literature Review

The literature review is outlined in three main categories: ICS/SCADA Risk Scientific researches, ICS/SCADA Risk repositories, and ICS/SCAD Risk reports and guides. This review covers the last decade from 2009 till 2018 to make it up to date with the latest ICT expressions and principles.

The main set of scientific papers was formed from the searches run on SCOPUS, ACM, Web of Science, and IEEE Explore, as recommended in Kitchenham and Brereton [27]. The search keywordswere based on two groups ofwords, with each paper containing at least one word from each group. The first group includes the words “risk,” “security,” “threat,” and “vulnerability”; whereas, the second group contains “SCADA” and “Industrial control system (ICS).” After that, the collected papers were filtered by focus on those that had interest in more than two parameters of risk identification in SCADA and ICS.

Security and Communication Networks 3

The second and third categories concentrated on databases and reports that had been issued by accredited academic and research organizations in the field of risk in SCADA and ICS systems. These organizations, like the National Institute of Standards and Technology (NIST) [28], European Union Agency for Network and Information Security (ENISA) [29], and the United States Department of Homeland Security (DHS) [30].

Our search produced thirteen papers, two databases, and six reports and guides, which will be presented in the next section. Then, a comparative study between them and the proposed model will be made in the last section of this paper.

2.1. ICS/SCADA Risk Scientific Studies (Papers). Nasser et al. [36] investigated cyber threats targeting physical systems. Theyproposed a classification based onfive parameters (types of attack, target sector, intention, impact, and incident cate- gory).They provided a matrix of these threats in conjunction with simple statistical data.Moreover, Finogeev and Finogeev [37] focused on attacks that target the SCADAwireless sensor network and that have been initiated by external agents.They classified attacks based on innovative impacts on SCADA components. Furthermore, Eden et al. [38] presented a global taxonomy for SCADA incidents’ response. They classified system assets into five categories based on risk impact. Three categories were based on safety process, timing, and location, while the other two categories are mission critical and business critical. They distinguished attacks into three types: hardware, software, and communication attacks. Woo and Kim [39] also identified fifteen types of threads and four SCADA system components. First, they linked between each thread and target component, and then they determined the vulnerabilities for each system component based on historical data and the component’s characteristics.

Hewett et al. [22] defined four types of attacks that can target SCADA sensor networks: Sybil attack, node compromise, eavesdropping, and data injection. For each attack, the researchers specified themethodology the attacker used to achieve the attack and the system components they may target. Miller et al. [24] proposed a framework for classifying cyber physical systems incidents. This framework relies on four dimensions: seven different source types, methods used in the incident, direct and indirect impact of incident, and victim of incident. However, Bompard et al. [20] classified threat origins into four types: natural threats, accidental threats, malicious threats, and emerging threats. They provided detailed descriptions on each type of threat and displayed their possible impacts on the system.

Gabriel et al. [25] proposed new approach for risk iden- tification and assessment in electricity infrastructure. They identified 21 main risks and 142 sub risks and classified them based on three criteria. The first criterion is the type of risk divided into technical and nontechnical risks. The second criterion is according to effect, in four categories: operational, environmental, financing, and quality compliance. The last criterion is according to risk severity, divided into critical, important, tolerable, and acceptance. Finally, they used a semi-quantitative methodology to rank these risks based on subjective assessment and specialist opinions. Nan et al. [11]

provided further investigation on the vulnerabilities resulting from the interdependency between the SCADA system and System Under Control (SUC). They displayed the negative impacts on each linking component: such as sensors, actua- tors, and RTU, due to attackers using these vulnerabilities and how tominimize these negative impacts. Guillermo et al. [40] distinguished the SCADA system into fivemain components: system, network, physical, employee, and information. They stated a very simplified set of vulnerabilities for each one of them. They also stated a few threats that can affect the system. Zhu et al. [21] outlined a general set of SCADA system vulnerabilities, such as insecure network, vulnerable oper- ating system, and misuse of encryption. They also classified threats based on target components like hardware, software, and communication stack and implemented protocols. Tsang [41] discussed SCADAnetwork attacks and incidents and dis- tinguished between accidental and intentional threats caused by threats agents and how they cause these threats. Further, they displayed a set of vulnerabilities in a SCADA network that can be used by threat agents.They summarized the set of actual attacks on a real-world SCADA network. Dong Kang et al. [42] presented thirty-two common computer system threats and spread themacross four parts of a SCADA system: control devices, communication links, control center, and communication with corporate network. This mapping was based on the probability of targeting these threats on those parts.

2.2. ICS/SCADA Risk Databases (Repositories). In 2001, Eric Byres and Mark Fabro developed a database for Indus- trial Control Systems (ICS). They called it the Repository of Industrial Security Incidents (RISI) [18]. This database focused on incidents, their caused agents, and which system’s components were affected. This database is flawed due to its small number of incidents recorded and the fact that it hasn’t been updated since January 2015.

The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) in the U.S. DHS developed a database that concentrates on the vulnerabilities of an ICS components’ platform rather than any other risk identification parameters like risk agents, their motivations, and the used penetration tools [19].

2.3. ISC/SCADA Risk Reports and Guides. Stouffer et al. [23] with NIST presented a guide for ICS security. This guide classified threats sources into four classes: adversarial, accidental, structural, and environmental. For each threat source, they described a sample of threats that can be caused by this class. Then they categorized the system into six categories: policy and procedure, architecture and design, configuration and maintenance, physical, software develop- ment, and communication and network. For each category, they listed its vulnerabilities.

The European Union Agency for Network and Infor- mation Security (ENISA) team presented report on com- munication network dependencies for ICS/SCADA Systems [32]. This report listed threats and vulnerabilities related to ICS/SCADA and showed eight attack scenarios. Each scenario targeted a main component of an ICS/SCADA

4 Security and Communication Networks

systemanddiscussed the steps that should be taken to prevent that attack scenario.

Brown andWylie [33] fromSANS Institute-InfoSec Read- ing Room team collected data from hundreds of specialists in the field of ICS security to produce an annual report on ICS’s most common risks. They provided statistics on the risks for each component in an ICS system and the threat agents that cause these risks.

The Trusted Information Sharing Network (TISN) for critical infrastructure reliance developed a generic SCADA risk management framework for Australian critical infras- tructure [34]. They classified threat agents into five classes based on scope, malicious intent, and nature. They also distinguished the system components into four main cate- gories: people, products, process, and reputation. Finally, they mapped each category of system components with all of their vulnerabilities and what class of threat agents can exploit these components.

DHS presented a report on CommonCyber Security Vul- nerabilities in ICS [35]. They classified these vulnerabilities into three categories: ICS software, ICS configuration, and ICS network security.

Schwab and Poujol from the Kaspersky lab team provided a report that summarized the state of ICS cybersecurity in 2018 in each geographical region all over the world [31]. They listed sixteen risks that could affect industrial systems’ operations. They also stated twelve vulnerabilities that can cause a negative impact on these systems.

3. Comparative Study

In this section, a comparative study among all previous studies is presented. The comparative study depends on two levels of comparison. The first level of comparison concentrates on individual risk identification parameters. Then these parameters are merged in two dimensions, three dimensions, and six dimensions parametermatrices and state the corresponding previous studies.

3.1. Single Parameter Mapping Comparison. In this compari- son, the previous works are distinguished based on number of risk identification parameters stated. As shown in Table 1, no single previous work had presented all parameters of risk identification.

The total number of parameters stated in each previous work is visualized in Figure 1. This figure shows that the biggest number of parameters stated in a previous work was five parameters, which was presented only one time in a scientific paper (Tsang [41]). There is one ICS report (ENISA [32]) and three scientific papers (Bompard et al. [20], Gabriel et al. [25], and Guillermo et al. [40]) that stated four parameters. The most parameters stated in a previous work were three parameters, which were stated in ten of the previous works. These ten works were classified as one database, three ICS reports and guides, and six scientific papers. Finally, the fewest parameters stated in a previous work was two, which was presented in six previous works, which are distributed as ICS-CERT database [19], two ICS reports and guides, and three scientific papers [11, 36, 37].

0

1

2

3

4

5

6

N o.

o f R

isk id

en tifi

ca tio

n' s

pa ra

m et

er s S

ta te

d

Pervious work Ref

IC S-C

ERT [1 9]

Byre s a

nd Fabro [1 8]

Schwab an d Poujol [3

1]

ENISA [3

2]

Brown an d W

yli e [

33 ]

Sto uffer

et al.

[23 ]

TISN [3

4]

DHS[3 5]

Nass er

et al.

[36 ]

Finogee v a

nd Finogee v [

37 ]

Eden et

al. [3

8]

Woo an d Kim

[3 9]

Hew ett

et al.

[2 2]

Mille r e

t a l. [

24 ]

Bompard et

al. [2

0]

Gabrie l et

al. [2

5]

Nan et

al. [1

1]

Guille rm

o et al.

[4 0]

Zhu et al.

[2 1]

Tsan g [

41 ]

Kan g e

t a l. [

42 ]

Figure 1: Total no. of risk identification parameters stated per previous works.

Another statistic is presented in Figure 2. This figure displays the total number of previous works stating each risk identification parameter. This shows that the most risk identification parameters stated in previous works were risk (What?) and system components (Where?), which were stated in sixteen previous works. Next parameter was com- ponent vulnerabilities (When?) in thirteen previous works, and then risk agent parameter in eleven previous works. Pen- etration technique (How?) was stated in six previous works. Finally, the risk identification parameter least presented in previous works was risk motivation (Why?), stated once in ENISA [32].

