An Integrated Approach to Cyber Risk Management with Cyber Threat Intelligence Framework to Secure Critical Infrastructure
Abstract
:1. Introduction
2. Background and Related Works
2.1. Cyber Risk Management
- Scope and Security Baseline: The first workshop in the framework defines the study’s scope, participants, and timeframe and identifies missions, business assets, and supporting assets while assessing feared events and their impact severity. It also establishes the security baseline and differential as the foundation for subsequent risk assessment and management activities. This workshop involves the top management, the business teams, the security manager, and the IT teams.
- Risk Origins: The second workshop focuses on identifying and characterizing Risk Origins (ROs) and their associated high-level target objectives (TOs). The most relevant RO/TO pairs are selected, and the outcomes are documented in a risk origins mapping, providing a structured understanding of the risks. Thus, this workshop can be an entry point for benefiting from threat intelligence information about threat actors. This workshop involves top management, business teams, the security manager, and, optionally, a specialist in digital threats.
- Strategic Scenarios: The third workshop aims to provide a comprehensive view of the ecosystem and map the digital threats relative to the studied object. This information is used to develop high-level strategic scenarios, which outline potential attack paths from risk origins to their targets. These scenarios determine the severity of the risk scenarios, and by the end of the workshop, security measures for the ecosystem can be defined, contributing to improved risk management. This workshop involves the business teams, functional architects, the security manager, and a cybersecurity specialist optionally.
- Operational Scenarios: In the fourth workshop, an approach similar to the preceding one is adopted, but the focus shifts to critical supporting assets, where technical scenarios are constructed to outline the methods of attack expected to be used by the risk origins in executing the strategic scenarios. Subsequently, the level of likelihood of each operational scenario derived from this workshop is assessed, determining the likelihood of the overall risk scenario. This workshop involves the IT teams, the security manager, and, optionally, a security specialist.
- Risk Treatment: In the last workshop, the culmination of all studied risks is summarized to formulate a comprehensive risk treatment strategy. This strategy is further delineated into security measures integrated into a continuous improvement plan. Additionally, this workshop entails the development of a summary of residual risks and establishing a risk monitoring framework. This workshop involves the top management, the business teams, the security manager, and the IT teams.
2.2. Cyber Threat Intelligence
- Planning and direction: In this foundational phase, the definition of the overall objective of the threat intelligence process not only sets the stage for subsequent activities but also establishes a strategic framework essential for informed decision-making.
- Collection: This data acquisition phase, characterized by the comprehensive gathering of raw data from diverse sources such as network traffic, system logs, clear and dark web forums, and more, exemplifies a diverse approach to intelligence gathering, vital for constructing a threat landscape.
- Processing and exploitation: Within this transformative phase, the intricate conversion of raw data into actionable information represents a critical juncture, emphasizing the importance of data refinement to unlock its true potential in subsequent analytical endeavors.
- Analysis and production: In this pivotal phase, information is analyzed to evolve into intelligence that might be of the following types:
- (a)
- Strategic: This high-level intelligence, focusing on threats and their motives within the organization’s threat landscape, is for strategic decision-making, providing crucial insights for management executives and organizational board members.
- (b)
- Tactical: Offering granular insights into threat actors’ tactics, techniques, and procedures, this intelligence category is an indispensable tool for architects and system administrators to enhance the organization’s defenses against evolving attack vectors.
- (c)
- Operational: This intelligence category, revealing specific details about incoming attacks, motives, timings, and nature, empowers security managers and defenders with actionable information to proactively safeguard the organization’s assets.
- (d)
- Technical: By encompassing indicators of compromise like IP addresses, file hashes, and domain names, this technical intelligence is for security operational center analysts and incident responders, facilitating rapid and precise responses to security incidents.
- Dissemination and integration: In this phase, characterized by the targeted delivery of information to its intended beneficiaries, effective dissemination mechanisms ensure that the intelligence generated is seamlessly integrated into organizational processes, promoting a cohesive and proactive cybersecurity posture.
- Feedback: This iterative phase ensures continuous improvement, enhancing the adaptability and efficacy of the threat intelligence process through a dynamic feedback loop.
