Improving ICS Cyber Resilience through Optimal Diversification of Network Resources

10/31/2018
by   Tingting Li, et al.
0

Network diversity has been widely recognized as an effective defense strategy to mitigate the spread of malware. Optimally diversifying network resources can improve the resilience of a network against malware propagation. This work proposes an efficient method to compute such an optimal deployment, in the context of upgrading a legacy Industrial Control System with modern IT infrastructure. Our approach can tolerate various constraints when searching for an optimal diversification, such as outdated products and strict configuration policies. We explicitly measure the vulnerability similarity of products based on the CVE/NVD, to estimate the infection rate of malware between products. A Stuxnet-inspired case demonstrates our optimal diversification in practice, particularly when constrained by various requirements. We then measure the improved resilience of the diversified network in terms of a well-defined diversity metric and Mean-time-to-compromise (MTTC), to verify the effectiveness of our approach. We further evaluate three factors affecting the performance of the optimization, such as the network structure, the variety of products and constraints. Finally, we show the competitive scalability of our approach in finding optimal solutions within a couple of seconds to minutes for networks of large scales (up to 10,000 hosts) and high densities (up to 240,000 edges).

READ FULL TEXT

page 9

page 10

page 13

page 14

research
02/09/2023

Mathematical Modeling of Cyber Resilience

We identify quantitative characteristics of responses to cyber compromis...
research
06/27/2022

Cyber Network Resilience against Self-Propagating Malware Attacks

Self-propagating malware (SPM) has led to huge financial losses, major d...
research
03/22/2023

Production Networks Resilience: Cascading Failures, Power Laws and Optimal Interventions

In this paper, we study the severity of cascading failures in supply cha...
research
09/23/2021

Cyber Resilience in IoT network: Methodology and example of assessment through epidemic spreading

Cyber Resilience is an important property of complex systems and is impo...
research
02/09/2023

Piecewise Linear and Stochastic Models for the Analysis of Cyber Resilience

We model a vehicle equipped with an autonomous cyber-defense system in a...
research
02/28/2022

Anti-Malware Sandbox Games

We develop a game theoretic model of malware protection using the state-...

Please sign up or login with your details

Forgot password? Click here to reset