3.2. Multi-Parameters Mapping Comparison. In this section, all the previous works are compared based on mapping risk identification parameters into two, three, and six dimensional matrices. All the previous works were examined to discover if they stated these parameter mappings or if they provided another mapping. Finally, this examination is summarized in Table 2.

The comparative study data in Table 2 were collected based on the total number of mapping matrices stated in each previous work as shown in Figure 3. This figure shows that the maximum number of mapping matrices stated in the previous works were three mappingmatrices, which were presented in only three previous works: ENISA [32], Gabriel et al. [25], and Tsang [32].Then, there are five previous works thatmentioned only twomappingmatrices and nine previous works that mentioned only one mapping dimension. There are four previous works that didn’t mention any mappings between two or more of risk identification parameters.

Another statistic on the previous works was based on the total number of previous works mentioning each risk identification mapping matrix, as shown in Figure 4. This figure shows that the mapping between risk (What?) and system components (Where?) was the most-stated mapping in previous works, mentioned eight times. Then, the map- ping between system components (Where?) and component vulnerabilities (When?) was mentioned in several previous works.Themapping between risk agent (Who?) and penetra- tion techniques (How?) in a two-dimensional matrix was the

Security and Communication Networks 5

Table 1: Risk parameters stated in each work.

Paper Risk Agent

(WHO?)

Risk Motivations (WHY?)

Risk (WHAT?)

Penetration Technique (HOW?)

System Components (WHERE?)

Component Vulnerabilities (WHEN?)

Risk Interdependency

SCADA & ICS Risk Databases ICS-CERT [19] √ √

Byres and Fabro [18] √ √ √

SCADA & ICS Reports and guides Schwab and Poujol [31] √ √

ENISA [32] √ √ √ √ √

Brown and Wylie [33] √ √ √

Stouffer et al. [23] √ √ √

TISN [34] √ √

DHS [35] √ √

SCADA & ICS scientific research Nasser et al. [36] √ √

Finogeev and Finogeev [37] √ √

Eden et al. [38] √ √ √

Woo and Kim [39] √ √ √

Hewett et al. [22] √ √ √

Miller et al. [24] √ √ √

Bompard et al. [20] √ √ √ √

Gabriel et al. [25] √ √ √ √ √

Nan et al. [11] √ √ √

Guillermo et al. [40] √ √ √ √

Zhu et al. [21] √ √ √

Tsang [41] √ √ √ √ √

Kang et al. [42] √ √ √

Component Vulnerabilities (WHEN?)

System Components (WHERE?)

Penetration technique (HOW?)

Risk (What?)

Risk Motivations (WHY?)

Risk Agent (WHO?)

0 2 4 6 8 10 12 14 16 18

No. of papers

13

16

6

16

1

11

Figure 2: Total no. of previous works stated each risk identification parameter.

mappingmatrix least-mentioned, only appearing one time in a previouswork.There are fourmappingmatrices that weren’t mentioned at all in the previous works, as shown in the figure.

4. Risk Identification Problem in SCADA System

So far, many researchers have tried to study the risks in SCADA systems. Their trails are short and suffer from describing an efficient algorithm in identifying the risk class. Moreover, a correct definition for vulnerability in SCADA

is missed. This paper tries to map the relation between the effective parameters that identifying the SCADA risks and the whole scenario for specific risks.The whole scenario for risks is targeted through rebuilding a significant database collected from previous resources and then analysing the results. The problems that face other researches are assumed in the DB and summarized in the following points:

(1) Giving a detailed level of identifying the risks and classifying them based on the nature of the risk agents, their action’smotivation, and the penetration tools/techniques that can be used to cause a risk on a SCADA system.

6 Security and Communication Networks

Ta bl e 2: Ri sk

pa ra m et er sm

ap pi ng

sta te d in

ea ch

w or k.

Pa pe r

2D M at rix

3D M at rix

6D M at rix

O th er

M ap pi ng

W ho

/W hy

W ha t

/W ho

W ho

/H ow

W ha t

/H ow

W ha t

/W he re

W he re

/W he n

H ow

/ W he n

W ha t

/W ho

/W hy

W ha t

/W ho

/H ow

W ha t/

W he re

/W he n

W ha t

/H ow

/W he n

W ha t/W

ho /

W hy /H

ow /

W he re /W

he n

SC AD

A & IC S Ri sk

D at ab as es

IC S- CE

RT [19

] √

By re sa

nd Fa br o [1 8]

√ √

SC AD

A & IC S Re po rt sa

nd gu id es

Sc hw

ab an d Po

uj ol [3 1]

EN IS A [3 2]

√ √

√ Br ow

n an d W yl ie [3 3]

√ St ou

ffe re

ta l. [2 3]

√ √

TI SN

[3 4]

√ w ho

, w he re ,

w he n

D H S[ 35 ]

SC AD

A & IC S sc ien

tifi cr es ea rc h

N as se re

ta l. [3 6]

√ Fi no

ge ev

an d Fi no

ge ev

[3 7]

Ed en

et al .[ 38 ]

√ W oo

an d Ki m

[3 9]

H ew

et te ta l. [2 2]

√ M ill er

et al .[ 24 ]

Bo m pa rd

et al .[ 20 ]

√ √

w ha t/

w ho

/ w he re

G ab rie

le ta l. [2 5]

√ N an

et al .[ 11 ]

√ √

G ui lle rm

o et al .[ 40

] √

Zh u et al .[ 21 ]

√ √

w ha t/

w he re /

ho w

Ts an g [4 1]

√ √

Ka ng

et al .[ 42 ]

w ha t/

w he re /

ho w

Security and Communication Networks 7

0

0.5

1

1.5

2

2.5

3

3.5

N o.

o f R

isk id

en tifi

ca tio

n' s

pr am

et er

s' m

ap pi

ng

Previous work

IC S-C

ERT [1 9]

Byre s a

nd Fabro [1 8]

Schwab an d Poujol [3

1]

ENISA [3

2]

Brown an d W

yli e [

33 ]

Sto uffer

et al.

[23 ]

TISN [3

4]

DHS[3 5]

Nass er

et al.

[36 ]

Finogee v a

nd Finogee v [

37 ]

Eden et

al. [3

8]

Woo an d Kim

[3 9]

Hew ett

et al.

[2 2]

Mille r e

t a l. [

24 ]

Bompard et

al. [2

0]

Gabrie l et

al. [2

5]

Nan et

al. [1

1]

Guille rm

o et al.

[4 0]

Zhu et al.

[2 1]

Tsan g [

41 ]

Kan g e

t a l. [

42 ]

Figure 3: Total no. of risk identification parameters per previous work.

What/Who/Why/How/Where/When What/How/When

What/Where/When What/Who/How What/Who/Why

How/When Where/When Where/When What/Where

What/How Who/How

What/WhoRi sk

id en

tifi ca

tio n

m ap

pi ng

m at

rix es

0 1 2 3 4 5 6 7 8 9

No. of previous works

Figure 4: Total no. of risk identification parameters mapping stated per previous work.

(2) Providing all possible components that formulate a SCADA system and state all known vulnerabilities that can be used by attackers to perform the attack.

(3) Mapping between risks, vulnerabilities, and system components by linking each risk with all possible vulnerabil- ities of system’s components that an attack agent can utilize to achieve the risk goals. A description of the estimated impact on that component as a result of an attack is also missing.

(4) Description of the interdependency among threats that can be used to present the possible attack path scenarios.

The main point in this work depends on the hierarchal- based method. The relation among related parameters is converted into matrices, which are linked synchronously to construct an augmented matrix with six dimensions, which is analyzed.

5. The Comprehensive Risk Identification Model for SCADA System

The risks that face SCADA were studied through a set of vulnerability resource databases, such as ICS-CERT [19], NVD [43], CVE [44], Bugtraq [45], OSVDB [46], Mitre [47], and exploit-DB; incidents repositories such as RISI [18]; and annual reports related to threats in the field of industrial

control systems and SCADA systems. These reports and guides were collected from NIST [28], and ENISA [29].

The collected information were organized and classified in the form of six main risk identification parameters, (What, Who, Why, How, Where, and When). Then, an analytical study that defines the relations among these parameters draws a complete view of the risk scenarios. Each scenario can define the risk affection on the SCADA system (What), the source of that risk (Who), the reasonable motivations behind performing specific actions (Why), penetration tools andmethodologies that cause the risk (How), possible system components wherever an attack can be targeted (Where), and the existing vulnerabilities in components when a threat source can execute his attack (When).

The hierarchical-based methodology was used to build the proposed model. The hierarchal tree consists of four levels. The first level aims to define each parameter’s val- ues. The consequent level is constructed by mapping each parameter with the most related parameters. Seven matrices are constructed in the second level. Hence, collections of matrices are similarly constructed based on reducing the number of neighbors and augmenting the relation among parameters in the next levels. By the third level, four matrices are constructed bymerging the sevenmatrices in the previous

8 Security and Communication Networks

Component Vulnerabilities

(When?)

System Components

(Where?)

Risks (What?)

Penetration Tools

(How?)

Risk Motivations

(Why?)

Risk Agents (Who?)

Where/WhenWhat/WhereHow/WhereWho/Howwhat/WhoWho/Why What/How

What/ Where/WhenWhat/ How/ WhereWhat/ Who/ HowWhat/ Who/ Why

What/ Who/ Why/ How/ Where/ When

Figure 5: The hierarchical methodology of the proposed model.

step. Finally, full-risk scenarios matrix is constructed by developing an algorithm used to relate all 3Dmatrices in level three and produces complete risk scenarios, as illustrated in Figure 5. The defined steps are stated as shown in the following steps:

5.1. Step 1. Define the six main parameters (risks, risk agents, agent motivation, system’s components, system’s vulnerabili- ties, risk’s penetration methodologies).

