Concept for Cyber-Physical Consequence Process
- Idaho National Laboratory (INL), Idaho Falls, ID (United States)
The Department of Homeland Security’s Office of Cyber and Infrastructure Analysis (DHS/OCIA) has a mission and vision that promotes innovation as central to expanding the organization’s capability to conduct consequence analysis. To pursue such innovation, OCIA is sponsoring a seedling effort with Idaho National Laboratory (INL) to leverage data from the proposed Automated Vulnerability Assessment (AVA) capability, which the DHS Science and Technology (S&T) Directorate is developing through a separate INL effort. The first phase of this effort is to develop a process by which recognized vulnerabilities can be scored relative to importance, reflected primarily in the ability to initiate high consequence and potentially cascading events. This report documents a cyber-physical metrics process (CPMP) to tie physical impact to the malicious exploitation of cyber vulnerabilities in industrial control systems (ICS) with the potential for initiating consequence in the critical infrastructure. The scale of achieving any particular physical consequence is dependent upon the ICS Component the vulnerability exists on, the Level of Access that the exploit would allow to component function and the Physical Impact (CLAPI) to the power system that the component is tied. A modified common vulnerability scoring system (CVSS) was detailed and demonstrated for the power sector with three case studies associated with a recognized vulnerability, with significant consequence detail provided to apply the process across the power sector. A detailed table that provides background on the power system components, ICS-enabled monitoring and control, potential consequence effects, and CVSS scoring is provided. To demonstrate the applicability of the CPMP, tables are provided as examples for other sectors that include chemical, water/wastewater and oil/gas.
- Research Organization:
- Idaho National Lab. (INL), Idaho Falls, ID (United States)
- Sponsoring Organization:
- USDOE Office of Nuclear Energy (NE)
- DOE Contract Number:
- AC07-05ID14517
- OSTI ID:
- 1482997
- Report Number(s):
- INL/EXT-15-37287-Rev000
- Country of Publication:
- United States
- Language:
- English
Similar Records
Cyber Security and Resilient Systems
Scenario-based approach to risk analysis in support of cyber security