论文标题

对水部门的网络安全事件的审查

A Review of Cybersecurity Incidents in the Water Sector

论文作者

Hassanzadeh, Amin, Rasekh, Amin, Galelli, Stefano, Aghashahi, Mohsen, Taormina, Riccardo, Ostfeld, Avi, Banks, Katherine

论文摘要

这项研究对水部门中披露,记录和恶意的网络安全事件进行了批判性审查,以告知保护网络安全威胁的努力。审查是在工业控制系统架构,攻击防御模型和安全解决方案的技术背景下进行的。通过搜索策略选择并分析了15起事件,其中包括各种公共信息来源,从联邦调查报告到科学论文。对于每个事件,汇编和描述了每个事件,情况,反应,补救和经验教训。这篇综述的结果表明,网络危机对水部门的频率,多样性和复杂性有所增加。尽管发现了新威胁的出现,例如勒索软件或隐脚劫机,但同样的脆弱性和威胁(例如内部威胁)的复发也很明显,也很明显,强调了对水网络防御水的适应性,合作和全面的方法的需求。

This study presents a critical review of disclosed, documented, and malicious cybersecurity incidents in the water sector to inform safeguarding efforts against cybersecurity threats. The review is presented within a technical context of industrial control system architectures, attack-defense models, and security solutions. Fifteen incidents were selected and analyzed through a search strategy that included a variety of public information sources ranging from federal investigation reports to scientific papers. For each individual incident, the situation, response, remediation, and lessons learned were compiled and described. The findings of this review indicate an increase in the frequency, diversity, and complexity of cyberthreats to the water sector. Although the emergence of new threats, such as ransomware or cryptojacking, was found, a recurrence of similar vulnerabilities and threats, such as insider threats, was also evident, emphasizing the need for an adaptive, cooperative, and comprehensive approach to water cyberdefense.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源