Abstract
Critical National Infrastructures (CNIs) face unique challenges in cybersecurity, as they must remain operational even during attacks, making traditional Anomaly Detection approaches and Intrusion Detection Systems (IDSs) insufficient. This paper introduces a novel approach that links Indicators of Compromise (IoCs) to the safety and resilient states of CNIs using Incident Fault Trees (IFTs). IFTs model disruptive events and the conditions necessary for their occurrence, allowing us to assess potential attack paths and formulate mitigating actions without affecting CNI operations. By leveraging real-time network traffic modelling and a well-established framework for attacks, our method enhances detection and response capabilities while ensuring operational resilience. We discuss the feasibility of automating this approach and outline future work focused on applying it to physical systems in our laboratory to validate its effectiveness in maintaining continuous CNI operations under cyber threats.
Original language | English |
---|---|
Title of host publication | CPSIoTSec'24 |
Subtitle of host publication | Proceedings of the Sixth Workshop on CPS&IoT Security and Privacy |
Publisher | Association for Computing Machinery (ACM) |
Pages | 104-110 |
Number of pages | 7 |
ISBN (Print) | 9798400712449 |
DOIs | |
Publication status | Published - 22 Nov 2024 |
Event | CCS '24: ACM SIGSAC Conference on Computer and Communications Security - Salt Lake City, United States Duration: 14 Oct 2024 → 18 Oct 2024 https://www.sigsac.org/ccs/CCS2024/ |
Publication series
Name | Proceedings of the ACM Conference on Computer and Communications Security |
---|---|
ISSN (Print) | 1543-7221 |
Conference
Conference | CCS '24: ACM SIGSAC Conference on Computer and Communications Security |
---|---|
Abbreviated title | CCS '24 |
Country/Territory | United States |
City | Salt Lake City |
Period | 14/10/24 → 18/10/24 |
Internet address |
Bibliographical note
Publisher Copyright:© 2024 Owner/Author.