DHSS 2013 Proceeding

Weighted attack trees for the cybersecurity analysis of SCADA systems

Authors:   Andrea Bobbio, Lavinia Egidi, Roberta Terruggia, Ester Ciancamerla, Michele Minichino

Abstract

In this paper we address the issue of security of SCADA systems; a topic of paramount importance because of the impact on physical security and very challenging because of the peculiarities that set SCADA systems aside from usual ICT networks. We apply the modeling technique based on structures called weighted Attack and Defense Trees (ADT) to a complex case study based on a typical SCADA architecture, in which the attack tree is enriched with the cost and the impact of the attack. We introduce a new analysis technique for weighted ADT based on the representation of the attack scenario by means of Multi- Terminal Binary Decision Diagrams (MTBDD) that al- low the modeler to identify the most probable attack sce- narios, in term of probability cost and impact, and gives an indication on how to mitigate the located breaches by means of suitable countermeasures.

I3M  Scientific Sponsors

I3M  Industrial Sponsors

I3M  Media Sponsors