Abstract
Desalination plants, heavily reliant on Industrial Control Systems (ICS), have emerged as increasingly vital resources in the wake of escalating global water scarcity. This raises an urgent need to prioritize their security, calling for the implementation of robust risk assessment measures. Recognizing these pressing issues, this paper proposes a risk assessment approach for ICS within water desalination facilities. The strategy integrates the capabilities of Bayesian Networks (BNs) and Dynamic Programming (DP). It evolves BNs into Multilevel Bayesian Networks (MBNs), an innovative form that adeptly navigates the intricacies of system complexity, facilitates efficient inference, and dynamically adapts risk profiles. The proposed methodology considers the perspective of potential attackers, which is critical for a comprehensive risk assessment and a robust defense strategy. The DP aspect enhances this approach by dissecting complex problems and identifying optimal attack paths. The work demonstrates the comprehensive risk assessment by executing multiple attacks on a water desalination plant with various strategies. It takes into account the probabilistic interdependence relationships within the system. Additionally, the paper formulates a mathematical risk assessment using system models and graphical representation, yielding realistic results.
Original language | English (US) |
---|---|
Title of host publication | CPSIoTSec 2023 - Proceedings of the 5th Workshop on CPS and IoT Security and Privacy |
Publisher | Association for Computing Machinery, Inc |
Pages | 11-23 |
Number of pages | 13 |
ISBN (Electronic) | 9798400702549 |
DOIs | |
State | Published - Nov 26 2023 |
Event | 5th Workshop on CPS and IoT Security and Privacy, CPSIoTSec 2023 - Copenhagen, Denmark Duration: Nov 26 2023 → … |
Publication series
Name | CPSIoTSec 2023 - Proceedings of the 5th Workshop on CPS and IoT Security and Privacy |
---|
Conference
Conference | 5th Workshop on CPS and IoT Security and Privacy, CPSIoTSec 2023 |
---|---|
Country/Territory | Denmark |
City | Copenhagen |
Period | 11/26/23 → … |
Bibliographical note
Publisher Copyright:© 2023 Owner/Author.
Keywords
- bayesian networks
- discrete graphical modeling.
- dynamic programming
- industrial control systems security
- risk assessment
- water desalination
ASJC Scopus subject areas
- Computer Networks and Communications