2.3. Cyber Threat Intelligence and Cyber Risk Management Integration
3. Methodology and Process
- Problem identification and motivation: The existing literature and documentation of cybersecurity risk management and threat intelligence frameworks were reviewed to identify the gaps, including frameworks, methodologies, and industry best practices. Current risk management methodologies often focus on technical vulnerabilities, overlooking the motives and tactics of threat actors, which limits their effectiveness in addressing emerging threats [51]. Integrating cyber threat intelligence into risk management is still uncommon, and there is a need for systematic approaches to incorporate threat intelligence feeds effectively [10,13]. Existing frameworks often struggle to adapt to the dynamic threat landscape, highlighting the importance of considering adversary techniques for proactive risk mitigation [14,52].
- The solution’s objective: This research aims to propose novel threat intelligence integration into an existing risk management process to enhance the process and response to emerging cybersecurity threats.
- Design and development: This phase includes selecting an existing cybersecurity risk management process and integrating threat intelligence into its different phases. The novel modifications in the EBIOS Risk Manager process aim to integrate the threat intelligence feeds into the different risk management phases. This leads to more accurate risk assessments that consider cyber threat actors’ capabilities and objectives and better treatment prioritization.
- Demonstration: This phase presents the use of the proposed framework to manage the risks in the context of a national telecommunications gateway. The main aim is to demonstrate the framework phases and aspects by assessing and managing risks of a defined scope based on threat intelligence information.
- Evaluation: This phase aims to evaluate and present the enhancements in the novel framework in contrast with the existing problem. This is achieved by analyzing the proposed framework, the results of its conducted application, and the existing frameworks in addressing the existing problem. This includes limitations such as the necessity of threat intelligence resources and implementation validation, which will be part of future work.
4. The Proposed Enhanced Cyber Threat Intelligence Integrated EBIOS Risk Manager
4.1. Scope and Security Baseline
4.2. Threat Intelligence and Assessment/Risk Origins
4.3. Strategic Scenarios
- Dependency: describes the importance of the stakeholder in the specified scope.
- Penetration: describes the level of access of the stakeholder in the specified scope.
- Cyber maturity: describes the security capacities of the stakeholder in the specified scope.
- Trust: describes the interests and intentions of the stakeholder against the organization’s objective in the specified scope.
4.4. Operational Scenarios
4.5. Risk Treatment
4.6. Risk and Threat Monitoring
- Context changes: The whole process should be re-conducted if significant changes occur to the scope.
- New information about threat actors: If new data are received about a new risk origin targeting the organization or a change in the objectives of a risk origin, the risk assessment is re-executed from the Threat Assessment/Risk Origins workshop to assess the new risk origin.
- Strategical information: If strategic details that include new information about a risk origin or the compromise of one of the ecosystem stakeholders by a risk origin is received, the risk assessment is re-executed from the Strategic Scenarios workshop to re-assess stakeholders and re-build strategic scenarios.
- Operational or tactical information: If operational or tactical information that includes new information about a risk origin operations, tactics, or the exploitation of a zero-day vulnerability is received, the risk assessment is re-conducted from the Operational Scenarios workshop to build new scenarios based on the new scope’s context and vulnerabilities.
5. Framework Application
5.1. Scope and Security Baseline
5.2. Threat Intelligence and Assessment/Risk Origins
- RO-01: State-sponsored threat actor with an objective to sabotage Internet connectivity.
- RO-02: State-sponsored threat actor with an objective to perform espionage and spying activities.
- RO-03: Organized crime threat actor with a lucrative objective.
- RO-04: A competitor with an objective of breaching the contracts’ terms in order to gain more clients.
5.3. Strategic Scenarios
- SAP-11: The attack path that can be used by RO-01 by exploiting a zero-day vulnerability to cut off the gateway services, as RO-01 is a threat group known for its capabilities to utilize zero-day vulnerabilities and develop new exploits. The impact of this scenario is assessed as critical.
- SAP-12: The attack path that RO-01 can use through ST-01 to cut off the gateway services, as RO-01 is also known to rely on phishing campaigns and supply chain attack strategies. The impact of this scenario is assessed as critical.
- SAP-21: The attack path that RO-02 can use through SP-02 to perform espionage activities on the international Internet gateway, as RO-02 is a threat group known for software supply chain attacks. The impact of this scenario is assessed as serious.
5.4. Operational Scenarios
- OAP-111: RO-01 scans the public-facing systems and identifies the used technologies. Once a zero-day vulnerability is discovered in one of the secondary systems, RO-01 develops an exploit and gains access to the internal network. After performing an internal reconnaissance, RO-01 moves laterally to reach the gateway and escalates privileges to gain control over the gateway services and its backups. Finally, RO-01 cuts off the gateway services and their backups. The likelihood of this attack path is assessed as likely.
