Bayesian network model to distinguish between intentional attacks and accidental technical failures:

来源 :网络空间安全科学与技术(英文版) | 被引量 : 0次 | 上传用户:nhekccxeadk
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Water management infrastructures such as floodgates are critical and increasingly operated by Industrial Control Systems(ICS).These systems are becoming more connected to the internet,either directly or through the corporate networks.This makes them vulnerable to cyber-attacks.Abnormal behaviour in floodgates operated by ICS could be caused by both(intentional)attacks and(accidental)technical failures.When operators notice abnormal behaviour,they should be able to distinguish between those two causes to take appropriate measures,because for example replacing a sensor in case of intentional incorrect sensor measurements would be ineffective and would not block corresponding the attack vector.In the previous work,we developed the attack-failure distinguisher framework for constructing Bayesian Network(BN)models to enable operators to distinguish between those two causes,including the knowledge elicitation method to construct the directed acyclic graph and conditional probability tables of BN models.As a full case study of the attack-failure distinguisher framework,this paper presents a BN model constructed to distinguish between attacks and technical failures for the problem of incorrect sensor measurements in floodgates,addressing the problem of floodgate operators.We utilised experts who associate themselves with the safety and/or security community to construct the BN model and validate the qualitative part of constructed BN model.The constructed BN model is usable in water management infrastructures to distinguish between intentional attacks and accidental technical failures in case of incorrect sensor measurements.This could help to decide on appropriate response strategies and avoid further complications in case of incorrect sensor measurements.
其他文献
Malware analysis is a task of utmost importance in cyber-security.Two approaches exist for malware analysis:static and dynamic.Modern malware uses an abundance of techniques to evade both dynamic and static analysis tools.Current dynamic analysis solution
期刊
腹腔感染常继发于腹腔中各类器官的损伤或病变,或者发生于腹部手术后。随着营养支持理念和技术的不断发展,营养支持逐渐成为腹腔感染病人治疗的重要手段之一。腹腔感染的综合治疗包括感染源控制、合理抗感染治疗、器官功能支持、营养治疗、免疫调理等。笔者回溯国内外相关研究成果,结合团队临床经验,对腹腔感染的营养支持策略进行分析和阐述。“,”Intra-abdominal infection is often secondary to the injury or lesion of various organs in th
Social engineering has posed a serious threat to cyberspace security.To protect against social engineering attacks,a fundamental work is to know what constitutes social engineering.This paper first develops a domain ontology of social engineering in cyber
SOHO(small office/home office)routers provide services for end devices to connect to the Internet,playing an important role in cyberspace.Unfortunately,security vulnerabilities pervasively exist in these routers,especially in the web server modules,greatl
With the ever-growing data and the need for developing powerful machine learning models,data owners increasingly depend on various untrusted platforms(e.g.,public clouds,edges,and machine learning service providers)for scalable processing or collaborative
Long-term prediction is still a difficult problem in data mining.People usually use various kinds of methods of Recurrent Neural Network to predict.However,with the increase of the prediction step,the accuracy of prediction decreases rapidly.In order to i
Tackling binary program analysis problems has traditionally implied manually defining rules and heuristics,a tedious and time consuming task for human analysts.In order to improve automation and scalability,we propose an alternative direction based on dis
Codes of Open Source Software(OSS)are widely reused during software development nowadays.However,reusing some specific versions of OSS introduces 1-day vulnerabilities of which details are publicly available,which may be exploited and lead to serious secu
目的:探讨头孢菌素联合吗啉硝唑预防肠外瘘病人手术部位感染(SSI)的临床价值。方法:采用回顾性队列研究方法。收集2017年1―12月中国人民解放军东部战区总医院收治的107例行择期消化道重建手术肠外瘘病人的临床病理资料;男76例,女31例;中位年龄为46岁,年龄范围为18~79岁。107例病人中,43例病人给予头孢菌素预防SSI,设为头孢菌素单药组;64例病人给予头孢菌素联合吗啉硝唑预防SSI,设为联合用药组。观察指标:(1)SSI发生情况。(2)分层分析。(3)SSI致病菌培养结果。(4)药物不良反应发
目的:探讨肝移植后发生腹腔感染的危险因素。方法:采用回顾性病例对照研究方法。收集2015年1月至2018年12月西安交通大学第一附属医院收治的356例肝移植受者的临床资料;男273例,女83例;中位年龄为46岁,年龄范围为21~67岁。观察指标:(1)肝移植后发生腹腔感染及病原菌分布情况。(2)肝移植后发生腹腔感染的影响因素分析。(3)随访和生存情况。采用门诊和电话方式进行随访,了解受者术后1年总体生存率和死亡原因。随访时间截至2020年6月。正态分布的计量资料以n x±n s表示;偏