SECUREGRID
Open Access DepositedContext-Aware Vulnerability Prioritization for Critical Infrastructure
Downloadable Content
SECUREGRID Score = EPSS_Score^1.6 × 32 × ICS Multiplier, where ICS Multiplier = 1 + ((Access Control Level + System Complexity + Cascade Effect Score) ÷ 15). This system adjusts prioritization based on risk levels, focusing on the context of low-risk vulnerabilities while boosting alerts for high-risk threats. Cross-validation demonstrated SECUREGRID's reliability and stability across different datasets, with sensitivity analysis revealing minimal variation (maximum deviation of ±1.85 %). The methodology addresses a key issue
organizations can only manage under 10% of vulnerabilities each month, meaning precise prioritization is essential to ensure maintenance resources target the most exploitable risks. This research not only advances the understanding of vulnerability exploitation but also offers practical solutions for critical infrastructure that often works under resource constraints. The findings challenge the traditional severity-based approach to vulnerability management and highlight the need for context-aware methods that factor in operational security through adaptive mechanisms. SECUREGRID marks a significant step forward in protecting essential systems from evolving threats, especially from nation-state actors targeting critical infrastructure. By making it easier to direct security resources toward vulnerabilities with real exploitation risks, SECUREGRID strengthens the cybersecurity of critical infrastructure while taking operational constraints into account. This research lays the groundwork for future advancements in vulnerability prioritization, supporting the long-term security and reliability of critical infrastructure that underpins modern society.
The growing use of Industrial Internet of Things (IIoT) devices in Supervisory Control and Data Acquisition (SCADA) systems has significantly increased the vulnerability of critical infrastructure, exacerbating cybersecurity challenges to an unprecedented level. Traditional methods for prioritizing vulnerabilities, such as the Common Vulnerability Scoring System (CVSS), haven’t been effective in addressing the specific challenges and risks associated with industrial control systems (ICS). This research aims to close the gap between current vulnerability assessment methods and the real-world conditions of SCADA environments by developing SECUREGRID (SCADA Exploitability and Contextualized Urgency-Driven Risk Evaluation for Grid Infrastructure Defense), a new, context-aware method for prioritizing vulnerabilities.A detailed statistical analysis of 1,000 SCADA-related vulnerabilities was created and validated against trusted sources like MITRE, CISA, and industry reports. The research examined 35 factors across eight categories, including technical severity, operational limits, supply chain risks, and patterns of threats from nation-state actors that are specific to ICS. The results showed that CVSS had almost no connection to real-world exploit outcomes in SCADA environments (r = 0.035, p = 0.274). In contrast, the Exploit Prediction Scoring System (EPSS) showed a clear improvement (r = 0.266, p < 0.001), and SECUREGRID outperformed with a correlation of 0.270 (p < 0.001). This represented a 1.5% improvement over EPSS, accompanied by a 54.9% increase in precision and a 51.6% decrease in false positives. SECUREGRID also had an Area Under the Curve (AUC) score of 0.796, surpassing EPSS (0.791) and significantly outperforming CVSS (0.538). The SECUREGRID formula uses adaptive logic through the structure
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.