The Experts below are selected from a list of 15 Experts worldwide ranked by ideXlab platform
Zhen Zhang - One of the best experts on this subject based on the ideXlab platform.
-
ENVIRONMENTAL REVIEW & CASE STUDY: NERC's Cybersecurity Standards for the Electric Grid: Fulfilling Its Reliability Day Job and Moonlighting as a Cybersecurity Model
Environmental Practice, 2011Co-Authors: Zhen ZhangAbstract:The electric industry is experiencing notable changes with the implementation of communication and automation technology, many of which are part of the smart grid movement. Similar to other Critical infrastructure industries such as banking, transportation, and the cross-sector Critical information infrastructure industry, the electric industry must protect itself from intentional and unintentional security breaches and incidents to ensure uninterrupted operations of essential services. Of the Critical infrastructure industries, the electric industry is the only private-sector industry subject to government-enforced mandatory Cybersecurity standards. This article presents an overview of the eight mandatory Cybersecurity standards by the North American Electric Reliability Corporation. As an example of how standards are evolving, it discusses CIP-002 (Critical Cyber Asset Identification) in depth because it establishes whether the remaining seven standards apply. This article then compares the North Americ...
-
NERC's Cyber Security Standards: Fulfilling Its Reliability Day Job and Moonlighting as a Cyber Security Model
2010Co-Authors: Zhen ZhangAbstract:The electric industry is experiencing notable changes with the implementation of communication and automation technology, many of which are part of the smart grid movement. Similar to other Critical infrastructure industries such as banking, transportation and the cross sector Critical information infrastructure industry, the electric industry must protect itself from intentional and unintentional security breaches and incidents to ensure uninterrupted operations of essential services. Of the Critical infrastructure industries, the electric industry is the only private-sector industry subject to government enforced mandatory Cyber security standards. This article gives an overview of the eight mandatory Cyber security standards by the North American Electric Reliability Corporation. As an example of how standards are evolving it discusses CIP-002 – Critical Cyber Asset Identification in depth because it establishes whether the remaining seven standards apply. This article then compares the North American Electric Reliability Corporation regulatory regime against Critical information infrastructure goals. The comparison finds that, at least on a basic level, the electric industry’s mandatory Cyber security standards meet the Critical information infrastructure goals and work to secure information networks, resources, and systems from Cyber and physical threats. The mandatory Cyber security standards promote an increase in technological products, better security management, personnel and public education and trust in the industry. Even though the electric industry’s mandatory standards are imperfect, the fact it satisfies the goals of the cross sector Critical information infrastructure indicates that the framework is sound. The electric industry’s experience with mandatory Cyber security standards is a valuable source of information and the regulatory regime itself can be a helpful model for other industries looking to develop their own security protection systems.
Piroska Haller - One of the best experts on this subject based on the ideXlab platform.
-
Behavior-based Critical Cyber Asset identification in Process Control Systems under Cyber Attacks
Proceedings of the 2015 16th International Carpathian Control Conference (ICCC), 2015Co-Authors: István Kiss, Béla Genge, Piroska HallerAbstract:The accelerated advancement of Process Control Systems (PCS) transformed the traditional and completely isolated systems view into a networked inter-connected “system of systems” perspective, where off-the-shelf Information and Communication Technologies (ICT) are deeply embedded into the heart of PCS. This has brought significant economical and operational benefits, but it also provided new opportunities for malicious actors targeting Critical PCS. To address these challenges, in this work we employ our previously developed Cyber Attack Impact Assessment (CAIA) technique to provide a systematic mechanism to help PCS designers and industry operators to assess the impact severity of various Cyber threats. Moreover, the question of why a device is more Critical than others, and also the motivation of this work, are answered through extensive numerical results showing the significance of systems dynamics in the context of closed-loop PCS. The CAIA approach is validated against the simulated Tennessee Eastman chemical process, including 41 observed variables and 12 control variables, involved in cascade controller structures. The results show the application possibilities and effectiveness of CAIA for various attack scenarios.
István Kiss - One of the best experts on this subject based on the ideXlab platform.
