Security Metrics in Industrial Control Systems
Zachary A. Collier (1), Mahesh Panwar (2), Alexander A. Ganin (3),, Alex Kott (4), Igor Linkov (1) ((1) US Army Engineer Research & Development, Center, Concord, MA, USA (2) Contractor to US Army Engineer Research &, Development Center, Concord, MA, USA (3)University of Virginia

TL;DR
This paper explores the development of cyber security metrics for Industrial Control Systems, emphasizing resilience metrics and presenting two approaches for their generation, to enhance system defense strategies.
Contribution
It introduces resilience as a key metric for ICS security and proposes matrix-based and network-based methods for generating these metrics, tailored to diverse ICS environments.
Findings
Resilience metrics provide valuable insights into ICS security.
Two approaches for generating resilience metrics are proposed.
Discussion of benefits and drawbacks of different metric methods.
Abstract
Risk is the best known and perhaps the best studied example within a much broader class of cyber security metrics. However, risk is not the only possible cyber security metric. Other metrics such as resilience can exist and could be potentially very valuable to defenders of ICS systems. Often, metrics are defined as measurable properties of a system that quantify the degree to which objectives of the system are achieved. Metrics can provide cyber defenders of an ICS with critical insights regarding the system. Metrics are generally acquired by analyzing relevant attributes of that system. In terms of cyber security metrics, ICSs tend to have unique features: in many cases, these systems are older technologies that were designed for functionality rather than security. They are also extremely diverse systems that have different requirements and objectives. Therefore, metrics for ICSs must…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Systems Engineering Methodologies and Applications · Smart Grid Security and Resilience