Risk (What?) defines the list of initial incidents that can threaten the SCADA system. These incidents cause a negative impact on a system’s availability, integrity, and/ or confidentiality, which leads to defects in achieving the system’s objectives and functionality. Risk agent (Who?) defines the list of themost possible risk agents [18, 23, 32] that represent the sources of any risk affecting the system either accidentally or intentionally.These agents are classified based on a set of features [14]:

(i) Nature: human agent and natural agent.

(ii) Scope: internal agent and external agent.

(iii) Intention: agent’s action that causes risk could be intentional and accidental.

(iv) Strength: for human agent, the strength feature expresses the overall characteristics to successfully execute risk. This feature has been calculated based on three characteristics (capability, knowledge, and skills) of a human agent [48]. For a natural agent, the strength feature represents the power of natural phenomena. This feature has been ranked into three levels: low, medium, and high.

This classification helps us understand the risk motivations for each agent. Risks can result from these motivations, as we will illustrate in the next sections. Any risk that occurs in a SCADA system has at least one reason. This reason incites the agent to carry out his attack on the system. The risk motivations (Why?) parameter defines these reasons. The system components (Where?) parameter defines the physical devices of a SCADA system that can be targeted for an attack. The most physical components of the SCADA system are categorized into eight main categories based on technical and functional characteristics of the component. The component vulnerabilities (When?) parameter illustrates the conditions when their existence could lead to or facilitate the risk agent from initiating his attack on the system. The penetration technique (How?) parameter defines the most common penetration methodologies, techniques, and tools that risk agents can use to exploit a system’s vulnerabilities and/or cause harm to one or more system components.

The six main parameters of the proposed model are listed in Table 3. This table lists 27 risks, 24 risk agents, 7 risk motivations, 14 penetration tools, 36 vulnerabilities, and 30 system components.

5.2. Step 2. In this step, the interdependency risk map, the cascading effect among all risks listed in step 1, is counted as shown in Figure 6. This map provides the common possible attack paths that can be used by risk agents to reach a specific risk. It also defines the direct and indirect effect of any risk.

For example, the data disclosure risk can conclude from this map where all possible attack paths that lead to data disclosure are declared, as shown in Figure 7. There are three paths leading to the data disclosure risk at the end. These paths are as follows:

Security and Communication Networks 9

Ta bl e 3: Ri sk

Id en tifi

ca tio

n Si x Pa ra m et er s.

Ri sk

(W ha t?) :

Ri sk

Ag en ts (W

ho ?) :

Ri sk

M ot iv at io ns

(W hy ?) :

Sy ste

m Co

m po ne nt s( W he re ?) :

Co m po ne nt

Vu ln er ab ili tie s( W he n? ):

Pe ne tra

tio n te ch ni qu e( H ow

?) :

(1 )H

um an

ris ks

(R 19 :In

ap pr op

ria te co nt ro l

co m m an ds )

(2 )P

hy sic al ris ks

(R 20 :S ite

pe ne tr at io n,

R1 :P hy sic

al th eft

of ha rd w ar e, R2

:D ev ic e

po w er

fa ilu

re ,

R3 :D es tr uc tio

n of

ha rd w ar e,

R6 :S ite -b

ui ld in g

de str

uc tio

n, R7

:N et w or k

w ire

ss te al in g, R8

:N et w or k

w ire

sd am

ag e, R1 5: Ph

ys ic al

th eft

of da ta ,R

22 :H ar dw

ar e

fa ilu

re ,R

24 :D

isa bl eD

ev ic e,

an d R2

7: Eq

ui pm

en tc ra sh )

(3 )S

o� wa

re ris ks

(R 4:

D ev ic ec

om pr om

ise ,R

5: D ev ic em

isc on

fig ur at io n,

R1 6: G ai n ph

ys ic al ac ce ss ,

R1 7: G ai n re m ot ea

cc es s,

R1 8: Id en tif y ne tw or k

de vi ce s, R2

1: G ai n de vi ce

ad m in ist ra to rp

as sw

or d,

R2 3: By

pa ss D ev ic ea

dm in

pa ss w or d, R2

5: N et w or k

ou ta ge ,R

26 :S oft

w ar e

fa ilu

re )

(4 )D

at a ris ks

(R 9: N et w or k

w ire

le ss sig

na ld

isr up

tio n,

R1 0: D at as

ni ffi ng

,R 11 :D

at a

in te rc ep tio

n, R1 2: D at a

di sto

rt io n,

R1 3: D at a

di sc lo se r, R1 4: Lo

sin g da ta )

(A 1) Cu

rr en tE

m pl oy ee

(A 2)

Fo rm

er Em

pl oy ee

(A 3)

Cu rr en tb

us in es sp

ar tn er .

(A 4)

Fo rm

er bu

sin es sp

ar tn er

(A 5)

Cu sto

m er

(A 6)

Sc rip

tK id ie s

(A 7)

In du

str ia ls pi es

(A 8)

O nl in es

oc ia lh

ac ke r

(A 9)

C or po

ra te /c om

pe tit or s

(A 10 )H

ac kt iv ist

(A 11 )C

yb er -c rim

in al gr ou

p (A

12 )C

yb er

te rr or ist

(A 13 )N

at io na ls ta te

(A 14 )E

ar th qu

ak es

(A 15 )F

lo od

s (A

16 )T

su na m is

(A 17 )L

an ds lid

es (A

18 )L

ig ht ni ng

(A 19 )H

ea vy

ra in s

(A 20 )H

ea vy

sn ow

fa lls

(A 21 )T

or na do

(A 22 )W

ild fir e

(A 23 )F

ire s

(A 24 )E

xp lo sio

ns

(M 1) C on

ve ni en ce .

(M 2)

M on

et iz at io n

(M 3)

Re ve ng

e. (M

4) So

ci al ly.

(M 5)

Id eo lo gi ca lly

(M 6)

N at io na lly .

(M 7)

En vi ro nm

en ta l

ch an ge s.

(1 )R

em ot es

ta tio

n (R T1 :s en so r,

RT 2: ac tu at or ,R

T3 :R

TU ,R

T4 :P

LC an d RT

5: IE D ).

(2 )C

om m un

ic at io n de vi ce

(C D 1:

sw itc h, CD

2: ro ut er ,C

D 3: re pe at er ,

CD 4: m od

em ,C

D 5: W LA

N ac ce ss

po in ta nd

CD 6: Fi re w al l).

(3 )W

ire m ed ia (W

M 1: co ax ia l

ca bl e, W M 2: tw ist ed

pa ir ca bl ea

nd W M 3: Fi be ro

pt ic ca bl e) .

(4 )W

ire le ss m ed ia (W

LM 1: ra di o

fre qu

en cy ,W

LM 2: m ic ro w av ea

nd W LM

3: sa te lli te ).

(5 )M

as te rs ta tio

n (M

S1 :

co m m un

ic at io n se rv er ,M

S2 :

SC A D A se rv er ,M

S3 :h ist or ia n

Se rv er

an d M S4 :H

M I)

(6 )C

or po

ra te ne tw or k (C

N 1:

Ap pl ic at io n se rv er ,C

N 2: w eb

se rv er ,C

N 3: m ob

ile se rv er ,T

R1 :

PC /la

pt op

an d TR

2: sm

ar t

ph on

e/ ta bl et ).

(7 )P

eo pl e( PE

1: sy ste

m em

pl oy ee s,

PE 2: sy ste

m cli en ts an d PE

3: 3r d

pa rt y stu

ff) .

(8 )B

S1 :B

ui ld in g & sit e.

(1 )H

um an

er ro rs (V

1: di sp la y in fo rm

at io n ab ou

tt he

sy ste

m an d w ho

op er at ei t, V 2: un

qu al ifi ed

em pl oy ee ,V

3: Le ak

of sk ill s, kn

ow le dg ea

nd tr ai ni ng

,V 4: Sh

ar in g pa ss w or d am

on g

us er s, V 5: pa ss w or d di sc lo su re ,V

6: Fo

rm er

em pl oy ee s/ co nt ac to re

xp os et he ir sy ste

m kn

ow le dg et o

ex te rn al pe rs on

s, V 7: Ac

co un

ts til la ct iv at ed

fo rf or m er

em pl oy ee

an d pa rt ne rs ,V

13 :U

sin g de fa ul tp

as sw

or d, V 14 :

N o pa ss w or d us ed ,V

15 :U

sin g w ea k pa ss w or d po

lic es ,V

27 :

In ap pr op

ria te or

un au th or iz ed

ac ce ss co nt ro ls,

V 36 :L

ac k of

re m ot ea

cc es sc

on tro

l) (2 )P

hy sic al vu ln er ab ili tie s( V 8: Is ol at ed

sit es ,V

9: Po

or m ai nt e n an ce ,V

10 :A

bs en ce

of al ar m

sy ste

m ,V

11 :W

ea k

w in do

w sa

nd do

or sc

on tro

lli ng

,V 12 :L

ac k or

w ea k of

ph ys ic al se cu rit y to ol s, V 24 :L

ac k of

di ve rs ity

in co m m un

ic at io n pa th sl ea d to

co m m un

ic at io n fa ilu

re ,V

28 :

Ab se nc eo

fu ps

an d po

w er

ge ne ra to rn

ot ex ist s, V 29 :

A ir- co nd

iti on

in g fa ilu

re ,V

30 :L

ac k of

re du

nd an th

ar dw

ar e,

V 33 :N

o w ar ra nt y ag re em

en t, V 34 :N

o sp ar es

m an ag em

en t)

