基于MITRE攻击与ICS框架的智能电网系统威胁映射

Ahmad Balya Izzuddin, Charles Lim
{"title":"基于MITRE攻击与ICS框架的智能电网系统威胁映射","authors":"Ahmad Balya Izzuddin, Charles Lim","doi":"10.1109/ICARES56907.2022.9993475","DOIUrl":null,"url":null,"abstract":"The smart grid system is an integration between power distribution systems with communication networks. A smart grid offers various benefits, but at the same time inherits various vulnerabilities from the implemented information and communication technology (ICT). Many devices in smart grid systems implement the TCP/IP stack to exchange data, which can lead to significant new cyber attack vectors, such as malware, Denial-of-service (DoS), man-in-the-middle (MITM), and replay attacks, as well as various other cybersecurity threats. One approach to deal with these security issues proactively is through threat modeling. We can utilize some tools to gather the threat data targeting the smart grid, such as using honeypots, then analyze the collected threat data to obtain the threat model in order to study the attackers' behavior. In this paper, we collected threat data targeting the smart grid system by deploying GridPot honeypot and analyzed the collected threat data by mapping them to the MITRE ATT&CK for Industrial Control System (ICS) framework. This experiment shows that the threats targeting the smart grid systems are real, and could harm any smart grid system in the world.","PeriodicalId":252801,"journal":{"name":"2022 IEEE International Conference on Aerospace Electronics and Remote Sensing Technology (ICARES)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-11-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Mapping Threats in Smart Grid System Using the MITRE ATT&CK ICS Framework\",\"authors\":\"Ahmad Balya Izzuddin, Charles Lim\",\"doi\":\"10.1109/ICARES56907.2022.9993475\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The smart grid system is an integration between power distribution systems with communication networks. A smart grid offers various benefits, but at the same time inherits various vulnerabilities from the implemented information and communication technology (ICT). Many devices in smart grid systems implement the TCP/IP stack to exchange data, which can lead to significant new cyber attack vectors, such as malware, Denial-of-service (DoS), man-in-the-middle (MITM), and replay attacks, as well as various other cybersecurity threats. One approach to deal with these security issues proactively is through threat modeling. We can utilize some tools to gather the threat data targeting the smart grid, such as using honeypots, then analyze the collected threat data to obtain the threat model in order to study the attackers' behavior. In this paper, we collected threat data targeting the smart grid system by deploying GridPot honeypot and analyzed the collected threat data by mapping them to the MITRE ATT&CK for Industrial Control System (ICS) framework. This experiment shows that the threats targeting the smart grid systems are real, and could harm any smart grid system in the world.\",\"PeriodicalId\":252801,\"journal\":{\"name\":\"2022 IEEE International Conference on Aerospace Electronics and Remote Sensing Technology (ICARES)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-11-24\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 IEEE International Conference on Aerospace Electronics and Remote Sensing Technology (ICARES)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICARES56907.2022.9993475\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE International Conference on Aerospace Electronics and Remote Sensing Technology (ICARES)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICARES56907.2022.9993475","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

智能电网系统是配电系统与通信网络的集成。智能电网具有多种优势,但同时也继承了信息通信技术(ICT)所带来的各种漏洞。智能电网系统中的许多设备实现TCP/IP堆栈来交换数据,这可能导致重要的新网络攻击媒介,例如恶意软件、拒绝服务(DoS)、中间人(MITM)和重放攻击,以及各种其他网络安全威胁。主动处理这些安全问题的一种方法是通过威胁建模。我们可以利用蜜罐等工具收集针对智能电网的威胁数据,然后对收集到的威胁数据进行分析,得到威胁模型,从而研究攻击者的行为。在本文中,我们通过部署GridPot蜜罐收集针对智能电网系统的威胁数据,并将收集到的威胁数据映射到MITRE工业控制系统(ICS)框架中进行分析。实验表明,针对智能电网系统的威胁是真实存在的,并且可能对世界上任何一个智能电网系统造成危害。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Mapping Threats in Smart Grid System Using the MITRE ATT&CK ICS Framework
The smart grid system is an integration between power distribution systems with communication networks. A smart grid offers various benefits, but at the same time inherits various vulnerabilities from the implemented information and communication technology (ICT). Many devices in smart grid systems implement the TCP/IP stack to exchange data, which can lead to significant new cyber attack vectors, such as malware, Denial-of-service (DoS), man-in-the-middle (MITM), and replay attacks, as well as various other cybersecurity threats. One approach to deal with these security issues proactively is through threat modeling. We can utilize some tools to gather the threat data targeting the smart grid, such as using honeypots, then analyze the collected threat data to obtain the threat model in order to study the attackers' behavior. In this paper, we collected threat data targeting the smart grid system by deploying GridPot honeypot and analyzed the collected threat data by mapping them to the MITRE ATT&CK for Industrial Control System (ICS) framework. This experiment shows that the threats targeting the smart grid systems are real, and could harm any smart grid system in the world.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信