论文标题
ICS-CTM2:工业控制系统网络安全测试床成熟度模型
ICS-CTM2: Industrial Control System Cybersecurity Testbed Maturity Model
论文作者
论文摘要
工业控制系统(ICS)测试床是评估和验证控制系统性能,网络安全工具和技术的平台。为了构建或增强ICS测试床,对其设计规范和特征属性有更深入的了解至关重要。满足此先决条件涉及对现有测试床的这些属性的检查和评估。为了进一步提高对测试床的功能的信心,重要的是对其与其他ICS测试床的规格进行比较分析非常重要。但是,目前尚无标准化方法来提供对不同测试床的比较评估。在本文中,我们提出了一种受网络安全能力成熟度模型(C2M2)启发的分析ICS测试床的方法。特别地,我们定义了ICS网络安全测试床的成熟度模型,其域和相关的成熟指标水平。为了证明该模型的好处,我们对代表不同工业领域的几个ICS测试床进行了案例研究分析。我们的分析提供了对这些测试床的相对优势和局限性的更深入的见解,以及与模型定义的域相对于未来增强的范围。
Industrial Control System (ICS) testbeds serve as a platform for evaluating and validating control system performances, cybersecurity tools and technologies. In order to build or enhance an ICS testbed, it is vital to have a deeper understanding of its design specifications and characteristic attributes. Satisfying this prerequisite involves examination and assessment of these attributes for existing testbeds. To further increase confidence in a testbed's functionality, it is important to perform a comparative analysis of its specifications with other ICS testbeds. However, at present, there is no standardized methodology available to provide a comparative assessment of different testbeds. In this paper, we propose a methodology for analyzing ICS testbeds, inspired by the Cybersecurity Capability Maturity Model (C2M2). In particular, we then define a ICS Cybersecurity Testbed Maturity Model, its domains, and the associated maturity indicator levels. To demonstrate the benefit of the model, we have conducted a case study analysis for several ICS testbeds, representing different industrial sectors. Our analysis provides deeper insights into the relative strengths and limitations of these testbeds, together with scope for future enhancements, with respect to the domains defined by the model.