(3 )S

o� wa

re vu ln er ab ili tie s( V 18 :C

rit ic al co nfi

gu ra tio

ns ar e

no ts to re d or

ba ck ed

up ,V

20 :O

pe n

co m m un

ic at io n/ un

pr ot ec te d pr ot oc ol sa

re us ed ,V

25 :P oo

r or

no n- ex ist en ts oft

w ar eu

pd at es ,V

21 :U

ns ec ur ed

w ire

le ss

ne tw or ks ,V

26 :U

ns ec ur ed

ph ys ic al po

rt s, V 31 :I nt ru sio

n de te ct io n/ pr ev en tio

n so ftw

ar en

ot us ed ,n

ot up

da te d, or

no t

te ste

d, V 32 :A

nt i-v

iru s/ an ti- m al w ar en

ot us ed ,n

ot up

da te d,

or no

tt es te d, V 33 :N

o w ar ra nt y ag re em

en t, V 35 :M

em or y

ov er flo

w )

(4 )D

at a vu ln er ab ili tie s( V 16 :S en sit iv ed

at au

np ro te ct ed

w ith

en cr yp tio

n an d pa ss w or d pr ot ec tio

n, V 17 :U

np ro te ct ed

da ta

tr an sfe

rr ed ,V

19 :A

bs en ce

or un

te ste

d ba ck up

pr oc ed ur e,

V 22 :S ys te m

lo g no

tm ai nt ai ne d or

re vi se d pe rio

di ca lly ,V

23 :

Se ns iti ve

da ta ar en

ot en cr yp te d in

tr an sit )

(P T1 )S

oc ia le ng

in ee rin

g/ ph

ish in g.

(P T2

)I nt er ce pt io n/ ea ve sd ro pp

in g/ es pi on

ag e.

(P T3

)E xp lo it ki ts.

(P T4

)M al ic io us

co de .

(P T5

)S pa m m in g.

(P T6

)W eb -b as ed

at ta ck s.

(P T7

)W eb

ap pl ic at io n at ta ck s.

(P T8

)B ot ne ts.

(P T9

)S po

ofi ng

. (P T1 0)

Ph ys ic al at ta ck .

(P T1 1) D isa

ste r

(g eo lo gi ca l/h

yd ro lo gi ca l/m

et eo ro lo gi ca l).

(P T1 2)

H um

an er ro r/ m isu

se of

re so ur ce s.

(P T1 3)

M al fu nc tio

n of

eq ui pm

en t.

(P T1 4)

D at am

an ip ul at io n or

fro gi ng

.

10 Security and Communication Networks

Site penetration

Site- building   destruction

Gain physical access

Physical the� of hardware

Device power failureDestruction of

hardware

Equipment crach

Hardware failure

Network wires damage

Network wires stealing

Physical the� of data

Data sniffing Gain remote access

Data interception

Bypass Device admin passwordIdentify network

devices

Gain device admin

password

Data disclosure

Device Disabled

Network  outage

Losing data Network

wireless signal disruption

So�ware failure

Device mis- configuration

Inappropriate control

commands

Device compremise

Data distortion

Figure 6: Interdependency risk map for the proposed model.

Gain physical access Data sniffing

Data discloserPhysical the� of data

Physical the� of hardware

site penetration

1,2

1

12

2,3

3 3

Figure 7: Interdependency risk map for data discloser risk.

(1) Site penetration -> Gain physical access -> Data sniffing Data discloser.

(2) Site penetration -> Gain physical access -> Physical theft of data - >Data discloser

(3) Site penetration -> Physical theft of hardware -> Physical theft of data - >Data discloser

5.3. Step 3. In this step, each parameter is linked to the most related parameters of the risk identification in a 2D matrices form in which all values of one parameter are organized in horizontal direction (row headers) and all values of the related parameter are organized in the vertical direction (col- umn headers). Each intersection between one column and one row represents the existing relation between the values of

Security and Communication Networks 11

the intersected row and column.This relation has two values, true (√) and false (null). Consequently, 2D matrices are built based on the collected information from the works in the literature review. The constructed seven 2D matrices present a complete view of the relation among all risk identification parameters.

The first 2D matrix, labeled (who/why), describes the relations between risk agents (who) and risk motivations (why). All risk agents are listed as row headers, and all risk motivations are listed in column headers, as shown in Figure 8. The risk motivation for each agent is classified based on agent intention feature. For example, the current employee agent has a convenience motivation only for acci- dental intention. On the other hand, the current employee has monetization and revenge motivations for intentional intention. The competitor has monetization, revenge, and social motivations.

Similarly, the other six matrices have been built. The matrix (what/who) describes the relation between risk agents (who) and risks (what) that were caused by each agent. All risk agents represent the row headers and all risks represent the column headers, as shown in Figure 9. The matrix (who/how) defines the relation between the risk agents (who) and penetration techniques (how) to illustrate the agent’s penetration tools that cause system risks. In this matrix, all risk agents represent row headers and all penetration tech- niques represent the column headers, as shown in Figure 10 The matrix (what/how) defines the relation between risks (what), which represent the column headers, and the pene- tration techniques (how), which represent the row headers, as shown in Figure 11.The (what/where) matrix defines the rela- tion between risks (what) and system components (where) in which these risks can occur. The risks list represents the columnheaders and all system components represent the row headers, as shown in Figure 12. The (where/when) matrix defines the relation between system components (where) and their vulnerabilities (when), in which their existence could result in a risk, as shown in Figure 13. Finally, the (when/how) matrix defines the relation between component vulnerabilities (where) and penetration techniques (how), which can cause these vulnerabilities to create risk, as shown in Figure 14.

5.4. Step 4. Another merge step is represented where both 2D matrices from step 3 are joined to form a 3D matrix to build a partial risk scenario. Each matrix is organized as two related columns and a single row. The first column rep- resents the most significant parameter. The second column represents all correlated values of the second parameter. A many–many corresponding relationship is defined between the first parameter and the second parameter values. The other columns’ headers represent the values of the third parameter. The mapping of these three parameters defines all values of the third parameter related to the other two parameters. Each intersection between each column and each row represents the relation between the values of the intersected row and column. Also, this relation has two values, true (√) and false (null).

The first 3D matrix joins the related two 2D matrices (Who/Why and What/Who), where risk agent (who) joins the two matrices. This matrix answers the question of what risk can be caused by an agent and his motivation. In this matrix, all risk agents have been listed in the first column. For each risk agent value, the risk motivations are presented using (who/why) matrix. On the other hand, all risks are represented as columns header. Using the (what/who)matrix, the first row of each risk agent displays all risks that can be caused by that agent. The following rows for that agent are constructed in conjunction with the risk motivation, where each row defines a specific agent and certain motivation. All checked risks from the first row of that agent are oriented on the agent/motivation rows based on each agent and motivation nature for that risk, as shown in Figure 15.

For example, the current employee agent has the first four rows. The first one represents all risks that can be done by the current employee. The next three rows represent all risks that can be done by the current employee for a specific risk motivation (convenience, monetization and revenge).

The second 3D matrix combined three 2D matrices from step 3 (what/who, what/how, and who/how) into one 3D matrix of (what/who/how). This 3D matrix answers the question of what risk can happen (what) from which agent (who) and which penetration tool (how). In this matrix, the first column represents all risk agents and the second column represents all penetration techniques for each agent using the (who/how) matrix. All risks are displayed from the third column up to the end of the risk. The first row of each risk agent displays all risks that can be caused by that agent using the (what/who) matrix. The following rows for that agent are made in conjunction with penetration techniques where each row defines a specific agent and certain penetration technique. All checked risks from the first row of that agent are oriented on the agent/penetration technique rows based on each agent and penetration technique he can use to cause that risk using the (who/how) matrix, as shown in Figure 16.

The third 3D matrix joined the two 2D matrices from step 3 (what/where and where/when) into one 3D matrix (what/where/when). This matrix answers the question of what risks exist (what) in what system components (where) that have specific vulnerabilities (when). In this matrix, all system components are listed in the first column. For each system component value, risks that can occur for that component are presented using the (what/where) matrix. All vulnerabilities are organized from the third column up till the end of the vulnerabilities. The first row of each component displays all vulnerabilities that can exist for that component using the (where/when) matrix. The following rows for that component are made in conjunction with risk where each row defines specific component and certain risk. All checked vulnerabilities from the first row of that component are oriented on the component/risk rows based on each component and risk that can exploit that vulnerability to successfully achieve that risk. This 3D matrix has two types of mappings between risk and vulnerabilities. The first one defines the risks directly occurring due to the existence of a specific vulnerability. This type is presented as the yellow color cells. The other type defines the risks that indirectly

12 Security and Communication Networks

Figure 8: Snapshot of who/why matrix.

current Employee

Risk Incident

Physi cal

th e�

of

hard ware

Devi ce

power fai

lure

dest ructi

on of

hard ware

devi ce

comprem ise

devi ce

misc onfigura

tio n

site - b

uil ding

dest ructi

on

netw ork wire

s

ste alin

g

netw ork wire

s

dam age

netw ork wire

les s

sig nal d

isr upti

on

data sn

iffi ng

data in

ter cep

tio n

data disto

rtio n

data disc

loser

losin g d

ata

Physi cal

th e�

of d ata

gai n physi

cal ac

ces s

gai n re

mote a cce

ss

iden tify

netw ork

devi ces

inapp rop

rat e c

ontro l

comman ds

site penetr

ati on

gai n devi

ce

ad minist

rat or

pass word

hard ware

fai lure

byp ass

pass word

val idati

on

Devi ce

Disa bled

netw ork outag

e

so�ware fai

lure

equipment c rac

h

Former Employee Current business partner (Contractor-provider-suppliers) Former business partner (Contractor-provider-suppliers) Customer Script Kidies industrial spies Online social hacker Coroperate / Competitors Hacktivist Cyber Criminal group Cyber Terrorist National state Earthquakes Floods Tsunamis Landslides Lightning Heavy rains Heavy snowfalls Tornado Wildfire Fires Explosions

Agent

    

    

   

    

                

                    

             

                      

  

            

               

     

                      

                    

                         

                       

                      

    

    

    

    

     

    

    

Figure 9: Snapshot of who/what matrix.

exist due to that vulnerability. This type is presented as red color cells, as shown in Figure 17. This mapping used the interconnected risk map shown in Figure 6 to determine the indirect risks from a specific vulnerability.

