<div class="csl-bib-body">
<div class="csl-entry">Bhosale, P., Kastner, W., & Sauter, T. (2024). Mapping ICS Vulnerabilities: Prioritization and Risk Propagation Analysis with MITRE ATT&CK Framework and Bayesian Belief Networks. In <i>2024 IEEE 29th International Conference on Emerging Technologies and Factory Automation (ETFA)</i>. 2024 IEEE 29th International Conference on Emerging Technologies and Factory Automation (ETFA), Padova, Italy. https://doi.org/10.1109/ETFA61755.2024.10710893</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/209902
-
dc.description.abstract
The introduction of Industry 4.0 and the integration of Information Technology (IT) with Operational Technology (OT) have brought significant advancements to Industrial Control Systems (ICS). With the convergence of IT/OT, ICS not only have to counteract against faults for safety reasons, but also have to encounter new challenges stemming from the security realm with an impact on safety issues. Ensuring the security of ICS has gained importance as any breach can cause disruption in industrial processes, leading to system downtime, production loss, and endangering human lives. Vulnerability assessment has become a crucial aspect of security research in ICS. The MITRE ATT&CK framework is one of the knowledge bases used for vulnerability management. It can be used to map identified vulnerabilities to a specific tactic provided by the framework. This mapping provides organizations with a structured approach focusing on identifying potential entry points for attackers and their progression through the system. The attacker's control of ICS could lead to a safety impact on people, processes, and the environment. This paper uses the mapping as a tool to prioritize the vulnerabilities and attacker's propagation through the network and thus help in building an effective risk propagation network using the Bayesian Belief Network (BBN). The implementation of the methodology is done using a Modular Production System (MPS) as a use case.
en
dc.description.sponsorship
TÜV Austria Holding AG
-
dc.language.iso
en
-
dc.subject
Bayesian Belief Network
en
dc.subject
Industrial Control Systems
en
dc.subject
MITRE ATT&CK framework
en
dc.title
Mapping ICS Vulnerabilities: Prioritization and Risk Propagation Analysis with MITRE ATT&CK Framework and Bayesian Belief Networks
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.relation.isbn
979-8-3503-6123-0
-
dc.relation.doi
10.1109/ETFA61755.2024
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
2024 IEEE 29th International Conference on Emerging Technologies and Factory Automation (ETFA)
-
tuw.peerreviewed
true
-
tuw.project.title
SafeSec System Architecture
-
tuw.researchTopic.id
I2
-
tuw.researchTopic.name
Computer Engineering and Software-Intensive Systems
-
tuw.researchTopic.value
100
-
tuw.publication.orgunit
E384-01 - Forschungsbereich Software-intensive Systems
-
tuw.publication.orgunit
E191-03 - Forschungsbereich Automation Systems
-
tuw.publication.orgunit
E056-16 - Fachbereich SafeSeclab
-
tuw.publisher.doi
10.1109/ETFA61755.2024.10710893
-
dc.description.numberOfPages
8
-
tuw.author.orcid
0000-0001-5760-2342
-
tuw.author.orcid
0000-0001-5420-404X
-
tuw.author.orcid
0000-0003-1559-8394
-
tuw.event.name
2024 IEEE 29th International Conference on Emerging Technologies and Factory Automation (ETFA)
en
tuw.event.startdate
10-09-2024
-
tuw.event.enddate
13-09-2024
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
Padova
-
tuw.event.country
IT
-
tuw.event.presenter
Bhosale, Pushparaj
-
wb.sciencebranch
Elektrotechnik, Elektronik, Informationstechnik
-
wb.sciencebranch.oefos
2020
-
wb.sciencebranch.value
100
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.cerifentitytype
Publications
-
item.languageiso639-1
en
-
item.fulltext
no Fulltext
-
item.openairetype
conference paper
-
item.grantfulltext
none
-
crisitem.author.dept
E191-03 - Forschungsbereich Automation Systems
-
crisitem.author.dept
E640 - Vizerektorat Digitalisierung und Infrastruktur
-
crisitem.author.dept
E384 - Institut für Computertechnik
-
crisitem.author.orcid
0000-0001-5760-2342
-
crisitem.author.orcid
0000-0001-5420-404X
-
crisitem.author.orcid
0000-0003-1559-8394
-
crisitem.author.parentorg
E191 - Institut für Computer Engineering
-
crisitem.author.parentorg
E000 - Technische Universität Wien
-
crisitem.author.parentorg
E350 - Fakultät für Elektrotechnik und Informationstechnik