Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Extended dependency modelling technique for cyber risk identification in ICS

Rotibi, Ayodeji, Saxena, Neetesh ORCID: https://orcid.org/0000-0002-6437-0807, Burnap, Peter ORCID: https://orcid.org/0000-0003-0396-633X and Tartar, Alex 2023. Extended dependency modelling technique for cyber risk identification in ICS. IEEE Access 11 , pp. 37229-37242. 10.1109/ACCESS.2023.3263671

[thumbnail of Extended_Dependency_Modelling_Technique_for_Cyber_Risk_Identification_in_ICS.pdf]
Preview
PDF - Published Version
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (4MB) | Preview

Abstract

Complex systems such as Industrial Control Systems (ICS) are designed as a collection of functionally dependent and highly connected units with multiple stakeholders. Identifying the risk of such complex systems requires an overall view of the entire system. Dependency modelling (DM) is a highly participative methodology that identifies the goals and objectives of a system and the required dependants to satisfy these goals. Researchers have proved DM to be suitable for identifying and quantifying impact and uncertainty in complex environments. However, there exist limitations in the current expressions of DM that hinder its complete adaptation for risk identification in a complex environment such as ICS. This research investigates how the capability of DM could be extended to address the identified limitations and proposes additional variables to address phenomena that are unique to ICS environments. The proposed extension is built into a system-driven ICS dependency modeller, and we present an illustrative example using a scenario of a generic ICS environment. We reflect that the proposed technique supports an improvement in the initial user data input in the identification of areas of risk at the enterprise, business process, and technology levels.

Item Type: Article
Date Type: Publication
Status: Published
Schools: Computer Science & Informatics
Publisher: Institute of Electrical and Electronics Engineers
ISSN: 2169-3536
Date of First Compliant Deposit: 5 April 2023
Date of Acceptance: 18 March 2023
Last Modified: 13 Jun 2023 18:17
URI: https://orca.cardiff.ac.uk/id/eprint/158292

Citation Data

Cited 3 times in Scopus. View in Scopus. Powered By Scopus® Data

Actions (repository staff only)

Edit Item Edit Item

Downloads

Downloads per month over past year

View more statistics