CySCPro - Cyber Supply Chain Provenance Framework for Risk Management of Energy Delivery Systems

Eranga Bandara, Deepak K. Tosh, S. Shetty, Bheshaj Krishnappa
{"title":"CySCPro - Cyber Supply Chain Provenance Framework for Risk Management of Energy Delivery Systems","authors":"Eranga Bandara, Deepak K. Tosh, S. Shetty, Bheshaj Krishnappa","doi":"10.1109/Blockchain53845.2021.00020","DOIUrl":null,"url":null,"abstract":"For operational efficiency, enterprise-level Energy Delivery Systems (EDS) rely on a number of software or hardware providers. Overseas suppliers generally manufacture and integrate critical EDS components, increasing the attack surface for adversaries looking to enter EDS (e.g., the recent SolarWinds supply chain attack). The EDS supply chain requires cyber risk management that can track cyber vulnerabilities, establish quantifiable mechanisms to understand the severity and exploitability of EDS applications while providing a remediation plan to effectively mitigate such risks. In this work, we propose a Cyber Supply Chain Provenance platform for EDS by leveraging distributed ledger technology for enabling cyber risk management capability to defend and respond to cyber supply-chain attacks (e.g., SolarWinds) and establish data provenance in a cyber supply chain ecosystem.","PeriodicalId":372721,"journal":{"name":"2021 IEEE International Conference on Blockchain (Blockchain)","volume":"26 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Conference on Blockchain (Blockchain)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/Blockchain53845.2021.00020","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

For operational efficiency, enterprise-level Energy Delivery Systems (EDS) rely on a number of software or hardware providers. Overseas suppliers generally manufacture and integrate critical EDS components, increasing the attack surface for adversaries looking to enter EDS (e.g., the recent SolarWinds supply chain attack). The EDS supply chain requires cyber risk management that can track cyber vulnerabilities, establish quantifiable mechanisms to understand the severity and exploitability of EDS applications while providing a remediation plan to effectively mitigate such risks. In this work, we propose a Cyber Supply Chain Provenance platform for EDS by leveraging distributed ledger technology for enabling cyber risk management capability to defend and respond to cyber supply-chain attacks (e.g., SolarWinds) and establish data provenance in a cyber supply chain ecosystem.
CySCPro -能源输送系统风险管理的网络供应链来源框架
为了提高运营效率,企业级能源交付系统(EDS)依赖于许多软件或硬件供应商。海外供应商通常制造和集成关键的EDS组件,增加了希望进入EDS的对手的攻击面(例如,最近的SolarWinds供应链攻击)。EDS供应链需要网络风险管理,可以跟踪网络漏洞,建立可量化的机制,以了解EDS应用的严重性和可利用性,同时提供补救计划,有效降低此类风险。在这项工作中,我们为EDS提出了一个网络供应链溯源平台,利用分布式账本技术实现网络风险管理能力,以防御和响应网络供应链攻击(例如,SolarWinds),并在网络供应链生态系统中建立数据溯源。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信