A Framework for Development of Risk-Informed Autonomous Adaptive Cyber ControllersSource: Journal of Computing and Information Science in Engineering:;2019:;volume( 019 ):;issue: 004::page 41004Author:Veeramany, Arun
,
Hutton, William J.
,
Sridhar, Siddharth
,
Gourisetti, Sri Nikhil Gupta
,
Coles, Garill A.
,
Skare, Paul M.
DOI: 10.1115/1.4043040Publisher: American Society of Mechanical Engineers (ASME)
Abstract: This article details a framework and methodology to risk-inform the decisions of an unsupervised cyber controller. A risk assessment methodology within this framework uses a combination of fault trees, event trees, and attack graphs to trace and map cyber elements with business processes. The methodology attempts to prevent and mitigate cyberattacks by using adaptive controllers that proactively reconfigure a network based on actionable risk estimates. The estimates are based on vulnerabilities and potential business consequences. A generic enterprise-control system is used to demonstrate the wide applicability of the methodology. In addition, data needs, implementation, and potential pitfalls are discussed.
|
Show full item record
| contributor author | Veeramany, Arun | |
| contributor author | Hutton, William J. | |
| contributor author | Sridhar, Siddharth | |
| contributor author | Gourisetti, Sri Nikhil Gupta | |
| contributor author | Coles, Garill A. | |
| contributor author | Skare, Paul M. | |
| date accessioned | 2019-09-18T09:06:09Z | |
| date available | 2019-09-18T09:06:09Z | |
| date copyright | 6/3/2019 12:00:00 AM | |
| date issued | 2019 | |
| identifier issn | 1530-9827 | |
| identifier other | jcise_19_4_041004 | |
| identifier uri | http://yetl.yabesh.ir/yetl1/handle/yetl/4258883 | |
| description abstract | This article details a framework and methodology to risk-inform the decisions of an unsupervised cyber controller. A risk assessment methodology within this framework uses a combination of fault trees, event trees, and attack graphs to trace and map cyber elements with business processes. The methodology attempts to prevent and mitigate cyberattacks by using adaptive controllers that proactively reconfigure a network based on actionable risk estimates. The estimates are based on vulnerabilities and potential business consequences. A generic enterprise-control system is used to demonstrate the wide applicability of the methodology. In addition, data needs, implementation, and potential pitfalls are discussed. | |
| publisher | American Society of Mechanical Engineers (ASME) | |
| title | A Framework for Development of Risk-Informed Autonomous Adaptive Cyber Controllers | |
| type | Journal Paper | |
| journal volume | 19 | |
| journal issue | 4 | |
| journal title | Journal of Computing and Information Science in Engineering | |
| identifier doi | 10.1115/1.4043040 | |
| journal fristpage | 41004 | |
| journal lastpage | 041004-10 | |
| tree | Journal of Computing and Information Science in Engineering:;2019:;volume( 019 ):;issue: 004 | |
| contenttype | Fulltext |