{"title":"System-specific risk rating of software vulnerabilities in industrial automation & control systems","authors":"Monika Maidl, Dirk Kröselberg, Tiange Zhao, Tobias Limmer","doi":"10.1109/ISSREW53611.2021.00097","DOIUrl":null,"url":null,"abstract":"Security vulnerabilities are constantly detected in software, and with CVE a world wide infrastructure exists to inform about such vulnerabilities. Typically, the software vendor issues a patch for the vulnerability. The system owners have to install patches timely in order protect against attacks that exploit vulnerabilities. In industrial automation & control systems, there is often a lot of overhead for installing patches, as availability must be ensured. Hence it makes sense to patch immediately only if the vulnerability poses a high risk to the operation of the plant. We propose an algorithm for calculating the system-specific risk of a vulnerability, based on a system model and a system risk image for system-specific exposure and impact. The system-specific exposure depends on the deployment, while the level of impact depends on the purpose of the system, e.g. in critical infrastructure.","PeriodicalId":385392,"journal":{"name":"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)","volume":"10 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISSREW53611.2021.00097","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Security vulnerabilities are constantly detected in software, and with CVE a world wide infrastructure exists to inform about such vulnerabilities. Typically, the software vendor issues a patch for the vulnerability. The system owners have to install patches timely in order protect against attacks that exploit vulnerabilities. In industrial automation & control systems, there is often a lot of overhead for installing patches, as availability must be ensured. Hence it makes sense to patch immediately only if the vulnerability poses a high risk to the operation of the plant. We propose an algorithm for calculating the system-specific risk of a vulnerability, based on a system model and a system risk image for system-specific exposure and impact. The system-specific exposure depends on the deployment, while the level of impact depends on the purpose of the system, e.g. in critical infrastructure.