...
首页> 外文期刊>Information Security Technical Report >A collaborative cyber incident management system for European interconnected critical infrastructures
【24h】

A collaborative cyber incident management system for European interconnected critical infrastructures

机译:用于欧洲互连的关键基础设施的协作式网络事件管理系统

获取原文
获取原文并翻译 | 示例
           

摘要

Today's Industrial Control Systems (ICSs) operating in critical infrastructures (CIs) are becoming increasingly complex; moreover, they are extensively interconnected with corporate information systems for cost-efficient monitoring, management and maintenance. This exposes ICSs to modern advanced cyber threats. Existing security solutions try to prevent, detect, and react to cyber threats by employing security measures that typically do not cross the organization's boundaries. However, novel targeted multi-stage attacks such as Advanced Persistent Threats (APTs) take advantage of the interdependency between organizations. By exploiting vulnerabilities of various systems, APT campaigns intrude several organizations using them as stepping stones to reach the target infrastructure. A coordinated effort to timely reveal such attacks, and promptly deploy mitigation measures is therefore required. Organizations need to cooperatively exchange security-relevant information to obtain a broader knowledge on the current cyber threat landscape and subsequently obtain new insight into their infrastructures and timely react if necessary. Cyber security operation centers (SOCs), as proposed by the European NIS directive, are being established worldwide to achieve this goal. CI providers are asked to report to the responsible SOCs about security issues revealed in their networks. National SOCs correlate all the gathered data, analyze it and eventually provide support and mitigation strategies to the affiliated organizations. Although many of these tasks can be automated, human involvement is still necessary to enable SOCs to adequately take decisions on occurring incidents and quickly implement counteractions. In this paper we present a collaborative approach to cyber incident information management for gaining situational awareness on interconnected European CIs. We provide a scenario and an illustrative use-case for our approach; we propose a system architecture for a National SOC, defining the functional components and interfaces it comprises. We further describe the functionalities provided by the different system components to support SOC operators in performing incident management tasks.
机译:在关键基础架构(CI)中运行的当今工业控制系统(ICS)变得越来越复杂。此外,它们与公司信息系统广泛互连,以实现经济高效的监视,管理和维护。这使ICS暴露于现代高级网络威胁中。现有的安全解决方案通过采用通常不会跨越组织边界的安全措施来尝试预防,检测和应对网络威胁。但是,新颖的针对性多阶段攻击(如高级持久性威胁(APT))利用了组织之间的相互依赖关系。通过利用各种系统的漏洞,APT活动侵入了多个组织,并以此作为踏入目标基础设施的垫脚石。因此,需要采取协调一致的措施及时发现此类攻击,并迅速部署缓解措施。组织需要合作交换与安全性有关的信息,以获取有关当前网络威胁状况的更广泛知识,并随后获得对其基础结构的新见解,并在必要时及时做出反应。欧洲NIS指令提议的网络安全运营中心(SOC)正在全球范围内建立,以实现这一目标。 CI提供者被要求向负责的SOC报告其网络中发现的安全问题。国家SOC将所有收集的数据关联起来,对其进行分析,并最终为附属组织提供支持和缓解策略。尽管许多任务可以自动化,但是仍然需要人工参与,以使SOC能够对发生的事件做出充分的决策并快速实施对策。在本文中,我们提出了一种网络事件信息管理的协作方法,旨在获得有关互连的欧洲CI的态势感知。我们为我们的方法提供了一个场景和一个说明性用例;我们为国家SOC提出了一种系统架构,定义了其组成的功能组件和接口。我们进一步描述了由不同系统组件提供的功能,以支持SOC操作员执行事件管理任务。

著录项

  • 来源
    《Information Security Technical Report》 |2017年第2期|166-182|共17页
  • 作者单位

    Digital Safety and Security Department, AIT — Austrian Institute of Technology, Donau-City-Straße 1, Vienna, Austria;

    Digital Safety and Security Department, AIT — Austrian Institute of Technology, Donau-City-Straße 1, Vienna, Austria;

    Digital Safety and Security Department, AIT — Austrian Institute of Technology, Donau-City-Straße 1, Vienna, Austria;

    Digital Safety and Security Department, AIT — Austrian Institute of Technology, Donau-City-Straße 1, Vienna, Austria;

    Corrig Court, Espion Limited, Corrig Road, Sandyford Industrial Estate, Dublin, Ireland;

    Corrig Court, Espion Limited, Corrig Road, Sandyford Industrial Estate, Dublin, Ireland;

    Fraunhofer AISEC, Parkring 4, Garching bei Muenchen, Germany;

    Fraunhofer AISEC, Parkring 4, Garching bei Muenchen, Germany;

    Fraunhofer AISEC, Parkring 4, Garching bei Muenchen, Germany;

    Airbus Defense and Space, Willy-Messerschmitt-Straße 1, Ottobrunn, Germany;

    Airbus Defense and Space, Willy-Messerschmitt-Straße 1, Ottobrunn, Germany;

    Airbus Defense and Space, Willy-Messerschmitt-Straße 1, Ottobrunn, Germany;

    IFAK — Institut fuer Automation und Kommunikation e.V. Magdeburg, Werner-Heisenberg-Str. 1, Magdeburg, Germany;

    Teknologian Tutkimuskeskus — VTT, Kaitovaeylae 1, Oulu, Finland;

  • 收录信息 美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Cyber incident handling; Cyber incident reporting; Cyber security; Information sharing; Security operation center;

    机译:网络事件处理;网络事件报告;网络安全;信息共享;保安运营中心;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号