서브메뉴
검색
Strategic Network Security for Critical Infrastructures
Strategic Network Security for Critical Infrastructures
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20260209102849
- ISBN
- 9798291563861
- DDC
- 310
- 저자명
- Palani, Kartik.
- 서명/저자
- Strategic Network Security for Critical Infrastructures
- 발행사항
- [Sl] : University of Illinois at Urbana-Champaign, 2023
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2023
- 형태사항
- 130 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 87-02, Section: B.
- 주기사항
- Advisor: Nicol, David M.
- 학위논문주기
- Thesis (Ph.D.)--University of Illinois at Urbana-Champaign, 2023.
- 초록/해제
- 요약The safety and integrity of critical infrastructures are of utmost importance to a nation's economy and security. In order to guarantee operational availability and service metrics, these infrastructures rely on automation provided by an underlying network of computers. In recent years, these automation systems have been used by attackers to gain access to and disrupt the physical processes being controlled. This dissertation aims to provide quantifiable methods to assess the risk added to the system by this extended attack surface and to design automated mechanisms for mitigating the system risk by selecting and deploying the right countermeasures.Any countermeasure strategy must account for the operational constraints that the system has in place for service guarantees and must make trade-offs between system availability and cybersecurity. The risk mitigation work presented in this dissertation generates countermeasure strategies that account for the strict communication deadlines between networked controllers, the regulatory requirements demanded by national regulators, and the security budgets of the infrastructure operators.Regarding risk assessment, we propose quantifiable metrics that can be used with operator expertise. We describe metrics that can be computed with or without knowledge about the attacker. We also provide a tool for measuring the monetary impact of a successful attack campaign. Regarding risk mitigation, we describe algorithms to select and deploy countermeasures. Since firewalls are used as a primary network security mechanism, we provide a detailed analysis of mitigating the risk allowed by the network access policy. We also show how we can rank countermeasure strategies that prioritize security against certain adversary groups under assumptions about attacker capabilities. Finally, we also design a new countermeasure that tackles one of the most commonly used attacker tactics.
- 일반주제명
- Statistics
- 일반주제명
- Computer science
- 일반주제명
- Electrical engineering
- 일반주제명
- Computer engineering
- 키워드
- Optimization
- 키워드
- Cybersecurity
- 키워드
- Algorithms
- 기타저자
- University of Illinois at Urbana-Champaign Electrical & Computer Eng
- 기본자료저록
- Dissertations Abstracts International. 87-02B.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260203s2023 us c eng d■001000017365891
■00520260209102849
■006m o d
■007cr#unu||||||||
■020 ▼a9798291563861
■035 ▼a(MiAaPQ)AAI32271362
■035 ▼a(MiAaPQ)httphdlhandlenet2142121396
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a310
■1001 ▼aPalani, Kartik.
■24510▼aStrategic Network Security for Critical Infrastructures
■260 ▼a[Sl]▼bUniversity of Illinois at Urbana-Champaign▼c2023
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2023
■300 ▼a130 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 87-02, Section: B.
■500 ▼aAdvisor: Nicol, David M.
■5021 ▼aThesis (Ph.D.)--University of Illinois at Urbana-Champaign, 2023.
■520 ▼aThe safety and integrity of critical infrastructures are of utmost importance to a nation's economy and security. In order to guarantee operational availability and service metrics, these infrastructures rely on automation provided by an underlying network of computers. In recent years, these automation systems have been used by attackers to gain access to and disrupt the physical processes being controlled. This dissertation aims to provide quantifiable methods to assess the risk added to the system by this extended attack surface and to design automated mechanisms for mitigating the system risk by selecting and deploying the right countermeasures.Any countermeasure strategy must account for the operational constraints that the system has in place for service guarantees and must make trade-offs between system availability and cybersecurity. The risk mitigation work presented in this dissertation generates countermeasure strategies that account for the strict communication deadlines between networked controllers, the regulatory requirements demanded by national regulators, and the security budgets of the infrastructure operators.Regarding risk assessment, we propose quantifiable metrics that can be used with operator expertise. We describe metrics that can be computed with or without knowledge about the attacker. We also provide a tool for measuring the monetary impact of a successful attack campaign. Regarding risk mitigation, we describe algorithms to select and deploy countermeasures. Since firewalls are used as a primary network security mechanism, we provide a detailed analysis of mitigating the risk allowed by the network access policy. We also show how we can rank countermeasure strategies that prioritize security against certain adversary groups under assumptions about attacker capabilities. Finally, we also design a new countermeasure that tackles one of the most commonly used attacker tactics.
■590 ▼aSchool code: 0090.
■650 4▼aStatistics
■650 4▼aComputer science
■650 4▼aElectrical engineering
■650 4▼aComputer engineering
■653 ▼aOptimization
■653 ▼aCybersecurity
■653 ▼aCyber-physical systems
■653 ▼aAlgorithms
■653 ▼aComputer networks
■690 ▼a0544
■690 ▼a0984
■690 ▼a0463
■690 ▼a0464
■71020▼aUniversity of Illinois at Urbana-Champaign▼bElectrical & Computer Eng.
■7730 ▼tDissertations Abstracts International▼g87-02B.
■790 ▼a0090
■791 ▼aPh.D.
■792 ▼a2023
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17365891▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