-
Behavior-based Critical Cyber Asset identification in Process Control Systems under Cyber Attacks
Proceedings of the 2015 16th International Carpathian Control Conference (ICCC), 2015Co-Authors: István Kiss, Béla Genge, Piroska HallerAbstract:The accelerated advancement of Process Control Systems (PCS) transformed the traditional and completely isolated systems view into a networked inter-connected “system of systems” perspective, where off-the-shelf Information and Communication Technologies (ICT) are deeply embedded into the heart of PCS. This has brought significant economical and operational benefits, but it also provided new opportunities for malicious actors targeting Critical PCS. To address these challenges, in this work we employ our previously developed Cyber Attack Impact Assessment (CAIA) technique to provide a systematic mechanism to help PCS designers and industry operators to assess the impact severity of various Cyber threats. Moreover, the question of why a device is more Critical than others, and also the motivation of this work, are answered through extensive numerical results showing the significance of systems dynamics in the context of closed-loop PCS. The CAIA approach is validated against the simulated Tennessee Eastman chemical process, including 41 observed variables and 12 control variables, involved in cascade controller structures. The results show the application possibilities and effectiveness of CAIA for various attack scenarios.
Pirogov Gleb - One of the best experts on this subject based on the ideXlab platform.
-
Analysis and evaluation of regulatory documents used for information security Smart Grid system
Київ, 2013Co-Authors: Юдин Алексей, Пирогов Глеб, Юдін Олексій, Пирогов Гліб, Yudin Oleksii, Pirogov GlebAbstract:В статті розглядається Smart Grid система як сукупність підсистеми передавання електричної енергії та інформаційно-телекомунікаційної підсистеми, і відповідно до цього здійснюється аналіз діючих нормативних документів. Об’єктом аналізу є нормативні документи, що відносяться до забезпечення інформаційної безпеки систем управління, систем диспетчерського керування та збору даних (SCADA), автоматизованих систем управління технологічним процесом (АСУ ТП) і Smart Grid, а саме: Міжнародні стандарти 1. IEEE 1402. IEEE Guide for Electric Power Substation Physical and Electronic Security, -IEEE 1686. IEEE Standard for Substation Intelligent Electronic Devices (IED) Cyber Security Capabilities, IEEE P1711. Trial Use Standard for a Cryptographic Protocol for Cyber Security of Substation Serial Links. 2. ISO 27019. Information security management guidelines for process control systems used in the energy utility industry on the basis of ISO/IEC 27002. 3. IEC TR 62210. Power system control and associated communications. Data and communication security, IEC 61784-4. Digital data communications for measurement and control – Profiles for secure communications in industrial networks, IEC 62443. Security for industrial process measurement and control – Network and system security, IEC 62351. Data and Communication Security, IEC/TR 62357. Power system control and associated communications – Reference architecture for object models, services and protocols. Національні галузеві стандарти 4. NIST SP800-82. Guide to Industrial Control Systems (ICS) Security, NIST SP800-53. Security and Privacy Controls for Federal Information Systems and Organizations, NISTIR 7628. Guidelines for Smart Grid Cyber Security. 5. ISA 99.00.01. Security for Industrial Automation and Control Systems: Concepts, Models and Terminology. 6. AGA 12-3 Protection of Networked Systems, AGA 12-4 Protection Embedded in SCADA Components. 7. NERC CIP-002. Cyber Security - Critical Cyber Asset Identification, NERC CIP-003. Cyber Security – Security Management Controls, NERC CIP-007. Cyber Security – Systems Security Management, NERC CIP-011. Cyber Security – Information Protection. В ході аналізу та оцінки нормативних документів були зроблені наступні висновки: 1. Стандарти, які розроблені Інститутом інженерів з електротехніки та електроніки, стосуються електричних підстанцій та різних інтелектуальних пристроїв. Ці документи не описують питання забезпечення безпеки в усіх доменах Smart Grid. 2. Документи Міжнародної організації зі стандартизації, на сьогодні, знаходяться на стадії розробки. Стандарт ISO 27019, виходячи зі змісту проекту документу, буде містити відомості про базові механізми захисту електричних підстанцій та інтелектуальних пристроїв. Тобто, стандарти цієї серії зможуть охопити чотири з семі доменів – генеруючи, передаючі, розподіляючі організації та споживачі. 3. Стандарти розроблені Міжнародною електротехнічною комісією, а саме – IEC 61784, 62443, 62351 и TR 62210, також орієнтовані на забезпечення інформаційної безпеки систем виробництва та керування виробництвом. Ця серія стандартів доволі детально та повно описує захист трьох доменів – генеруючих, передаючих та розподіляючих організацій. 