- OAP-112: RO-01 scans the public-facing systems and identifies the used technologies. RO-01 aims at discovering and exploiting zero-day vulnerabilities in the public-facing main gateway systems. After that, RO-01 gains access to the main gateway systems, disables the backup services, and cuts off the international connection. The likelihood of this attack path is assessed as very likely.
- OAP-123: RO-01, knowing that ST-01 is part of the ecosystem, performs identity information gathering on ST-01 staff. Then, it compromises one of the applications used by ST-01 staff (drive by compromise) and sends spear-phishing emails to trick ST-01 users into downloading and executing a backdoor malware. Then, after internal reconnaissance, lateral movement, and privilege escalation, RO-01 reaches the gateway services, disables the backup services, and cuts off the international connection. The likelihood of this attack path is assessed as rather unlikely.
- OAP-214: RO-02, knowing that SP-02 is part of the ecosystem, performs identity information gathering on SP-02 staff. Then, RO-02 sends spear phishing emails to gain access to one of SP-02’s systems. RO-02 deploys spying malware inside one of the administrative software provided by SP-02. After pushing a new update, the new malicious software mirrors network traffic and exfiltrates data. The likelihood of this attack path is assessed as likely.
5.5. Risk Treatment
- R-01: A state-sponsored threat actor sabotages Internet services by exploiting a zero-day vulnerability.
- R-02: A state-sponsored threat actor sabotages Internet services by obtaining access to one of the stakeholders (ST-01).
- R-03: A state-sponsored threat actor sabotages Internet services by obtaining access to one of the stakeholders (SP-02).
- R-04: A state-sponsored threat actor steals information by mirroring the Internet traffic.
5.6. Risk and Threat Monitoring
- Threat Assessment/Risk Origins: The new risk origin (RO-05) is an organized crime group. RO-05 has a lucrative objective to deploy ransomware, hold data captive, and blackmail by re-selling organizations’ data. RO-05 is assessed as highly motivated with significant resources.
- Strategic Scenarios: The ecosystem stakeholders are still the same. However, they are separate since the threat intelligence information specifies that RO-05 relies on a direct attack path. Figure 7 presents the corresponding strategic scenario. The impact of this scenario is assessed as critical since the vulnerability has been proven to exist in the public-facing application.
- Operational Scenarios: Operational threat intelligence about the risk origin reveals the following potential operational scenario; after actively scanning the public-facing systems, RO-05 can identify the used vulnerable application. RO-05 has to develop and customize an exploit and ransomware. After exploitation, a command and control server connection is established to enumerate the internal network and environment. After propagation and lateral movement through internal services, the ransomware is executed. It infects the majority of the internal systems and exfiltrates data through encrypted channels. Then, existing data are encrypted, and a ransom is demanded. Figure 8 presents the operational scenario of the newly identified risk origin. The likelihood of this attack path is assessed as nearly certain.
- Risk Treatment: The newly identified risk (R-05) is that an organized crime can sabotage Internet gateway services for lucrative purposes. To remediate this risk, the treatment plan is modified as follows:
- New treatment TR-08 to implement new rules on the firewall to detect any abuse of the vulnerable services. Priority: high.
- Modify TR-03 priority from medium to high to ensure the detection of anomalies for zero-day vulnerabilities until patches are released.
- Modify TR-05 priority from medium to low since more demanding actions are required.
6. Framework Evaluation
6.1. Enhancements over EBIOS
6.2. Comparative Analysis
6.3. Limitations
7. Conclusions and Future Work
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- IBM. Cost of a Data Breach Report 2023. Available online: https://www.ibm.com/security/digital-assets/cost-data-breach-report/ (accessed on 31 May 2024).
- Shevchenko, P.V.; Jang, J.; Malavasi, M.; Peters, G.W.; Sofronov, G.; Trück, S. The nature of losses from cyber-related events: Risk categories and business sectors. J. Cybersecur. 2023, 9, tyac016. [Google Scholar] [CrossRef]
- Ahmad, A.; Maynard, S.B.; Desouza, K.C.; Kotsias, J.; Whitty, M.T.; Baskerville, R.L. How can organizations develop situation awareness for incident response: A case study of management practice. Comput. Secur. 2021, 101, 102122. [Google Scholar] [CrossRef]
- Verizon. 2024 Data Breach Investigations Report. Available online: https://enterprise.verizon.com/resources/reports/dbir/ (accessed on 31 May 2024).