The final 3D matrix merged the (what/how) matrix with the (when/how)matrix to generate a new 3Dmatrix of (what/ how/when). This matrix defines the vulnerabilities (when) and which penetration tools (how) can use them to cause certain risks (what). In thismatrix, the first column represents all risks, and the second column represents all penetration techniques for each risk using the (what/how) matrix. All vulnerabilities are displayed from the third column up to the end of the vulnerabilities, as shown in Figure 18.

5.5. Step 5. The consequent step aims to generate the com- plete scenarios by combining the four 3D matrices. The complete risk identification scenarios for SCADA systems are defined by Algorithm 1.

6. A Benchmark Database for the Proposed Model

A benchmark database was developed using the proposed model. This database uses MySQL DB version 5.7.19 MySQL [49] as the database engine. As shown in Figure 19, the Entity Relationship Diagram (ERD) of the database contains 11 tables: one table for coding each risk parameter and

Security and Communication Networks 13

        

        

        

        

         

        

       

       

          

       

         

     

          

 

 

 

 

 

 

 

 

 

 

 

Agent social engineering / phishing

interception/ eavesdropping / espionage

Exploit kits

malicious code Spamming

Web-based attacks

Web application attacks Botnets spoofing

physical attack Disaster

human error /misuse of resources

malfunction of equipement

data manipulation or froging

current Employee

Former Employee Current business partner Former business partner Customer Script Kidies industrial spies Online social hacker Coroperate / Competitors Hacktivist Cyber Criminal group Cyber Terrorist National state Earthquakes Floods Tsunamis Landslides Lightning Heavy rains Heavy snowfalls Tornado Wildfire Fires Explosions

Penetration Techniques

Figure 10: Snapshot of who/how matrix.

Risk Penetration technique

Physi cal

th e�

of

hard ware

Devi ce

power fai

lure

dest ructi

on of

hard ware

devi ce

comprem ise

devi ce

misc onfigura

tio n

site - b

uil ding

dest ructi

on

netw ork wire

s

ste alin

g

netw ork wire

s

dam age

netw ork wire

les s

sig nal d

isr upti

on

data sn

iffi ng

data in

ter cep

tio n

data disto

rtio n

data disc

loser

losin g d

ata

Physi cal

th e�

of d ata

gai n physi

cal ac

ces s

gai n re

mote a cce

ss

iden tify

netw ork

devi ces

inapp rop

rat e c

ontro l

comman ds

site penetr

ati on

gai n devi

ce

ad minist

rat or

pass word

hard ware

fai lure

byp ass

pass word

val idati

on

Devi ce

Disa bled

netw ork outag

e

so�ware fai

lure

equipment c rac

h

social engineering / phishing interception/ eavesdropping / espionage Exploit kits(sw / fw) malicious code Spamming Web-based attacks Web application attacks Botnets spoofing physical attack Disaster ( heat/ water / wind/ land sliding) human error /misuse of resources malfunction of equipement data manipulation or froging

    

     

            

   

        

          

 

  

          

     

            

       

 

Figure 11: Snapshot of what/how matrix.

four tables for mapping the 3D matrices (agent mot risk, agent tool risk, comp risk vuln and risk vuln tool). The last table (Risk scenarios) contains the full risk scenarios matrix for the SCADA system,whichwas generated usingAlgorithm 1.

The risk scenario table resulting from Algorithm 1 con- tains 19,163 scenarios. Figures 20, 21, 22, and 23 show the total number of risk scenarios for each risk, risk agent, risk motivation, and penetration tool, respectively.

7. Case Study

In this section, a case study of the proposed model and the resulted database is presented. This case study shows a short sample of the detailed data about the possible risks scenarios that could occur in a SCADA system and that could be used further by decision makers and risk managers. This data can

help managers to determine the weak points in the system, the possible risk agents, causes that make them attack the system, and the tools and methodologies agents can use to perform these attacks. Also, the benchmark database that was produced by this model could be used to generate a SCADA risk knowledgebase for SCADA Risk Management simulation tools. To the best of our knowledge, this level of detailed information presented by the proposed model and resulted database hasn’t been provided by any type of related research work or database.

7.1. Case Study 1. One of the questions that can be answered by the proposed model is what are the possible risks that risk agents can use to attack a SCADA system and what are the risk scenarios for these attacks?

To answer this question, the proposed model will be applied on Hacktivist as an example of risk agents. The

14 Security and Communication Networks

System Components

Risk

Physi cal

th e�

of

hard ware

Devi ce

power fai

lure

dest ructi

on of

hard ware

devi ce

comprem ise

devi ce

misc onfigura

tio n

site - b

uil ding

dest ructi

on

netw ork wire

s

ste alin

g

netw ork wire

s

dam age

netw ork wire

les s

sig nal d

isr upti

on

data sn

iffi ng

data in

ter cep

tio n

data disto

rtio n

data disc

loser

losin g d

ata

Physi cal

th e�

of d ata

gai n physi

cal ac

ces s

gai n re

mote a cce

ss

iden tify

netw ork

devi ces

inapp rop

rat e c

ontro l

comman ds

site penetr

ati on

gai n devi

ce

ad minist

rat or

pass word

hard ware

fai lure

byp ass

ad min

pass word

Disa ble D

evi ce

netw ork outag

e

so�ware fai

lure

equipem ent c

ras h

Sensor c1                   

Actuator c2                   

RTU c3                    

PLC c4                    

IED c5                    

Switch                    

Router                  

Repeater                 

Modem                  

WLAN access point                 

Firewall                 

Coaxial cable       

Twisted pair cable         

Fiber optic cable         

Radio frequency      

Microwave    

satellite    

Communication server                      

SCADA Server                      

Historian Server                

HMI              

Application server                  

Web server                 

Mobile server                  

PC / labtop                  

Smart phone/ tablet                  

System employees  

System Clients 

3rd party stuff  

Building & site  

Figure 12: Snapshot of what/where matrix.

Building & site

Sensor c1

Actuator c2

RTU c3 PLC c4 IED c5 Switch Router Repeater Modem WLAN access point

Firewall Coaxial cable

Twisted pair

cable

Fiber optic cable

Radio frequency

Microwave satellite Communication

server SCADA Server

Historian Server

HMI Application

server Web

server Mobile server

PC / labtop

Smart phone/ tablet

System employe

es

System Clients

3rd party stuff

Building & site

display information about the system and who operate it unqualified employee

leak of skills, knowledge and training sharing password among users password disclosure former employees / contactor expose their system knowledge to external persons account still activated for former employee and partners isolated sites Poor maintenance apsence of Alarm system weak Windows and Doors controlling Lack or weak of Physical Security Tools

using default password No password used using weak password polices sensitve data unprotected with encryption and password protection unprotected data transefered Critical configurations are not stored or backed up apsence or untested backup procedure Open communication / unprotected protocols are used Unsecured wireless networks system log not maintained or revised periodicaly

Passwords are not encrypted in transit Lack of diversity in communication paths lead to communication failure Poor or non-existent so�ware updates magement Unsecured physical ports Inappropriate or unauthorized access controls absence of UpS and power generator not exists airconditioning failure lack of reduendent hardware introsion detection / prevention so�ware not used, not updated, or not tested anti-virus / anti-mulware not used , not updated, or not tested no warranty agreement No spares management Memory overflow lack of remote access control

Master station corporate network People

Vulnerability

Remote station Communication device wire media Wireless media

√ √

√ √ √ √ √ √ √ √ √ √

√ √ √

√ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √

√ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

√ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

Figure 13: Snapshot of where/when matrix.

steps of the proposed model will be followed to reach the full description of risk scenarios that can exist because of the Hacktivist risk agent. Given the predefined lists of six risk identification parameters, as stated in step 1 of the proposed model, in the upper level the following steps will be performed:

(1) Build the following seven 2D matrices that define the relation between Hacktivist and other risk identifica- tion parameters.

(a) Themotivation ofHacktivist is ideologically and socially (Who/Why matrix).

(b) Risks Hacktivist can cause are destruction of hardware, device compromise, and device mis- configuration (What/Who matrix).

(c) Penetration tools Hacktivist can use are physical attack, malicious code, Web-based attacks and Web application attacks (Who/How matrix).

(d) The relation between each risk Hacktivist can cause and one of his penetration tools he can use is defined in the What/How matrix, such as compromising a device using malicious code or a web-based attack.

Security and Communication Networks 15

Figure 14: Snapshot of when/how matrix.

