Investigating a novel approach for cybersecurity risk analysis with application to remote pilotage operations
dc.contributor | Aalto-yliopisto | fi |
dc.contributor | Aalto University | en |
dc.contributor.author | Bolbot, Victor | en_US |
dc.contributor.author | Basnet, Sunil | en_US |
dc.contributor.author | Zhao, Hanning | en_US |
dc.contributor.author | Valdez Banda, Osiris | en_US |
dc.contributor.author | Silverajan, Bilhanan | en_US |
dc.contributor.department | Department of Energy and Mechanical Engineering | en |
dc.contributor.groupauthor | Marine Technology | en |
dc.contributor.organization | Tampere University | en_US |
dc.date.accessioned | 2022-11-09T08:04:43Z | |
dc.date.available | 2022-11-09T08:04:43Z | |
dc.date.issued | 2022-10-04 | en_US |
dc.description.abstract | Remote pilotage constitutes a novel type of service aiming at reduction of operational costs and safety improvement. However, the increased inter-connectivity of remote pilotage renders it vulnerable to cyberattacks. In this paper, we investigate a novel approach to cybersecurity risk analysis, which integrates System-Theoretic Process Analysis method, Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) method, SysML, MITRE ATT&CK, and ranking method. To integrate the methods, we apply a series of relevant adjustments and amendments. As a result, we are able to investigate multiple facets of cyber risk, identify the most critical issues and propose relevant risk control measures. For the remote pilotage, the most important STRIDE attacks involve Spoofing, Tampering, and Denial of Service attacks, whilst the most critical MITRE ATT&CK attack techniques are the use of default credentials, the exploitation of public-facing applications, and replication through removable media, if general hacker profile is considered for the attack. | en |
dc.format.extent | 7 | |
dc.format.mimetype | application/pdf | en_US |
dc.identifier.citation | Bolbot, V, Basnet, S, Zhao, H, Valdez Banda, O & Silverajan, B 2022, Investigating a novel approach for cybersecurity risk analysis with application to remote pilotage operations . in Proceedings of the MARESEC 2022 . Zenodo, European Workshop on Maritime Systems Resilience and Security, Bremerhaven, Bremen, Germany, 20/06/2022 . https://doi.org/10.5281/zenodo.7143998 | en |
dc.identifier.doi | 10.5281/zenodo.7143998 | en_US |
dc.identifier.other | PURE UUID: ee5cdfe4-b6eb-4c87-a584-33e026a93fe5 | en_US |
dc.identifier.other | PURE ITEMURL: https://research.aalto.fi/en/publications/ee5cdfe4-b6eb-4c87-a584-33e026a93fe5 | en_US |
dc.identifier.other | PURE LINK: https://zenodo.org/record/7143998#.Y2UnjXbP1aQ | en_US |
dc.identifier.other | PURE FILEURL: https://research.aalto.fi/files/91337208/MARESEC_2022_14_final.pdf | en_US |
dc.identifier.uri | https://aaltodoc.aalto.fi/handle/123456789/117714 | |
dc.identifier.urn | URN:NBN:fi:aalto-202211096485 | |
dc.language.iso | en | en |
dc.relation.ispartof | European Workshop on Maritime Systems Resilience and Security | en |
dc.relation.ispartofseries | Proceedings of the MARESEC 2022 | en |
dc.rights | openAccess | en |
dc.subject.keyword | remote pilotage | en_US |
dc.subject.keyword | Cyberattack | en_US |
dc.subject.keyword | STPA | en_US |
dc.subject.keyword | STRIDE analysis | en_US |
dc.subject.keyword | MITRE ATT&CK | en_US |
dc.subject.keyword | SysML | en_US |
dc.subject.keyword | CYRA-MS | en_US |
dc.subject.keyword | Risk analysis | en_US |
dc.title | Investigating a novel approach for cybersecurity risk analysis with application to remote pilotage operations | en |
dc.type | A4 Artikkeli konferenssijulkaisussa | fi |
dc.type.version | publishedVersion |