HESTIA: High-level and Extensible System for Training and - - PowerPoint PPT Presentation

hestia high level and extensible system for training and
SMART_READER_LITE
LIVE PREVIEW

HESTIA: High-level and Extensible System for Training and - - PowerPoint PPT Presentation

HESTIA: High-level and Extensible System for Training and Infrastructure risk Assessment Ananth A. Jillepalli, University of Idaho cred-c.org | 1 Introduction Transition Transition of Industrial Control Systems (ICS) into Cyber


slide-1
SLIDE 1

cred-c.org | 1

HESTIA: High-level and Extensible System for Training and Infrastructure risk Assessment

Ananth A. Jillepalli, University of Idaho

slide-2
SLIDE 2

cred-c.org | 2

Introduction – Transition

  • Transition of Industrial Control Systems (ICS) into Cyber Physical Control

Systems (CPCS).

  • Digital / analog equipment of ICS is being replaced by cyber-enabled equipment.
slide-3
SLIDE 3

cred-c.org | 3

Introduction – New Vector of Vulnerabilities

  • Increased connectivity of CPCS to the internet.
  • Open-source applications are purchased commercially off-the-shelf

(COTS), without consideration of applying current standard patches.

slide-4
SLIDE 4

cred-c.org | 4

Introduction – Change in Attack Framework

  • Until recently, CPCS attacks originated from an insider threat.
  • In the recent years, attacks originating from outside are becoming

frequent.

slide-5
SLIDE 5

cred-c.org | 5

Introduction – Financial Impact

  • Cyber-attacks on CPCS are occurring at an ever-increasing rate, incurring

financial loss to both governments and industries.

  • Estimates project losses as high as $1.87 billion by 2018, due to cyber-

attacks on CPCS infrastructure.

slide-6
SLIDE 6

cred-c.org | 6

Problem – Identifying Vulnerabilities

  • For a Chief Security Officer (CSO):
  • Identifying vulnerabilities specific to a particular CPCS infrastructure can

be a challenge, if there is no high-level security policy specification.

slide-7
SLIDE 7

cred-c.org | 7

Problem – Designing best hardening strategy

  • Obtaining the high-level security policy specification of the existing CPCS

state is not sufficient by itself.

  • A CSO should be able to design the best hardening strategy for their

particular CPCS system.

slide-8
SLIDE 8

cred-c.org | 8

Problem – Designing best hardening strategy

  • Obtaining the high-level security policy specification of the existing CPCS

state is not sufficient by itself.

  • A CSO should be able to design the best hardening strategy for their

particular CPCS system.

slide-9
SLIDE 9

cred-c.org | 9

Problem – Required Investigation

  • Such a design process includes investigating:
  • “where to best use defense resources, which parts to harden, and in which

particular order?”

slide-10
SLIDE 10

cred-c.org | 10

Problem – Investigation Factors

  • Several factors come into play:
  • Completeness and consistency of the CPCS infrastructure policies;
  • Likeliness of attacks and respective defenses against the particular system;
  • Overall cost of possible attacks versus overall cost of possible defenses.
  • Overall cost = Time and money.
slide-11
SLIDE 11

cred-c.org | 11

Problem – Investigation Factors

  • Several factors come into play:
  • Completeness and consistency of the CPCS infrastructure policies;
  • Likeliness of attacks and respective defenses against the particular system;
  • Overall cost of possible attacks versus overall cost of possible defenses.
  • Overall cost = Time and money.
slide-12
SLIDE 12

cred-c.org | 12

Proposed Solution – HESTIA

  • HESTIA: High-level and Extensible System for Training and Infrastructure

risk Assessment.

  • Work in progress.
slide-13
SLIDE 13

cred-c.org | 13

Data Flow of HESTIA

slide-14
SLIDE 14

cred-c.org | 14

Data Flow of HESTIA

slide-15
SLIDE 15

cred-c.org | 15

Architecture of HESTIA

slide-16
SLIDE 16

cred-c.org | 16

Architecture of HESTIA

slide-17
SLIDE 17

cred-c.org | 17

Architecture of HESTIA

slide-18
SLIDE 18

cred-c.org | 18

Architecture of HESTIA

slide-19
SLIDE 19

cred-c.org | 19

Architecture of HESTIA

slide-20
SLIDE 20

cred-c.org | 20

Architecture of HESTIA

slide-21
SLIDE 21

cred-c.org | 21

Current Research Status and Conclusion

  • Developed a specification language called HERMES.
  • In process to develop the ‘Consistency check engine’.
  • We hope that this endeavor will contribute to solving the problem of

enabling a CSO to design the best hardening strategy.

slide-22
SLIDE 22

http://cred-c.org @credcresearch facebook.com/credcresearch/

Funded by the U.S. Department of Energy and the U.S. Department of Homeland Security