Related Experiment Videos
Cyber security risk assessment for SCADA and DCS networks
P A S Ralston1, J H Graham, J L Hieb
1University of Louisville, JB Speed School of Engineering, 40292 Louisville, KY, United States. parals01@louisville.edu
ISA Transactions
|July 13, 2007
Summary
Cyber security threats to industrial control systems like SCADA and DCS are increasing. This paper reviews risk assessment methods, including HHM, IIM, RFRM, and PRA, to help engineers manage these critical infrastructure vulnerabilities.
Area of Science:
- Cybersecurity
- Industrial Control Systems
- Risk Assessment
Background:
- Critical infrastructures and industrial automation increasingly rely on interconnected cyber-physical control systems.
- This dependence introduces significant and previously unforeseen cybersecurity threats to Supervisory Control and Data Acquisition (SCADA) and Distributed Control Systems (DCS).
- Engineers and managers require accessible information and understanding of these evolving threats.
Purpose of the Study:
- To provide a comprehensive overview of cybersecurity and risk assessment specifically for SCADA and DCS environments.
- To introduce key industry organizations and government bodies involved in industrial cybersecurity.
- To offer a detailed review of the existing literature on the subject.
Main Methods:
- Introduction to major risk assessment concepts and methodologies applied to SCADA systems.
- Discussion of specific methods such as Hierarchical Hazard Method (HHM), Impact-Impact Method (IIM), and Risk Reduction Factor Method (RFRM).
- Overview of Probability Risk Analysis (PRA) techniques including Fault Tree Analysis (FTA), Event Tree Analysis (ETA), and Failure Modes and Effects Analysis (FMEA).
Main Results:
- Successful application of methods like HHM, IIM, and RFRM to complex SCADA systems with interdependencies.
- Highlighting the critical need for quantifiable metrics in risk assessment for industrial control systems.
- Presentation of two recent quantitative methods utilizing compromise graphs and augmented vulnerability trees.
Conclusions:
- The paper provides a foundational understanding of cybersecurity risks and assessment methods for SCADA and DCS.
- It emphasizes the importance of quantifiable metrics and introduces advanced techniques for evaluating attack probability, impact, and countermeasure effectiveness.
- This work aims to equip engineers and managers with the knowledge to navigate and mitigate cybersecurity threats in critical infrastructures.
Related Concept Videos
Distribution Reliability and Automation
Distribution reliability in electrical power systems is critical for ensuring an uninterrupted power supply to consumers at minimal cost. According to IEEE Standard Terms, reliability is the probability that a device will function without failure over a specified time period or amount of usage. For electric power distribution, this translates to maintaining continuous power supply and addressing customer concerns over power outages. Several indices, as defined by IEEE Standard 1366-2012, are...
Hazard Analysis and Critical Control Points (HACCP)
Hazard Analysis and Critical Control Points (HACCP) is a science-based, preventive system used globally to ensure food safety by identifying, evaluating, and controlling biological, chemical, and physical hazards throughout food production. Originally developed by NASA and the Pillsbury Company for astronaut food, HACCP is now a core component of the Codex Alimentarius.HACCP operates on prerequisite programs—such as Good Manufacturing Practices (GMPs), sanitation procedures, and supplier...
Pilot and Numeric Relaying
Pilot relaying is a type of differential protection used in power systems. It compares electrical quantities at the terminals of equipment via a communication channel instead of direct relay interconnection. This method is essential for transmission lines where the terminals are far apart, typically up to 80 km for lines with 69 to 115 kV ratings. Four types of communication channels are used for pilot relaying:
Zones of Protection
In power systems, the entire setup is divided into protective zones to isolate faults and protect the rest of the network. These zones include generators, transformers, buses, transmission lines, distribution lines, and motors. Each zone can be visualized as a separate room in a house, with each room protected by its own circuit breaker.
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Guidelines and Strategies for Safe Computer Charting
The guidelines and strategies provided by the American Nurses Association (ANA) and the Canadian Nurses Association (CNA) offer essential principles for ensuring safe and secure computer charting systems in healthcare settings. Let's break down each recommendation:
Maintain Confidentiality and Security:
Maintain Confidentiality and Security:
Reclosers and Fuses
Automatic circuit reclosers enhance the protection of distribution circuits by interrupting and auto-reclosing an AC circuit according to a preset sequence. They effectively manage temporary faults on overhead distribution lines, often caused by tree limbs or wildlife, by briefly disrupting service to improve overall reliability. However, contact with reclosers or energized broken conductors on the ground can pose serious hazards.
A comprehensive protection scheme for radial distribution...
A comprehensive protection scheme for radial distribution...