Guide to developing case-based attack scenarios and establishing defense strategies for cybersecurity exercise in ICS environment

Citations

WEB OF SCIENCE

1
Citations

SCOPUS

2

초록

Critical infrastructure mainly performs its role through an industrial control system (ICS). Organizations conduct cyber exercises between red and blue teams, focusing on offense and defense. Practical exercises require explicit attack scenarios and corresponding defense strategies. However, systematic guides for deriving cyberattack scenarios or defense strategies still need to be improved. This paper proposes a guide for establishing realistic attack scenarios and defense strategies for cybersecurity exercises in ICS environments. Attack scenario generation is divided into four steps: generating attack references, deriving attack sequences, mapping threat information, and mapping vulnerable implementation patterns. Deriving a defensive strategy consists of two steps parallel to developing an attack scenario: deriving containment and eradication. The methodology we propose guides exercise planning based on a knowledge base, thereby assisting exercise planners in generating various scenarios and deriving clear defense strategies. We showed that a clear exercise plan could be established through a case study.

키워드

Cyber exerciseAttack scenarioDefense strategyMITRE ATT& CKMITRE D3FENDSTUXNET
제목
Guide to developing case-based attack scenarios and establishing defense strategies for cybersecurity exercise in ICS environment
저자
Kim, DonghyunJeon, SeunghoKim, KwangsooKang, JaesikLee, SeungwoonSeo, Jung Taek
DOI
10.1007/s11227-024-06273-9
발행일
2024-10
유형
Article
저널명
Journal of Supercomputing
80
15
페이지
21642 ~ 21675