{"title":"AMI中自动响应和恢复响应动作的成本建模","authors":"Ahmed M. Fawaz, R. Berthier, W. Sanders","doi":"10.1109/SmartGridComm.2012.6486008","DOIUrl":null,"url":null,"abstract":"The smart grid is creating new security vulnerabilities due to the deployment of networked devices into the traditional grid. A core component of the smart grid is the advanced metering infrastructures (AMIs), which increase the attack surface due to smart devices deployed at households. Manual management of security incidents in such a large and complex system is impractical, and the need for automated response and recovery to attacks is critical. This paper addresses that challenge through two main contributions. First, we introduce and classify an extended set of AMI-specific cyber incident response actions. Second, we define a cost model and an approach to translate security properties into monetary costs. The cost model is a key element in enabling an automated response engine to make optimal decisions and mitigate cyber incidents.","PeriodicalId":143915,"journal":{"name":"2012 IEEE Third International Conference on Smart Grid Communications (SmartGridComm)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2012-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":"{\"title\":\"Cost modeling of response actions for automated response and recovery in AMI\",\"authors\":\"Ahmed M. Fawaz, R. Berthier, W. Sanders\",\"doi\":\"10.1109/SmartGridComm.2012.6486008\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The smart grid is creating new security vulnerabilities due to the deployment of networked devices into the traditional grid. A core component of the smart grid is the advanced metering infrastructures (AMIs), which increase the attack surface due to smart devices deployed at households. Manual management of security incidents in such a large and complex system is impractical, and the need for automated response and recovery to attacks is critical. This paper addresses that challenge through two main contributions. First, we introduce and classify an extended set of AMI-specific cyber incident response actions. Second, we define a cost model and an approach to translate security properties into monetary costs. The cost model is a key element in enabling an automated response engine to make optimal decisions and mitigate cyber incidents.\",\"PeriodicalId\":143915,\"journal\":{\"name\":\"2012 IEEE Third International Conference on Smart Grid Communications (SmartGridComm)\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2012-11-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"8\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2012 IEEE Third International Conference on Smart Grid Communications (SmartGridComm)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SmartGridComm.2012.6486008\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 IEEE Third International Conference on Smart Grid Communications (SmartGridComm)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SmartGridComm.2012.6486008","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Cost modeling of response actions for automated response and recovery in AMI
The smart grid is creating new security vulnerabilities due to the deployment of networked devices into the traditional grid. A core component of the smart grid is the advanced metering infrastructures (AMIs), which increase the attack surface due to smart devices deployed at households. Manual management of security incidents in such a large and complex system is impractical, and the need for automated response and recovery to attacks is critical. This paper addresses that challenge through two main contributions. First, we introduce and classify an extended set of AMI-specific cyber incident response actions. Second, we define a cost model and an approach to translate security properties into monetary costs. The cost model is a key element in enabling an automated response engine to make optimal decisions and mitigate cyber incidents.