Dependencies and, eventually, interdependencies among Critical Infras- tructures are difficult to identify and to model, because their effects appears in few situations with unpredictable consequences. Adding cy- ber attacks in this context makes analysis even more complex. Inte- grating cyber attacks and interdependencies consequences requires the knowledge of both fields with a common abstraction level. CISIApro is a Critical Infrastructure simulator, and it was born for eval- uating consequences of faults and failures on interdependent infrastruc- tures. In this paper, CISIApro implements the effects of cyber attacks on physical equipment and on infrastructure services. The case study highlights the main functionality of the simulator, with a complex scenario where several events may happen: first an ARP spoofing attack, and then a worm infection. The scenario considers three interconnected infrastructures: a medium voltage power grid, controlled by a SCADA control center over a SCADA network, interconnected with a general-purpose telecommunication network. The simulation results display the output of CISIApro in event of cyber attacks. The simulation demonstrates the help of CISIApro output in a decision making process for electric operators: specifically, the choice between different re-configurations.
Foglietta, C., Palazzo, C., Santini, R., Panzieri, S. (2015). ASSESSING RISK OF CYBER THREATS USING CISIAPRO SIMULATOR. In Springer New York LLC (a cura di), IFIP Advances in Information and Communication Technology. NEW YORK : Springer.
ASSESSING RISK OF CYBER THREATS USING CISIAPRO SIMULATOR
FOGLIETTA, CHIARA
;Palazzo C;SANTINI, RICCARDO;PANZIERI, Stefano
2015-01-01
Abstract
Dependencies and, eventually, interdependencies among Critical Infras- tructures are difficult to identify and to model, because their effects appears in few situations with unpredictable consequences. Adding cy- ber attacks in this context makes analysis even more complex. Inte- grating cyber attacks and interdependencies consequences requires the knowledge of both fields with a common abstraction level. CISIApro is a Critical Infrastructure simulator, and it was born for eval- uating consequences of faults and failures on interdependent infrastruc- tures. In this paper, CISIApro implements the effects of cyber attacks on physical equipment and on infrastructure services. The case study highlights the main functionality of the simulator, with a complex scenario where several events may happen: first an ARP spoofing attack, and then a worm infection. The scenario considers three interconnected infrastructures: a medium voltage power grid, controlled by a SCADA control center over a SCADA network, interconnected with a general-purpose telecommunication network. The simulation results display the output of CISIApro in event of cyber attacks. The simulation demonstrates the help of CISIApro output in a decision making process for electric operators: specifically, the choice between different re-configurations.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.