skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Concept for Cyber-Physical Consequence Process

Technical Report ·
DOI:https://doi.org/10.2172/1482997· OSTI ID:1482997

The Department of Homeland Security’s Office of Cyber and Infrastructure Analysis (DHS/OCIA) has a mission and vision that promotes innovation as central to expanding the organization’s capability to conduct consequence analysis. To pursue such innovation, OCIA is sponsoring a seedling effort with Idaho National Laboratory (INL) to leverage data from the proposed Automated Vulnerability Assessment (AVA) capability, which the DHS Science and Technology (S&T) Directorate is developing through a separate INL effort. The first phase of this effort is to develop a process by which recognized vulnerabilities can be scored relative to importance, reflected primarily in the ability to initiate high consequence and potentially cascading events. This report documents a cyber-physical metrics process (CPMP) to tie physical impact to the malicious exploitation of cyber vulnerabilities in industrial control systems (ICS) with the potential for initiating consequence in the critical infrastructure. The scale of achieving any particular physical consequence is dependent upon the ICS Component the vulnerability exists on, the Level of Access that the exploit would allow to component function and the Physical Impact (CLAPI) to the power system that the component is tied. A modified common vulnerability scoring system (CVSS) was detailed and demonstrated for the power sector with three case studies associated with a recognized vulnerability, with significant consequence detail provided to apply the process across the power sector. A detailed table that provides background on the power system components, ICS-enabled monitoring and control, potential consequence effects, and CVSS scoring is provided. To demonstrate the applicability of the CPMP, tables are provided as examples for other sectors that include chemical, water/wastewater and oil/gas.

Research Organization:
Idaho National Lab. (INL), Idaho Falls, ID (United States)
Sponsoring Organization:
USDOE Office of Nuclear Energy (NE)
DOE Contract Number:
AC07-05ID14517
OSTI ID:
1482997
Report Number(s):
INL/EXT-15-37287-Rev000
Country of Publication:
United States
Language:
English

Similar Records

Cyber Security Testing and Training Programs for Industrial Control Systems
Conference · Thu Mar 01 00:00:00 EST 2012 · OSTI ID:1482997

Cyber Security and Resilient Systems
Conference · Wed Jul 01 00:00:00 EDT 2009 · OSTI ID:1482997

Scenario-based approach to risk analysis in support of cyber security
Conference · Sat Jul 01 00:00:00 EDT 2006 · OSTI ID:1482997