Ship cyber security assessment model based on probability attack graph

Expand
  • (Navigation College, Dalian Maritime University, Dalian 116026, China;Dalian Ship Cyber Security Engineering Research Center, Dalian 116026, China)

Online published: 2023-01-29

Abstract

In order to improve the ship cyber security evaluation model, a quantitative ship cyber security evaluation model was built by combining probability graph model and time index. On the basis of considering time index, the probability attack graph was used to calculate the probability of the ship cyber being attacked. Monte Carlo method was used to simulate the relationship between the probability of ship cyber being conquered and the length of access path, the probability of node being conquered and the time length. The results show that the ship cyber security evaluation model based on probability attack graph can evaluate the impact of different indicators on the probability of ship cyber being attacked.

Cite this article

YANG Jiaxuan, XU Zhoujin, LAI Yuan, SUN Yao . Ship cyber security assessment model based on probability attack graph[J]. Journal of Dalian Maritime University, 2023 , 49(1) : 26 -33 . DOI: 10.16411/j.cnki.issn1006-7736.2023.01.003

References

[1]CAPROLU M, PIETRO R D, RAPONI S, et al. Vessels cyber security: issues, challenges, and the road ahead[J]. IEEE, 2020,58 (6): 90-96.
[2]Navaldome. Naval dome hacks into ships’ system to prove cyber vulnerabilities [EB/OL]. (2018-01-02)[2022-10-13].https://navaldome.com/threat.html.
[3]ICS-Advisory. Auto-Maskin RP210E, DCU210E, and Marine Observer Pro [EB/OL].(2020-02-20)[2022-10-13].http//www.uscert.gov/ics/advisories/icsa-20-051-04.
[4]苏义鑫, 刘宇杰, 龙飞. 船舶网络安全综述[J]. 船电技术, 2018, 38(9): 5-10.SUN Y X, LIU Y J, LONG F. Overview on ship cyber security[J]. Marine Electric & Electronic Engineering, 2018, 38(9): 5-10.(in Chinese)
[5]王志中.船舶通信网络安全评估模型研究[J].舰船科学技术,2018,40(6):88-90.
WANG Z Z. Research on ship communication network security evaluation model[J]. Ship Science and Technology, 2018, 40(6):88-90. (in Chinese).
[6]时荣, 王喜.舰船网络安全评估的仿真模拟实验研究[J].舰船科学技术,2019, 41(18): 154-156.
SHI R, WANG X. Simulated experimental study on ship network security assessment[J]. Ship Science and Technology, 2019, 41(18): 154-156. (in Chinese).
[7]SVILICIC B, RUDAN I, JUGOVIC A, et al. A study on cyber security threats in a shipboard integrated navigational system[J]. Marine Science and Engineering, 2019, 7(10): 364-375.
[8]SAHAY R, MENG W, ESTAY D S, et al. Cyber Ship-IoT: a dynamic and adaptive SDN-based security policy enforcement framework for ships[J]. Future Generation Computer Systems, 2019, 100(2): 736-750.
[9]SVILICIC B, BRCIC D,ZUSKIN S D, et al. Raising awareness on cyber security of ECDIS[J]. TransNav: the International Journal on Marine Navigation and Safety of Sea Transportation, 2019, 13 (1): 107-114.
[10]SVILICIC B, KAMAHARA J, ROOKS M, et al. Maritime cyber risk management: an experimental ship assessment[J]. The Journal of Navigation, 2019, 72(5): 1108-1120. 
[11]KAVALLIERATOS G, KATSIKAS S. GKIOULOS V. Cyber-attacks against the autonomous ship [M]// Computer Security. [S.l.]: Springer, 2018: 20-36.
[12]TAM K, JONES K. MaCRA: a model-based framework for maritime cyber-risk assessment[J]. WMU Journal of Maritime Affairs, 2019, 18(1): 129-163.
[13]TAM K, JONES K. Cyber-risk assessment for autonomous ships[C]//2018 International Conference on Cyber Security and Protection of Digital Services. Glasgow: IEEE,2018: 1-8.
[14]BALDUZZI M, PASTA A, WILHOIT K. A security evaluation of AIS automated identification system[C]//Proceedings of the 30th Annual Computer Security Applications Conference. New York: ACSA, 2014: 436-445. 
[15]KESSLER G C, CRAIGER J P, HAASS J C. A taxonomy framework for maritime cyber security: a demonstration using the automatic identification system[J]. TransNav: International Journal on Marine Navigation and Safety of Sea Transportation, 2018, 12(3): 429-439. 
[16]ENOCH S Y, LEE J S, KIMD S. Novel security models, metrics and security assessment for maritime vessel networks[J]. Computer Networks, 2021, 189(6): 107934-107952.
[17]MELL P, SCARFONE K, ROMANOSKY S. Common vulnerability scoring system version 2: specification document [EB/OL](2007-07-30)[2022-10-13]. https://www.first.org/cvss/v2/guide.
Outlines

/