Engineering Management Methodology for Assessing and Improving the Cyber Resilience of Critical Infrastructures
Open AccessThe praxis investigates the concept of building cyber resilience into the system architecture of critical infrastructures through the lens of an Engineering Management tool developed for this research. The research demonstrates that embedding well-engineered decoys, which mimic real system components, into the Informational Technology (IT) and Operational Technology (OT) systems architecture of an industrial system builds cyber resilience into the architecture thus reducing the probability of successful attacks, the impact on real system components and increasing the Mean Time to Breach. This is illustrated through the Python model of an infrastructure based on the Purdue System architecture subjected to simulated Advanced Persistent Threat-style attacks. The research demonstrates that the mean-time-to a successful breach and control over the command-and-control signals of a SCADA system is proportionate to the number and complexity of decoy components in an IT/OT environment. Also demonstrated is that the more deception built into the IT system architecture the less the impact of an attack on OT and real system components. The research tool can be used to assess the cyber resilience of an infrastructure through the use of probabilities determined through quantitative risk assessments.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.