skip to main content
10.1145/3422337.3450320acmconferencesArticle/Chapter ViewAbstractPublication PagescodaspyConference Proceedingsconference-collections
poster

IIoT-ARAS: IIoT/ICS Automated Risk Assessment System for Prediction and Prevention

Published:26 April 2021Publication History

ABSTRACT

As IT/OT convergence continues to evolve, the traditionally isolated ICS/OT systems are increasingly exposed to a myriad of online and offline threats. Although IIoT enhances the reachability in ICS, improved data analytics, ensuring ease of access and decision making, it unwittingly opens the ICS environment to attackers. The design of IIoT introduces multiple entry points to an isolated system, which is used to protect itself via air-gapping and risk avoidance strategies. This study explores a comprehensive mapping of threats and risks for IT/OT convergence. Additionally, we propose IIoT-ARAS - an automated risk assessment system based on OCTAVE Allegro and ISO/IEC 27030 methodologies. The design of IIoT-ARAS is aimed to be agentless, with minimum interruptions to the OT environment. Furthermore, the system performs automated regular asset inventory checks, threshold optimization, probability computation, risk evaluations, and contingency plan configuration.

Skip Supplemental Material Section

Supplemental Material

CODASPY21-codas04p.mp4

mp4

6.5 MB

References

  1. Caralli, Richard A., et al. Introducing octave allegro: Improving the information security risk assessment process. No. Carnegie Mellon University/SEI-2007-TR-012. Carnegie-Mellon Univ Pittsburgh PA Software Engineering Inst, 2007.Google ScholarGoogle ScholarCross RefCross Ref
  2. "Guidelines for Security and Privacy in Internet of Things" ISO/IEC 27030, https://www.iso27001security.com/html/27030.htmlGoogle ScholarGoogle Scholar
  3. Zahran, Bassam, Stacy Nicholson, and Aisha Ali-gombe. "Cross-Platform Malware: Study of the Forthcoming Hazard Adaptation and Behavior." Proceedings of the International Conference on Security and Management (SAM). The Steering Committee of The World Congress in Computer Science, Computer Engineering and Applied Computing (WorldComp), 2019.Google ScholarGoogle Scholar
  4. Conto, Ruggero, and Lawrence Orans. OT Security Best Practices, 14 Sept. 2018, www.gartner.com/doc/reprints?id=1--242JE25AGoogle ScholarGoogle Scholar

Index Terms

  1. IIoT-ARAS: IIoT/ICS Automated Risk Assessment System for Prediction and Prevention

                      Recommendations

                      Comments

                      Login options

                      Check if you have access through your login credentials or your institution to get full access on this article.

                      Sign in
                      • Published in

                        cover image ACM Conferences
                        CODASPY '21: Proceedings of the Eleventh ACM Conference on Data and Application Security and Privacy
                        April 2021
                        348 pages
                        ISBN:9781450381437
                        DOI:10.1145/3422337

                        Copyright © 2021 Owner/Author

                        Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

                        Publisher

                        Association for Computing Machinery

                        New York, NY, United States

                        Publication History

                        • Published: 26 April 2021

                        Check for updates

                        Qualifiers

                        • poster

                        Acceptance Rates

                        Overall Acceptance Rate149of789submissions,19%

                        Upcoming Conference

                        CODASPY '24
                      • Article Metrics

                        • Downloads (Last 12 months)65
                        • Downloads (Last 6 weeks)11

                        Other Metrics

                      PDF Format

                      View or Download as a PDF file.

                      PDF

                      eReader

                      View online with eReader.

                      eReader