4. Серія стандартів NERC CIP, в основному, орієнтована на забезпечення кібербезпеки в SCADA. Ці документи носять декларативний характер і на враховують специфіку забезпечення інформаційної безпеки в Smart Grid. 5. Стандарти Національного інституту стандартизації і технологій описують питання безпеки в промислових системах. В той же час, технічний звіт NISTIR 7628 вводить поняття кібербезпеки в Smart Grid системах. Цей документ є першим, орієнтованим виключно на Smart Grid. Він найповніше дає опис множини об’єктів та суб’єктів Smart Grid, їх взаємодії і механізмів захисту. Таким чином можна припустити, що для розуміння процесу забезпечення інформаційної безпеки Smart Grid систем найповніше підходить технічний звіт NISTIR 7628. Це пов’язано з тим, що саме цей документ описує відмінності в підходах до забезпечення інформаційної безпеки SCADA, АСУ ТП та Smart Grid.In the article the Smart Grid system is considered as a set of subsystems transmission of electrical energy, and information and telecommunication sub-system, and in accordance with this analysis is relevant regulations. The object of the analysis are the regulations pertaining to information security control systems, supervisory control and data acquisition (SCADA), automated process control systems (PCS) and the Smart Grid: International Standards 1. IEEE 1402. IEEE Guide for Electric Power Substation Physical and Electronic Security, -IEEE 1686. IEEE Standard for Substation Intelligent Electronic Devices (IED) Cyber Security Capabilities, IEEE P1711. Trial Use Standard for a Cryptographic Protocol for Cyber Security of Substation Serial Links. 2. ISO 27019. Information security management guidelines for process control systems used in the energy utility industry on the basis of ISO/IEC 27002. 3. IEC TR 62210. Power system control and associated communications. Data and communication security, IEC 61784-4. Digital data communications for measurement and control – Profiles for secure communications in industrial networks, IEC 62443. Security for industrial process measurement and control – Network and system security, IEC 62351. Data and Communication Security, IEC/TR 62357. Power system control and associated communications – Reference architecture for object models, services and protocols. National industry standards 4. NIST SP800-82. Guide to Industrial Control Systems (ICS) Security, NIST SP800-53. Security and Privacy Controls for Federal Information Systems and Organizations, NISTIR 7628. Guidelines for Smart Grid Cyber Security. 5. ISA 99.00.01. Security for Industrial Automation and Control Systems: Concepts, Models and Terminology. 6. AGA 12-3 Protection of Networked Systems, AGA 12-4 Protection Embedded in SCADA Components. 7. NERC CIP-002. Cyber Security – Critical Cyber Asset Identification, NERC CIP-003. Cyber Security – Security Management Controls, NERC CIP-007. Cyber Security – Systems Security Management, NERC CIP-011. Cyber Security – Information Protection. The analysis and evaluation of regulations has made the following conclusions: The standards developed by the Institute of Electrical and Electronics Engineers, concerning electrical substations and various intelligent devices. These documents do not describe the security issues in all domains of Smart Grid. 1. Documents of the International Organization for Standardization for today are still under development. Standard ISO 27019, judging from the content of the draft document will contain information about the basic mechanisms for the protection of electrical substations and smart devices. That is, the standards of this series will cover four of the seven domains - generating, transmitting, distributing the organization and the consumer. The standards developed by the International Electrotechnical Commission, namely IEC 61784, 62443, 62351 and TR 62210, also focused on the provision of information security systems of production and management. This series is quite detailed and complete protection describes three domains – generation, transmission and distribution organizations. 2. A series of standards NERC CIP, primarily focused on Cyber security in SCADA. These documents are of a declarative nature and also do not take into account the specificity of information security in the Smart Grid. 3. Standards of the National Institute of Standards and Technology describe Cyber security in industrial systems. At the same time, Technical Report NISTIR 7628 introduces the concept of Cyber security in the Smart Grid systems. This paper is the first to specifically target Smart Grid and provides the most complete description of a set of objects and subjects of the Smart Grid, their interactions and mechanisms of protection. Thus, it can be assumed that an understanding of the process of information security Smart Grid systems more fully suited Technical Report NISTIR 7628, since this document describes the differences in the approaches to information security SCADA, DCS and Smart Grid.Рассматривается Smart Grid система как совокупность подсистемы передачи электрической энергии и информационно-телекоммуникационной подсистемы и в соответствии с этим осуществляется анализ действующих нормативных документов. Объектом анализа являются нормативные документы, относящиеся к обеспечению информационной безопасности систем управления, систем диспетчерского управления и сбора данных (SCADA), автоматизированных систем управления технологическим процессом (АСУ ТП) и Smart Grid, а именно: Международные стандарты 1. IEEE 1402. IEEE Guide for Electric Power Substation Physical and Electronic Security, -IEEE 1686. IEEE Standard for Substation Intelligent Electronic Devices (IED) Cyber Security Capabilities, IEEE P1711. Trial Use Standard for a Cryptographic Protocol for Cyber Security of Substation Serial Links. 