- Gartner. Forecast: Information Security and Risk Management, Worldwide, 2021–2027, 2Q23 Update. Available online: https://www.gartner.com/en/documents/4488199 (accessed on 31 May 2024).
- Bederna, Z.; Szádeczky, T. Managing the financial impact of cybersecurity incidents. Secur. Def. Q. 2023, 41, 15–35. [Google Scholar] [CrossRef]
- Freeman, C.F.; Lewis, R. Bridging the gap between cyber risk management and cyber threat intelligence. Comput. Secur. 2017, 66, 1–9. [Google Scholar]
- Samtani, S.; Abate, M.; Benjamin, V.; Li, W. Cybersecurity as an industry: A cyber threat intelligence perspective. In The Palgrave Handbook of International Cybercrime and Cyberdeviance; Spinger: Berlin/Heidelberg, Germany, 2020; pp. 135–154. [Google Scholar]
- Mizrak, F. Integrating Cybersecurity Risk Management into Strategic Management: A Comprehensive Literature Review. Res. J. Bus. Manag. 2023, 10, 98–108. [Google Scholar] [CrossRef]
- Kotsias, J.; Ahmad, A.; Scheepers, R. Adopting and integrating cyber-threat intelligence in a commercial organisation. Eur. J. Inf. Syst. 2023, 32, 35–51. [Google Scholar] [CrossRef]
- Akyeşilmen, N. Cybersecurity and Cyberwar: What Everyone Needs to Know. Cyberpolitik J. 2016, 1, 368–372. [Google Scholar]
- Oltsik, J.; Poller, J. Automation and Analytics versus the Chaos of Cybersecurity Operations. ESG MCAFEE 2017.
- Ferreira, D.J.; Mateus-Coelho, N.; Mamede, H.S. Methodology for Predictive Cyber Security Risk Assessment (PCSRA). Procedia Comput. Sci. 2023, 219, 1555–1563. [Google Scholar] [CrossRef]
- Cheimonidis, P.; Rantos, K. Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review. Future Internet 2023, 15, 324. [Google Scholar] [CrossRef]
- Giuca, O.; Popescu, T.M.; Popescu, A.M.; Prostean, G.; Popescu, D.E. A Survey of Cybersecurity Risk Management Frameworks. In Proceedings of the International Workshop Soft Computing Applications; Springer: Berlin/Heidelberg, Germany, 2018; pp. 240–272. [Google Scholar]
- Ionita, D. Current Established Risk Assessment Methodologies and Tools. Master’s Thesis, University of Twente, Enschede, The Netherlands, 2013. [Google Scholar]
- Lambrinoudakis, C.; Gritzalis, S.; Xenakis, C.; Katsikas, S.; Karyda, M.; Tsochou, A.; Papadatos, K.; Rantos, K.; Pavlosoglou, Y.; Gasparinatos, S.; et al. Compendium of Risk Management Frameworks with Potential Interoperability: Supplement to the Interoperable EU Risk Management Framework Report; European Union Agency for Cybersecurity (ENISA): Athens, Greece, 2022.
- ISO/IEC 27005: 2018; Information Technology. Security Techniques. Information Security Risk Management. International Organization for Standardization: Geneva, Switzerland, 2018.
- Initiative, J.T.F.T. Guide for Conducting Risk Assessments; Technical Report NIST SP 800-30r1; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2012. [CrossRef]
- Caralli, R.; Stevens, J.; Young, L.; Wilson, W. Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process; Technical Report CMU/SEI-2007-TR-012; Software Engineering Institute, Carnegie Mellon University: Pittsburgh, PA, USA, 2007. [Google Scholar]
- Agence Nationale de la Sécurité des Systèmes d’Information. La Méthode EBIOS Risk Manager—Le Guide; Technical Report ANSSI-PA-048-EN; Agence Nationale de la Sécurité des Systèmes d’Information: Paris, France, 2019. [Google Scholar]
- Mathey, F.; Bonhomme, C.; Rocha, J.; Lombardi, J.; Joly, B. Risk Assessment Optimisation with MONARC. Available online: https://www.monarc.lu/assets/files/publications/2018-HACK.LU-CASES.pdf (accessed on 31 May 2024).
