Are the processing facilities safe and secured against cyber threats?

IF 11 1区 工程技术 Q1 ENGINEERING, INDUSTRIAL Reliability Engineering & System Safety Pub Date : 2025-03-08 DOI:10.1016/j.ress.2025.111011
Rajeevan Arunthavanathan , Faisal Khan , Zaman Sajid , Md. Tanjin Amin , Kalyan Raj Kota , Shreyas Kumar
{"title":"Are the processing facilities safe and secured against cyber threats?","authors":"Rajeevan Arunthavanathan ,&nbsp;Faisal Khan ,&nbsp;Zaman Sajid ,&nbsp;Md. Tanjin Amin ,&nbsp;Kalyan Raj Kota ,&nbsp;Shreyas Kumar","doi":"10.1016/j.ress.2025.111011","DOIUrl":null,"url":null,"abstract":"<div><div>Most processing facilities, including those in the chemical, petrochemical, and mineral industries, aim to operate as cyber-physical systems to achieve higher plant efficiency, productivity, and, in some cases, safety. However, this digital transformation increases the vulnerability of process control systems to cyber-attacks, which can disrupt operations and lead to catastrophic consequences. Traditional approaches often consider cybersecurity solely as an Information Technology (IT) issue, overlooking the critical role of Operational Technology (OT) in managing cyber threats and ensuring plant resilience. This article reviews OT cybersecurity challenges and solutions, culminating in developing a robust OT-specific cybersecurity framework. The proposed framework integrates threat modeling, real-time attack detection, and real-time mitigation to protect physical plant operations while ensuring operational continuity. Unlike existing models, the proposed framework bridges the safety-security gap by combining IT-driven cybersecurity strategies with OT-specific risk management and defense mechanisms. Key features of the framework include layered defense mechanisms, adaptive response strategies, and risk-based prioritization, all of which collectively strengthen resilience against advanced cyber threats. By systematically reviewing current cybersecurity practices and proposing a comprehensive framework, this study further recommends approaches to enhance scalability and practical applicability for advancing cybersecurity in process plant operations. The findings underscore the necessity of integrating IT and OT cybersecurity strategies to ensure industrial safety, security, and uninterrupted operations.</div></div>","PeriodicalId":54500,"journal":{"name":"Reliability Engineering & System Safety","volume":"260 ","pages":"Article 111011"},"PeriodicalIF":11.0000,"publicationDate":"2025-03-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Reliability Engineering & System Safety","FirstCategoryId":"5","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0951832025002121","RegionNum":1,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, INDUSTRIAL","Score":null,"Total":0}
引用次数: 0

Abstract

Most processing facilities, including those in the chemical, petrochemical, and mineral industries, aim to operate as cyber-physical systems to achieve higher plant efficiency, productivity, and, in some cases, safety. However, this digital transformation increases the vulnerability of process control systems to cyber-attacks, which can disrupt operations and lead to catastrophic consequences. Traditional approaches often consider cybersecurity solely as an Information Technology (IT) issue, overlooking the critical role of Operational Technology (OT) in managing cyber threats and ensuring plant resilience. This article reviews OT cybersecurity challenges and solutions, culminating in developing a robust OT-specific cybersecurity framework. The proposed framework integrates threat modeling, real-time attack detection, and real-time mitigation to protect physical plant operations while ensuring operational continuity. Unlike existing models, the proposed framework bridges the safety-security gap by combining IT-driven cybersecurity strategies with OT-specific risk management and defense mechanisms. Key features of the framework include layered defense mechanisms, adaptive response strategies, and risk-based prioritization, all of which collectively strengthen resilience against advanced cyber threats. By systematically reviewing current cybersecurity practices and proposing a comprehensive framework, this study further recommends approaches to enhance scalability and practical applicability for advancing cybersecurity in process plant operations. The findings underscore the necessity of integrating IT and OT cybersecurity strategies to ensure industrial safety, security, and uninterrupted operations.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
处理设施是否安全,能够抵御网络威胁?
大多数加工设施,包括化工、石化和矿产行业的设施,旨在作为网络物理系统运行,以实现更高的工厂效率、生产力,在某些情况下,还包括安全性。然而,这种数字化转型增加了过程控制系统对网络攻击的脆弱性,这可能会破坏操作并导致灾难性后果。传统方法通常只将网络安全视为信息技术(IT)问题,而忽略了运营技术(OT)在管理网络威胁和确保工厂恢复能力方面的关键作用。本文回顾了OT网络安全挑战和解决方案,并最终开发了一个健壮的OT专用网络安全框架。拟议的框架集成了威胁建模、实时攻击检测和实时缓解,以保护物理工厂的操作,同时确保操作的连续性。与现有模型不同,该框架通过将it驱动的网络安全策略与iot特定的风险管理和防御机制相结合,弥合了安全缺口。该框架的主要特征包括分层防御机制、自适应响应策略和基于风险的优先级,所有这些共同增强了对高级网络威胁的弹性。通过系统地回顾当前的网络安全实践并提出一个全面的框架,本研究进一步推荐了提高可扩展性和实际适用性的方法,以推进过程工厂运营中的网络安全。研究结果强调了整合IT和OT网络安全策略以确保工业安全、安保和不间断运营的必要性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
Reliability Engineering & System Safety
Reliability Engineering & System Safety 管理科学-工程:工业
CiteScore
15.20
自引率
39.50%
发文量
621
审稿时长
67 days
期刊介绍: Elsevier publishes Reliability Engineering & System Safety in association with the European Safety and Reliability Association and the Safety Engineering and Risk Analysis Division. The international journal is devoted to developing and applying methods to enhance the safety and reliability of complex technological systems, like nuclear power plants, chemical plants, hazardous waste facilities, space systems, offshore and maritime systems, transportation systems, constructed infrastructure, and manufacturing plants. The journal normally publishes only articles that involve the analysis of substantive problems related to the reliability of complex systems or present techniques and/or theoretical results that have a discernable relationship to the solution of such problems. An important aim is to balance academic material and practical applications.
期刊最新文献
Enhancing power grid cybersecurity against FDI attacks via deep Q-network-based moving target defense Optimal Bayesian maintenance policy for gear shafts under variable operating conditions with partially observable information Optimization of isolation valve operation and identification of critical components for enhancing the resilience of water distribution systems Hazard and vulnerability analysis of NaTech disasters induced by hydrological events to support probabilistic safety assessment in natural gas pipelines A pressure-chlorine driven approach to design effective district metered areas (DMA) configurations in water distribution systems
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1