2. ISO 27019. Information security management guidelines for process control systems used in the energy utility industry on the basis of ISO/IEC 27002. 3. IEC TR 62210. Power system control and associated communications. Data and communication security, IEC 61784-4. Digital data communications for measurement and control – Profiles for secure communications in industrial networks, IEC 62443. Security for industrial process measurement and control – Network and system security, IEC 62351. Data and Communication Security, IEC/TR 62357. Power system control and associated communications – Reference architecture for object models, services and protocols. Национальные отраслевые стандарты 4. NIST SP800-82. Guide to Industrial Control Systems (ICS) Security, NIST SP800-53. Security and Privacy Controls for Federal Information Systems and Organizations, NISTIR 7628. Guidelines for Smart Grid Cyber Security. 5. ISA 99.00.01. Security for Industrial Automation and Control Systems: Concepts, Models and Terminology. 6. AGA 12-3 Protection of Networked Systems, AGA 12-4 Protection Embedded in SCADA Components. 7. NERC CIP-002. Cyber Security - Critical Cyber Asset Identification, NERC CIP-003. Cyber Security – Security Management Controls, NERC CIP-007. Cyber Security – Systems Security Management, NERC CIP-011. Cyber Security – Information Protection. В ходе анализа и оценки нормативных документов были сделаны следующие выводы. 1. Стандарты, разработанные Институтом инженеров по электротехнике и электронике, касаются электрических подстанций и различных интеллектуальных устройств. Данные документы не описывают вопросы обеспечения безопасности во всех доменах Smart Grid. 2. Документы Международной организации по стандартизации на сегодня находятся на стадии разработки. Стандарт ISO 27019, судя по содержанию проекта документа, будет содержать сведения о базовых механизмах защиты электрических подстанций и интеллектуальных устройств. То есть стандарты этой серии смогут охватить четыре из семи доменов – генерирующие, передающие, распределяющие организации и потребителя. 3. Стандарты, разработанные Международной электротехнической комиссией, а именно IEC 61784, 62443, 62351 и TR 62210, также ориентированы на обеспечение информационной безопасности систем производства и управления производством. Данная серия довольно детально и полно описывает защиту трех доменов – генерирующих, передающих и распределяющих организаций. 4. Серия стандартов NERC CIP, в основном, ориентирована на обеспечение кибербезопасности в SCADA. Эти документы носят декларативный характер и также не учитывают специфику обеспечения информационной безопасности в Smart Grid. 5. Стандарты Национального института стандартизации и технологий описывают вопросы безопасности в промышленных системах. В тоже время технический отчет NISTIR 7628 вводит понятие кибербезопасности в Smart Grid системах. Данный документ является первым ориентированным именно на Smart Grid и наиболее полно дает описание множества объектов и субъектов Smart Grid, их взаимодействия и механизмов защиты. Таким образом, можно предположить, что для понимания процесса обеспечения информационной безопасности Smart Grid систем наиболее полно подходит технический отчет NISTIR 7628, так как именно этот документ описывает отличия в подходах к обеспечению информационной безопасности SCADA, АСУ ТП и Smart Grid
Béla Genge - One of the best experts on this subject based on the ideXlab platform.
-
Behavior-based Critical Cyber Asset identification in Process Control Systems under Cyber Attacks
Proceedings of the 2015 16th International Carpathian Control Conference (ICCC), 2015Co-Authors: István Kiss, Béla Genge, Piroska HallerAbstract:The accelerated advancement of Process Control Systems (PCS) transformed the traditional and completely isolated systems view into a networked inter-connected “system of systems” perspective, where off-the-shelf Information and Communication Technologies (ICT) are deeply embedded into the heart of PCS. This has brought significant economical and operational benefits, but it also provided new opportunities for malicious actors targeting Critical PCS. To address these challenges, in this work we employ our previously developed Cyber Attack Impact Assessment (CAIA) technique to provide a systematic mechanism to help PCS designers and industry operators to assess the impact severity of various Cyber threats. Moreover, the question of why a device is more Critical than others, and also the motivation of this work, are answered through extensive numerical results showing the significance of systems dynamics in the context of closed-loop PCS. The CAIA approach is validated against the simulated Tennessee Eastman chemical process, including 41 observed variables and 12 control variables, involved in cascade controller structures. The results show the application possibilities and effectiveness of CAIA for various attack scenarios.