关键基础设施对象信息系统网络安全风险评估

V. Mokhor, S. Honchar, A. Onyskova
{"title":"关键基础设施对象信息系统网络安全风险评估","authors":"V. Mokhor, S. Honchar, A. Onyskova","doi":"10.1109/PICST51311.2020.9467957","DOIUrl":null,"url":null,"abstract":"The concept of complex cybersecurity risk of information systems of critical infrastructure objects is substantiated in the paper, the vector model of risk and model of complex risk is offered, the method of calculation of total risk, complex risk is offered, the structural decision of computer system for calculation of cybersecurity risk of information systems of critical infrastructure objects is developed. Using the proposed method, it is possible to solve the issue related to the possibility of calculating the amount of risks, which allows to assess the risk as a whole, taking into account the human factor in risk assessment, which is extremely important for critical infrastructure, especially in the energy sector. The proposed computing system can be used as part of a decision support system for assessing cybersecurity risks of information systems of critical infrastructure facilities. The results obtained can be used to assess the cybersecurity risk of information systems of critical infrastructure objects in the construction and implementation of information security management systems, integrated information protection systems in automated systems in the development of a threat model, security policy, and protection plan. Despite a significant number of approaches to solving this problem, it remains relevant for the entire world community.","PeriodicalId":123008,"journal":{"name":"2020 IEEE International Conference on Problems of Infocommunications. Science and Technology (PIC S&T)","volume":"232 3","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":"{\"title\":\"Cybersecurity Risk Assessment of Information Systems of Critical Infrastructure Objects\",\"authors\":\"V. Mokhor, S. Honchar, A. Onyskova\",\"doi\":\"10.1109/PICST51311.2020.9467957\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The concept of complex cybersecurity risk of information systems of critical infrastructure objects is substantiated in the paper, the vector model of risk and model of complex risk is offered, the method of calculation of total risk, complex risk is offered, the structural decision of computer system for calculation of cybersecurity risk of information systems of critical infrastructure objects is developed. Using the proposed method, it is possible to solve the issue related to the possibility of calculating the amount of risks, which allows to assess the risk as a whole, taking into account the human factor in risk assessment, which is extremely important for critical infrastructure, especially in the energy sector. The proposed computing system can be used as part of a decision support system for assessing cybersecurity risks of information systems of critical infrastructure facilities. The results obtained can be used to assess the cybersecurity risk of information systems of critical infrastructure objects in the construction and implementation of information security management systems, integrated information protection systems in automated systems in the development of a threat model, security policy, and protection plan. Despite a significant number of approaches to solving this problem, it remains relevant for the entire world community.\",\"PeriodicalId\":123008,\"journal\":{\"name\":\"2020 IEEE International Conference on Problems of Infocommunications. Science and Technology (PIC S&T)\",\"volume\":\"232 3\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-10-06\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"5\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 IEEE International Conference on Problems of Infocommunications. Science and Technology (PIC S&T)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/PICST51311.2020.9467957\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE International Conference on Problems of Infocommunications. Science and Technology (PIC S&T)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/PICST51311.2020.9467957","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

摘要

提出了关键基础设施对象信息系统复杂网络安全风险的概念,提出了风险矢量模型和复杂风险模型,给出了总风险、复杂风险的计算方法,开发了关键基础设施对象信息系统网络安全风险计算的计算机系统结构决策。使用所提出的方法,可以解决与计算风险数量的可能性相关的问题,从而可以整体评估风险,考虑到风险评估中的人为因素,这对于关键基础设施,特别是在能源部门极为重要。该计算系统可作为决策支持系统的一部分,用于评估关键基础设施信息系统的网络安全风险。所得结果可用于评估关键基础设施对象信息系统在构建和实施信息安全管理系统时的网络安全风险,以及在制定威胁模型、安全策略和保护计划时的自动化系统中的集成信息保护系统。尽管有许多解决这一问题的办法,但它仍然与整个国际社会有关。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Cybersecurity Risk Assessment of Information Systems of Critical Infrastructure Objects
The concept of complex cybersecurity risk of information systems of critical infrastructure objects is substantiated in the paper, the vector model of risk and model of complex risk is offered, the method of calculation of total risk, complex risk is offered, the structural decision of computer system for calculation of cybersecurity risk of information systems of critical infrastructure objects is developed. Using the proposed method, it is possible to solve the issue related to the possibility of calculating the amount of risks, which allows to assess the risk as a whole, taking into account the human factor in risk assessment, which is extremely important for critical infrastructure, especially in the energy sector. The proposed computing system can be used as part of a decision support system for assessing cybersecurity risks of information systems of critical infrastructure facilities. The results obtained can be used to assess the cybersecurity risk of information systems of critical infrastructure objects in the construction and implementation of information security management systems, integrated information protection systems in automated systems in the development of a threat model, security policy, and protection plan. Despite a significant number of approaches to solving this problem, it remains relevant for the entire world community.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信