Risk Agent Risk Motivations

Risk

Physi cal

th e�

of

hard ware

Devi ce

power fai

lure

dest ructi

on of

hard ware

devi ce

comprem ise

devi ce

misc onfigu

rat ion

site - b

uild ing

dest ructi

on

netw ork wire

s

ste ali

ng

netw ork wire

s

dam age

netw ork wire

les s

sig nal d

isr uptio

n

data sn

iffi ng

data in

ter cep

tio n

data disto

rti on

data disc

loser

losin g d

ata

Physi cal

th e�

of d ata

gai n physi

cal ac

ces s

gai n re

mote a cce

ss

identify netw

ork

devi ces

inapproprat e c

ontro l

comman ds

Risk Agent Risk Motivations

current Employee √ √ √ √ √ √ √ √ √ √ √ current Employee Convenience √ √ √ √ √ √ √ √ √ √ current Employee Monetization √ √ √ current Employee Revenge √ √ √ √ √ √ √ √ Former Employee √ √ √ √ √ √ √ √ √ √ √ √ √ √ Former Employee Convenience √ √ √ Former Employee Monetization √ √ √ √ √ √ √ √ √ Former Employee Revenge √ √ √ √ √ √ √ √ √ √ √ Former Employee Socially √ √ √ Current business partner √ √ √ √ √ √ √ √ Current business partner Convenience √ √ √ √ √ √ Current business partner Monetization √ √ √ √ √ √ √ √ Former business partner √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ Former business partner Convenience √ √ √ √ √ Former business partner Monetization √ √ √ √ √ √ √ √ √ √ Former business partner Revenge √ √ √ √ √ √ √ √ √ √ √ √ Customer √ √ √ √ Customer Convenience √ √ Customer Monetization √ √

Figure 15: Snapshot of what/who/why matrix.

Agent Penetration Tools Risk

Physi cal

th e�

of

hard ware

Devi ce

power fai

lure

dest ructi

on of

hard ware

devi ce

comprem ise

devi ce

misc onfigu

rat ion

site - b

uild ing

dest ructi

on

netw ork wire

s

ste ali

ng

netw ork wire

s

dam age

netw ork wire

les s

sig nal d

isr uptio

n

data sn

iffi ng

data in

ter cep

tio n

data disto

rti on

data disc

loser

losin g d

ata

Physi cal

th e�

of d ata

gai n physi

cal ac

ces s

gai n re

mote a cce

ss

identify netw

ork

devi ces

inapproprat e c

ontro l

comman ds

site pen

etr ati

on

gai n devi

ce

ad ministr

ato r

pass word

hard ware

fai lure

data manipulation or froging √ √ Cyber Criminal group √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

social engineering / phishing √ Exploit kits(sw / fw) √ √ √ √ √ √ malicious code(worm / trojan/ virus) √ √ √ √ √ √ √ √ √ Spamming √ √ √ √ Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)

√ √ √ √ √ √

Web application attacks(SQL injection / Code Injection / cross-site scripting/ DDoS attacks)

√ √ √ √ √ √ √

Botnets spoofing (E-mail/ IP Address / identity) √ √ √

physical attack (sabotage /vandalism/ the� /terrorism)

√ √ √ √ √ √ √ √ √ √

data manipulation or froging √ √ Cyber Terrorist √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √ √

malicious code(worm / trojan/ virus) √ √ √ √ √ √ √ √ √ Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)

√ √ √ √ √ √

Figure 16: Snapshot of what/who/how matrix.

16 Security and Communication Networks

          

         

Poor or non-existent so�ware updates management – vulnerabilities to communications equipment routers, switches, firewalls

Unsecured physical ports

Inappropriate or unauthorized access controls

absence of UpS and power generator not exists

airconditioni ng failure

lack of reduendent hardware

introsion detection / prevention so�ware not used, not updated, or not tested

anti-virus / anti- mulware not used , not updated, or not tested

no warranty agreement

No spares manage ment

Memory overflow

lack of remote access control

so�ware failure equipement crash

SCADA Server Physical the� of hardware Device power failure destruction of hardware device compremise device misconfiguration data sniffing data interception data distortion data discloser losing data Physical the� of data gain physical access gain remote access inapproprate control commands identify network devices gain device administrator password hardware failure bypass admin password Disable Device network outage so�ware failure equipement crash

Historian Server Physical the� of hardware Device power failure destruction of hardware device compremise

Component Risk

Vulnerabilities

Figure 17: Snapshot of what/where/when matrix.

 

 

 

 

 

 

 

   

    

    

   

    

    

 

 

 

 

Risk Peneteration Tool

Unsecured wireless networks

system log not maintained or revised periodicaly

Sensitive data are not encrypted in transit

Lack of diversity in communication paths lead to communication failure

Poor or non-existent so�ware updates management – vulnerabilities to communications equipment routers, switches, firewalls

Unsecured physical ports

Inappropri ate or unauthori zed access controls

absence of UpS and power generator not exists

aircondit ioning failure

lack of reduenden t hardware

introsion detection / prevention so�ware not used, not updated, or not tested

anti-virus / anti-mulware not used , not updated, or not tested

Physical the� of hardware physical attack (sabotage /vandalism/ the� /terrorism)

Device power failure physical attack (sabotage /vandalism/ the� /terrorism)

Device power failure Disaster ( heat/ water / wind/ land sliding)

Device power failure human error /misuse of resources destruction of hardware physical attack (sabotage/vandalism/ the� /terrorism)

destruction of hardware Disaster ( heat/ water / wind/ land sliding)

destruction of hardware human error /misuse of resources

device compremise malicious code(worm / trojan/ virus)

device compremise Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)

device compremise Web application attacks(SQL injection / Code Injection / cross- site scripting/ DDoS attacks)

device misconfiguration malicious code(worm / trojan/ virus)

device misconfiguration Web-based attacks ( malicious URLS/ web backdoors/ comprimise web pages/ browser exploits)

device misconfiguration Web application attacks(SQL injection / Code Injection / cross- site scripting/ DDoS attacks)

site- building destruction physical attack (sabotage /vandalism/ the� /terrorism)

site- building destruction Disaster ( heat/ water / wind/ land sliding)

site- building destruction human error /misuse of resources

network wires stealing physical attack (sabotage /vandalism/ the� /terrorism)

Vulnerability

Figure 18: Snapshot of what/ when/ how matrix.

(e) For each risk a Hacktivist can cause, define all system components that can be affected by this risk in the What/Where matrix, such as device misconfiguration that can affect components like the PLC, actuator, Communication server, etc.

(f) For each component that could be attacked by Hacktivist, determine the component’s vul- nerabilities in the Where/When matrix, such

as open communication/unprotected protocols and poor or non-existent software updates management vulnerabilities for communication server.

(g) The relations among system components Hack- tivist can attack and penetration tools he can use are defined in the How/Where matrix, such as physical attacks on a SCADA server component.

Security and Communication Networks 17

Risk Vulnerability ComponentPenetration toolMotivationAgent

agent_mot_risk agent_tool_risk comp_risk_vuln risk_vuln_tool

Risk Scenario

Figure 19: The entity relationship diagram of the proposed model’s database.

0 500

1000 1500 2000 2500 3000 3500

132

2464

1672

658

1294

200 225

1384

228

1583

28

890 387

698

1421

76

712 674 514 75 24 180 180 45 36

3383

Ri sk

S ce

na tr

io s

Total No. of Risk Scenarios Per Risk

byp ass

ad min pass

word

data disc

loser

data disto

rti on

data in

ter cep

tio n

data sn

iffi ng

dest ructi

on of h ard

ware

devi ce

compromise

devi ce

misc onfigu

rat ion

Devi ce

power fai

lure

Disa ble D

evi ce

equipem ent c

ras h

gai n devi

ce ad

ministr ato

r p ass

word

gai n physi

cal ac

ces s

gai n re

mote a cce

ss

hard ware

fai lure

identify netw

ork devi ces

inapproprat e c

ontro l co

mman ds

losin g d

ata

netw ork outag

e

netw ork wire

s d am

age

netw ork wire

s s tea

lin g

Physi cal

th e�

of d ata

Physi cal

th e�

of h ard

ware

site pen

etr ati

on

site - b

uild ing d

est ructi

on

so�ware fai

lure

Figure 20: Total number of risk scenarios per risk.

(2) After that, the previous 2Dmatrices will be combined to form four 3Dmatrices, which provide a description of risks caused by a Hacktivist agent as follows:

(a) Who/Why and What/Who matrices will be combined to define the relation among Hack- tivist, his motivation, and risks he can cause (What/Who/Why matrix), such as a Hacktivist can cause device compromise because of his ideological motivation.

(b) Who/How andWhat/Howmatrices are merged to show risks a Hacktivist can cause and by which penetration tools (What/Who/How matrix) such as a Hacktivist can cause device misconfiguration risk by using web-based attacks.

(c) What/How and How/Where matrices are com- bined to specify risks that can be caused by Hacktivist using which tool and in what com- ponents (What/How/Where matrix), such as

18 Security and Communication Networks

0

500

1000

1500

2000

2500

3000

2579

1137

1701

660

1960

1201

41 41 39 41

2211

1936

306

39 39

1116

41 41

1735

506

1870

41 41 41

Ri sk

S ce

na rio

s

Total No. of Scenarios Per Risk Agent

Coropera te /

Competi tors

Curre nt b

usin ess

part ner

cu rre

nt E mployee

Custo mer

Cyb er

Crim inal g

roup

Cyb er

Terr oris

t

Eart hquakes

Exp losio

ns Fire

s Floods

Form er

busin ess

part ner

Form er

Employee

Hack tiv

ist

Heav y r

ain s

Heav y s

nowfal ls

industr ial

sp ies

Lan dslid

es

Ligh tning

Nati onal s

tat e

Onlin e s

ocia l h

ack er

Scri pt K

idies

Tornad o

Tsunam is

Wild fire

Figure 21: Total number of risk scenarios per risk agent.

