Eranga Bandara, Deepak K. Tosh, S. Shetty, Bheshaj Krishnappa
{"title":"CySCPro - Cyber Supply Chain Provenance Framework for Risk Management of Energy Delivery Systems","authors":"Eranga Bandara, Deepak K. Tosh, S. Shetty, Bheshaj Krishnappa","doi":"10.1109/Blockchain53845.2021.00020","DOIUrl":null,"url":null,"abstract":"For operational efficiency, enterprise-level Energy Delivery Systems (EDS) rely on a number of software or hardware providers. Overseas suppliers generally manufacture and integrate critical EDS components, increasing the attack surface for adversaries looking to enter EDS (e.g., the recent SolarWinds supply chain attack). The EDS supply chain requires cyber risk management that can track cyber vulnerabilities, establish quantifiable mechanisms to understand the severity and exploitability of EDS applications while providing a remediation plan to effectively mitigate such risks. In this work, we propose a Cyber Supply Chain Provenance platform for EDS by leveraging distributed ledger technology for enabling cyber risk management capability to defend and respond to cyber supply-chain attacks (e.g., SolarWinds) and establish data provenance in a cyber supply chain ecosystem.","PeriodicalId":372721,"journal":{"name":"2021 IEEE International Conference on Blockchain (Blockchain)","volume":"26 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Conference on Blockchain (Blockchain)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/Blockchain53845.2021.00020","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
For operational efficiency, enterprise-level Energy Delivery Systems (EDS) rely on a number of software or hardware providers. Overseas suppliers generally manufacture and integrate critical EDS components, increasing the attack surface for adversaries looking to enter EDS (e.g., the recent SolarWinds supply chain attack). The EDS supply chain requires cyber risk management that can track cyber vulnerabilities, establish quantifiable mechanisms to understand the severity and exploitability of EDS applications while providing a remediation plan to effectively mitigate such risks. In this work, we propose a Cyber Supply Chain Provenance platform for EDS by leveraging distributed ledger technology for enabling cyber risk management capability to defend and respond to cyber supply-chain attacks (e.g., SolarWinds) and establish data provenance in a cyber supply chain ecosystem.