The Impact of Social Engineering on Industrial Control System Security

B. Green, D. Prince, J. Busby, D. Hutchison
{"title":"The Impact of Social Engineering on Industrial Control System Security","authors":"B. Green, D. Prince, J. Busby, D. Hutchison","doi":"10.1145/2808705.2808717","DOIUrl":null,"url":null,"abstract":"In assessing the security posture of Industrial Control Systems (ICS), several approaches have been proposed, including attack graphs, attack trees, Bayesian networks and security ideals. Predominantly focusing on technical vulnerabilities, challenges stemming from social and organisational factors are often reviewed in isolation, if at all. Taking a mean time-to-compromise (MTTC) metric as a base for expansion, we explore the impact social engineering attack vectors (malicious e-mails) could have on such assessments. The applied method takes a holistic view, to better understand the potential impact of social engineering across a small European utility company. The results of this review are analysed and discussed, highlighting the level of access an attacker could gain through social engineering, and the need for assessment metrics to include vulnerabilities stemming not only from technical factors, but social and organisational ones as well.","PeriodicalId":144851,"journal":{"name":"Proceedings of the First ACM Workshop on Cyber-Physical Systems-Security and/or PrivaCy","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-10-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"16","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the First ACM Workshop on Cyber-Physical Systems-Security and/or PrivaCy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2808705.2808717","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 16

Abstract

In assessing the security posture of Industrial Control Systems (ICS), several approaches have been proposed, including attack graphs, attack trees, Bayesian networks and security ideals. Predominantly focusing on technical vulnerabilities, challenges stemming from social and organisational factors are often reviewed in isolation, if at all. Taking a mean time-to-compromise (MTTC) metric as a base for expansion, we explore the impact social engineering attack vectors (malicious e-mails) could have on such assessments. The applied method takes a holistic view, to better understand the potential impact of social engineering across a small European utility company. The results of this review are analysed and discussed, highlighting the level of access an attacker could gain through social engineering, and the need for assessment metrics to include vulnerabilities stemming not only from technical factors, but social and organisational ones as well.
社会工程对工业控制系统安全的影响
在评估工业控制系统(ICS)的安全状态时,已经提出了几种方法,包括攻击图,攻击树,贝叶斯网络和安全理想。主要侧重于技术漏洞,社会和组织因素产生的挑战往往被孤立地审查,如果有的话。以平均入侵时间(MTTC)度量作为扩展的基础,我们探索了社会工程攻击向量(恶意电子邮件)可能对此类评估产生的影响。应用的方法采用整体的观点,以更好地理解社会工程对一家小型欧洲公用事业公司的潜在影响。对审查的结果进行了分析和讨论,突出了攻击者可以通过社会工程获得的访问级别,以及评估指标的需求,这些指标不仅包括技术因素,还包括社会和组织因素。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信