0

1000

2000

3000

4000

5000

6000

7000

2872

6565

3447 2935

1735 1364

445

Total No. of Scenarios Per Risk Motivation

Conven ien

ce

Moneti zat

ion

Reve nge

Socia lly

nati onally

Ideol og

ica lly

Envir onmental

ch an

ges

Figure 22: Total number of risk scenarios per risk motivation.

using a physical attack to cause destruction of hardware in HMI.

(d) What/Where and Where/When matrices are combined to determine in what system com- ponent risks can be caused by a Hacktivist and because of what vulnerabilities (What/ Where/When matric), such as destruction of hardware to a PLC due to a lack of or weak physical security tools vulnerability.

(3) Finally, Algorithm 1 will be used to combine the four 3D matrices of the Hacktivist agent to generate the comprehensive description of possible risk scenarios he can cause. The output of running Algorithm 1 is 306 comprehensive scenarios for risks that can be caused by a Hacktivist agent against the SCADA system.

The 306 risk scenarios the risk agent (Hacktivist) can cause are represented in a graphical representation, as shown in Figure 24. All risk identification parameters are coded to be

Security and Communication Networks 19

0 500

1000 1500 2000 2500 3000 3500 4000 4500 5000

132 1395 957

4685

1074 1676

3402

554 68

2896

445 381 978 720

Total No. of Scenarios Per Penetration Tools

socia l en

gin eer

ing / phish

ing

eav esd

ropping / es

pionage

Exp loit k

its

mali cio

us c ode

Sp am

ming

Web-base d att

ack s

Web ap plica

tio n att

ack s

Botnets

spoofing

physi cal

att ack

Disa ste

r

human er

ror

malf uncti

on of eq uipem

ent

data m

an ipulat

ion or fr ogin

g

Figure 23: Total number of risk scenarios per penetration tool.

used in the graphical representation in a readable manner. All parameters’ values and codes are summarized in Table 1. Every path from the Hacktivist Risk agent (A10) at the most left-hand side until Risk (R3, R4, and R5) at the most right-hand side represents an individual comprehensive risk scenario caused by a Hacktivist agent. The path starts from a Hacktivist node (A10) passing through motivations (M), penetration tools (PT), vulnerabilities (V), and components until it reaches the Risk (R) caused by this attack scenario. In Figure 24, three examples of 306 Hacktivist scenarios have been distinguished based on color into green, blue, and red as follows:

(i) In the green scenario, Hacktivist (A10), because of his social motivation (MO4), can use malicious code (PT4) to cause a device compromise (R4) to any router (CD2) when sensitive data are not encrypted in transit vulnerability (V23) occurs.

(ii) In the red scenario, Hacktivist (A10), because of his social motivation (MO4), can use Web-based attacks (PT6) to cause a device misconfiguration risk (R5) to any Communication server (MS1) in the SCADA system when the open communication/unprotected protocols vulnerability (V20) are used.

(iii) In the blue scenario, Hacktivist (A10), because of his ideological motivation (MO5), can use a physical attack (PT10) to destroy the hardware (R3) of any SCADA server (MS2) when a lack of or weak Physical Security Tools vulnerability (V12) occurs.

The other risk scenarios that affect the SCADA system by a Hacktivist can be traced using the graphical representa- tion in Figure 24 and the risk parameters value codes in Table 1. Figure 21 shows the total number of risk scenarios that can be affected in the SCADA system for each risk agent.

7.2. Case Study 2. Another question from SCADA and security managers the proposed model and benchmark DB

can answer is who are the risk agents that can cause a specific risk to the system, and what are the scenarios for that risk? To answer this type of question, the proposed model will be applied to gaining physical access as an example of a risk that can affect the system. Starting from the gaining physical access risk, the seven 2D matrices related to this risk will be built. These 2D matrices will then be combined to form the four 3D matrices for the gaining physical access risk. Finally, Algorithm 1 will be run to generate the possible scenarios for this risk. There are 387 scenarios that can result from gaining physical access to a system. These resulting scenarios for this risk are graphically represented in Figure 25, which shows that there are eight agents that can cause the gaining physical access risk on 23 system components. The total possible risk scenarios for each risk are summarized in Figure 20.

8. Conclusion and Future Work

SCADA systems are one of the most critical industrial systems because of their functionality in supervising and controlling large and worldwide industrial networks, such as electricity and gas distribution networks. Their criticality nature exposes them to a large set of risks from either natural or human sources. To manage these risks, a powerful risk management framework is needed to predict the most significant risks and handle them correctly. This framework should be based on a comprehensive risk identification step. In this paper, the most important parameters that are needed to define SCADA risks were outlined. Then, previous works in the field of risk identification phases of SCADA systems were discussed. A comparative study was provided based on a number of risk identification parameters and the level of mapping between these parameters. Then, a comprehen- sive model for risk identification of SCADA systems was proposed. This model used the hierarchical representation methodology to build themodel, which started fromdefining all risk parameters and mapping them gradually into 2D

20 Security and Communication Networks

A10

M4

M5

PT4

PT6

PT7

PT10

CD3

CD4

CD5

CD6

MS1

RS1

RS2

RS3

CD1

CD2

RS4

RS5

MS2

MS3

CN1

CN2

CN3

TR1

TR2

MS4

V31

V32

V18

V25

V20

V27

V36

V12

V17

V23

R4

R5

R3

Figure 24: Possible Risk scenarios on SCADA system by Hacktivist attacker.

Security and Communication Networks 21

R16

A2

A3

A4

A1

A9

A11

A12

M2

M3

M4

M5

M6

M1

A13

PT6

V12

V26

CD3

CD4

CD5

CD6

MS1

RS1

RS2

RS3

CD1

CD2

RS4

RS5

MS2

MS3

WM1

WM2

WM3

TR1

TR2

CN1

MS4

CN2

CN3

Risk

Component

Vulnerability

Penetration tool

Motivation

Agent

Figure 25: Possible Risk scenarios on SCADA system cause gain physical access.

matrices and on to a 6D matrix. This 6D matrix represented the relations among six risk parameters that were defined to draw complete risk scenarios. Finally, this model was used to build a benchmark database containing 19,163 risk scenarios that could be applied to SCADA systems.

In the future, a classification model should be built using this database to generate a set of rules that could be used further in analyzing and assessing the risks affecting any SCADA system. Then, a simulation for managing SCADA system risks should be developed.

22 Security and Communication Networks

Input: amr is the agent motivation risk matrix, atr is agent tool risk matrix, rvt is the risk vulnerability tool matrix and crv is the component risk vulnerability matrix

Output: RSM is Risk Scenarios Matrix which maps (agent, motivation, risk, tool, vulnerability, component). Begin

1 Fetch all data from amr. 2 for all amri E amr do 3 current agent = amri .agent 4 current motivation = amri .motivation 5 current risk = amri .risk 6 Fetch all tools from atr matrix as amr tools where atr.agent = current agent and atr.risk = current risk 7 for all amr toolsj E amr tools do 8 current tool = amr toolsj .tool 9 Fetch all vulnerabilities from rvt matrix as amrt-vulnerabilities where rvt.risk = current risk and rvt.tool =

current tool 10 for all amrt-vulnerabilitiesk E amrt-vulnerabilities do 11 current-vulnerability = amrt-vulnerabilities k .vulnerability 12 Fetch all components from crv matrix as amrtv-components where crv.risk = current risk and

crv.vulnerability = current-vulnerability 13 for all amrtv-componentsi E amrtv-components do 14 current component = amrtv-components i .component 15 Insert into RSM (currenta gent, current-motivation, current risk, current tool, current vulnerability,

current- component). 16 end for 17 end for 18 end for 19 end for

End

Algorithm 1: Generate 6-dimension SCADA risk matrix.

Data Availability

The data used to support the findings of this study are included within the supplementary information file(s) (avail- able here).

Conflicts of Interest

The authors declare that they have no conflicts of interest.

Supplementary Materials

Supplementary material file is a compressed file that con- tains two files: a. The first file “SCADA Risk identifica- tion data.xlsx” is a spreadsheet file that contains the full mapping of the risk identification parameters stated in the paper as 2D and 3D matrices. The snapshots of these matrices were presented in the paper. b. The second file “scada risk secnarios.sql” is sql script of our proposedmodel database. This database contains the six tables for coding the six risk identification parameters and four tables for four 3D matrices demonstrated in the model. The last table “risk scenarios” is the 6D matrix that was produced by Algorithm 1 to present the full mapping of risk identification scenarios.This table contains 19163 scenarios that can be used as risk scenario for using in the risk assessment purpose of SCADA systems. (Supplementary Materials)

References

[1] T.Macaulay andB. L. Singer,Cybersecurity for Industrial Control Systems, CRC Press, Boca Raton, Fla, USA, 2012.

[2] K. Markantonakis and K. Mayes, Secure Smart Embedded Devices, Platforms and Applications, Springer New York, New York, NY, USA, 2014.

[3] J. Gao, J. Liu, B. Rajan et al., “SCADA communication and security issues,” Security and Communication Networks, vol. 7, no. 1, pp. 175–194, 2014.

[4] A. Nicholson, S. Webber, S. Dyer, T. Patel, and H. Janicke, “SCADA security in the light of cyber-warfare,” Computers & Security, vol. 31, no. 4, pp. 418–436, 2012.

[5] M. Riis and T. Sjomoem, Integration between SCADA Systems and Hydraulic Network Simulation Models, 2016, http://hdl.handle.net/11250/2433613.

[6] A. Rezai, P. Keshavarzi, and Z. Moravej, “Secure SCADA communication by using a modified key management scheme,” ISA Transactions, vol. 52, no. 4, pp. 517–524, 2013.

[7] S. Huda, J. Yearwood, M. M. Hassan, and A. Almogren, “Secur- ing the operations in SCADA-IoT platform based industrial control system using ensemble of deep belief networks,”Applied So� Computing, vol. 71, pp. 66–77, 2018.

[8] A. Rezai, P. Keshavarzi, and Z. Moravej, “Key management issue in SCADA networks: a review,” Engineering Science and Technology, an International Journal, vol. 20, no. 1, pp. 354–363, 2017.

[9] E. Luiijf, “SCADAsecurity good practices for the drinkingwater sector,” 2008, http://publications.tno.nl/publication//KpvRNU/ TNO-DV2008C096 web.pdf.

Security and Communication Networks 23

[10] S. Karnouskos and A. W. Colombo, “Architecting the next generation of service-based SCADA/DCS system of systems,” in Proceedings of the the 37th Annual Conference of the IEEE Industrial Electronics Society, 2011.

[11] C. Nan, I. Eusgeld, and W. Kröger, “Analyzing vulnerabilities between SCADA system and SUC due to interdependencies,” Reliability Engineering & System Safety, vol. 113, no. 1, pp. 76–93, 2013.

[12] A. Rezai, P. Keshavarzi, and Z. Moravej, “Advance hybrid key management architecture for SCADA network security,” Security and Communication Networks, vol. 9, no. 17, pp. 4358– 4368, 2016.

[13] O. Andreeva, S. Gordeychik, G. Gritsai et al., “Indus- trial control systems and their online availability,” 2016, https://kas.pr/KL ICS Availability Statistics.

[14] M. Jouini, L. B. A. Rabai, and A. B. Aissa, “Classification of security threats in information systems,” Procedia Computer Science, vol. 32, pp. 489–496, 2014.

[15] International Organization for Standardization, “Risk management Principles and guidelines,” ISO 31000, 2018, https://www.iso.org/obp/ui#iso:std:iso:31000:ed-2:v1:en.

[16] D.Kasap andM.Kaymak, “Risk identification step of the project risk management,” in Proceedings of the Portland International Conference on Management of Engineering and Technolog, pp. 2116–2120, 2007.

[17] Y. Cherdantseva, P. Burnap, and A. Blyth, “A review of cyber security risk assessment methods for SCADA systems,” Com- puters & Security, vol. 56, pp. 1–27, 2016.

[18] E. Byres and M. Fabro, “RISI - The Repository of Industrial Security Incidents,” 2015, http://www.risidata.com/Database.

[19] Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), 2018, https://ics-cert.us-cert.gov/.

[20] E. Bompard, T. Huang, Y. Wu, and M. Cremenescu, “Classi- fication and trend analysis of threats origins to the security of power systems,” International Journal of Electrical Power & Energy Systems, vol. 50, no. 1, pp. 50–64, 2013.

[21] B. Zhu, A. Joseph, and S. Sastry, “A taxonomy of cyber attacks on SCADA systems,” in Proceedings of the 2011 International Con- ference on Internet of �ings and 4th International Conference on Cyber, Physical and Social Computing, pp. 380–388, Dalian, China, 2011.

[22] R. Hewett, S. Rudrapattana, and P. Kijsanayothin, “Cyber- security analysis of smart grid SCADA systems with game models,” in Proceedings of the 9th Annual Cyber and Information Security Research Conference, pp. 109–112, Tennessee, Tenn, USA, 2014.

[23] K. Stouffer, V. Pillitteri, S. Lightman et al., “Guide to industrial control systems security (NIST SP 80082),” 2015, http://dx.doi .org/10.6028/NIST.SP.800-82r2.

[24] W. B. Miller, D. C. Rowe, R. Helps et al., “A comprehensive and open framework for classifying incidents involving cyber- physical systems,” in Proceedings of the 2014 IAJC/ISAM Joint International Conference, 2014.

[25] J. C. H. Gabriel, M. Y. Jose, and L. A. Roberto, “Using inter- connected risk maps to assess the threats faced by electricity infrastructures,” International Journal of Critical Infrastructure Protection, vol. 6, no. 3, pp. 197–216, 2013.

[26] A. M. Elhady, A. Abou Elfetouh, H. M. El-bakry et al., “Generic Software risk management framework for SCADA system,” International Journal of Computer Applications, vol. 70, no. 3, pp. 45–52, 2013.

[27] B. Kitchenham and P. Brereton, “A systematic review of systematic review process research in software engineering,” Information and So�ware Technology, vol. 55, no. 12, pp. 2049– 2075, 2013.

[28] National Institute of Standards and Technology (NIST), 2018, https://www.nist.gov/.

[29] EuropeanUnionAgency for Network and Information Security (ENISA), 2019, https://www.enisa.europa.eu/.

[30] United State Department of Homeland Security (US. DHS), 2018, https://www.dhs.gov/.

[31] W. Schwab andM. Poujol, “The state of industrial cybersecurity 2018,” 2018, https://ics.kaspersky.com/media/2018-Kaspersky- ICS-Whitepaper.pdf.

[32] Communication network dependencies for ICS/SCADA Systems, 2016, https://www.enisa.europa.eu/publications/ics- scada-dependencies.

[33] B. G. Brown and D. Wylie, “Securing Industrial Control Systems,” 2017, https://www.tripwire.com/solutions/industrial- control-systems/sans-state-of-ics-report-register/.

[34] Generic SCADA Risk Management Framework for Australian Critical Infrastructure, 2012, https://www.tisn.gov.au/Documents/ SCADA-Generic-Risk-Management-Framework.pdf.

[35] Common cyber security vulnerabilities in industrial control systems, 2009, https://www.hsdl.org/?view&did=7970.

[36] M. Nasser, R. Ahmad, W. Yassin et al., “Cyber-security inci- dents: a review cases in cyber-physical systems,” International Journal of Advanced Computer Science and Applications, vol. 9, no. 1, 2018.

[37] A. G. Finogeev and A. A. Finogeev, “Information attacks and security in wireless sensor networks of industrial SCADA systems,” Journal of Industrial Information Integration, vol. 5, pp. 6–16, 2017.

[38] P. Eden, P. Burnap, A. Blyth et al., “A forensic taxonomy of SCADA systems and approach to incident response,” in Proceedings of the 3rd International Symposium for ICS and SCADA Cyber Security Research, pp. 27–39, 2015.

[39] P. S. Woo and B. H. Kim, “A study on quantitative methodology to assess cyber security risk of SCADA systems,” Advanced Materials Research, vol. 960-961, pp. 1602–1611, 2014.

[40] A. F. Guillermo, T. David, and D. Joshua, “Security Best Prac- tices and Risk Assessment of SCADA and Industrial Control Systems,” in Proceedings of the 2012 world congress in computer science, computer engineering, and applied computing, 2012.

[41] R. Tsang, Cyberthreats, Vulnerabilities and Attacks on SCADA Networks, Goldman School of Public Policy. University of California, 2010.

[42] D. Kang, J. Lee, S. Kim et al., “Analysis on cyber threats to SCADA systems,” in Proceedings of the 2009 Transmission and Distribution Conference and Exposition: Asia and Pacific, 2009.

[43] National Vulnerability Database (NVD), 2019, https://nvd.nist .gov/.

[44] Common Vulnerabilities and Exposures (CVE), 2019, https:// cve.mitre.org/.

[45] Bugtraq Team, 2016, http://bugtraq-team.com/. [46] Open Sourced Vulnerability Database (OSVDB), 2017, https://

blog.osvdb.org/.

24 Security and Communication Networks

[47] Open Vulnerability and Assessment Language (OVAL), 2016, http://oval.mitre.org/.

[48] L. Marinos, A. Belmonte, and E. Rekleitis, “enisa threat landscape 2015,” 2016, https://www.enisa.europa.eu/publications/ etl2015/at download/fullReport.

[49] Mysql.com, 2018, https://www.mysql.com/.

International Journal of

Aerospace Engineering Hindawi www.hindawi.com Volume 2018

Robotics Journal of

Hindawi www.hindawi.com Volume 2018

Hindawi www.hindawi.com Volume 2018

Active and Passive Electronic Components

VLSI Design

Hindawi www.hindawi.com Volume 2018

Hindawi www.hindawi.com Volume 2018

Shock and Vibration

Hindawi www.hindawi.com Volume 2018

Civil Engineering Advances in

Acoustics and Vibration Advances in

Hindawi www.hindawi.com Volume 2018

Hindawi www.hindawi.com Volume 2018

Electrical and Computer Engineering

Journal of

Advances in OptoElectronics

Hindawi www.hindawi.com

Volume 2018

Hindawi Publishing Corporation http://www.hindawi.com Volume 2013 Hindawi www.hindawi.com

The Scientific World Journal

Volume 2018

Control Science and Engineering

Journal of

Hindawi www.hindawi.com Volume 2018

Hindawi www.hindawi.com

Journal ofEngineering Volume 2018

Sensors Journal of

Hindawi www.hindawi.com Volume 2018

International Journal of

Rotating Machinery

Hindawi www.hindawi.com Volume 2018

Modelling & Simulation in Engineering Hindawi www.hindawi.com Volume 2018

Hindawi www.hindawi.com Volume 2018

Chemical Engineering International Journal of Antennas and

Propagation

International Journal of

Hindawi www.hindawi.com Volume 2018

Hindawi www.hindawi.com Volume 2018

Navigation and Observation

International Journal of

Hindawi

www.hindawi.com Volume 2018

Advances in

Multimedia

Submit your manuscripts at www.hindawi.com