- BSI-Standard 200-2: IT-Grundschutz-Methodology. Available online: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi-standard-2002_en_pdf.html (accessed on 4 February 2023).
- European Commission Directorate-General for Communication. Security Standards Applying to All European Commission Information Systems: EU ITSRM, IT Security Risk Management Methodology V1.2. 2020. Available online: https://ec.europa.eu/info/publications/security-standards-applying-all-european-commission-information-systems_en (accessed on 31 May 2024).
- Information Security Forum. Security Standards Applying to All European Commission, ISF, Information RISK Assessment Methodology 2 (IRAM2). Available online: https://www.securityforum.org/solutions-and-insights/information-risk-assessment-methodology-2-iram2/ (accessed on 31 May 2024).
- Brunner, M.; Sillaber, C.; Breu, R. Towards automation in information security management systems. In Proceedings of the 2017 IEEE International Conference on Software Quality, Reliability and Security (QRS), Prague, Czech Republic, 25–29 July 2017; pp. 160–167. [Google Scholar]
- Schmitz, C.; Pape, S. LiSRA: Lightweight security risk assessment for decision support in information security. Comput. Secur. 2020, 90, 101656. [Google Scholar] [CrossRef]
- Akinrolabu, O.; New, S.; Martin, A. CSCCRA: A Novel Quantitative Risk Assessment Model for SaaS Cloud Service Providers. Computers 2019, 8, 66. [Google Scholar] [CrossRef]
- Poletykin, A. Cyber security risk assessment method for SCADA of industrial control systems. In Proceedings of the 2018 International Russian Automation Conference (RusAutoCon), Sochi, Russia, 9–16 September 2018; pp. 1–5. [Google Scholar]
- Lee, I. Internet of Things (IoT) cybersecurity: Literature review and IoT cyber risk management. Future Internet 2020, 12, 157. [Google Scholar] [CrossRef]
- Ma, S.; Hao, W.; Dai, H.N.; Cheng, S.; Yi, R.; Wang, T. A Blockchain-Based Risk and Information System Control Framework. In Proceedings of the 2018 IEEE 16th Intl Conf on Dependable, Autonomic and Secure Computing, 16th Intl Conf on Pervasive Intelligence and Computing, 4th Intl Conf on Big Data Intelligence and Computing and Cyber Science and Technology Congress (DASC/PiCom/DataCom/CyberSciTech), Athens, Greece, 12–15 August 2018; pp. 106–113. [Google Scholar] [CrossRef]
- El Amin, H.; Oueidat, L.; Chamoun, M.; Samhat, A.E.; Feghali, A. Blockchain-based multi-organizational cyber risk management framework for collaborative environments. Int. J. Inf. Secur. 2023, 23, 1231–1249. [Google Scholar] [CrossRef]
- Shin, B.; Lowry, P.B. A review and theoretical explanation of the ‘Cyberthreat-Intelligence (CTI) capability’ that needs to be fostered in information security practitioners and how this can be accomplished. Comput. Secur. 2020, 92, 101761. [Google Scholar] [CrossRef]
- Hutchins, E.M.; Cloppert, M.J.; Amin, R.M. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Lead. Issues Inf. Warf. Secur. Res. 2011, 1, 80. [Google Scholar]
- Caltagirone, S.; Pendergast, A.; Betz, C. The diamond model of intrusion analysis. Threat Connect 2013, 298, 1–61. [Google Scholar]
- Bianco, D. The Pyramid of Pain. 2013. Available online: https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html (accessed on 31 May 2024).
- Strom, B.E.; Applebaum, A.; Miller, D.P.; Nickels, K.C.; Pennington, A.G.; Thomas, C.B. Mitre Att&ck: Design and Philosophy; Technical report; The MITRE Corporation: McLean, VA, USA, 2018. [Google Scholar]
- Barnum, S. Standardizing Cyber Threat Intelligence Information with the Structured Threat Information Expression (Stix); MITRE Corporation: McLean, VA, USA, 2012; Volume 11, pp. 1–22. [Google Scholar]
- Connolly, J.; Davidson, M.; Schmidt, C. The Trusted Automated Exchange of Indicator Information (Taxii); The MITRE Corporation: McLean, VA, USA, 2014; pp. 1–20. [Google Scholar]
- Filigran—OpenCT—Open Platform for Cyber Threat Intelligence. Available online: https://www.filigran.io/en/products/opencti/ (accessed on 4 February 2023).
- Wagner, C.; Dulaunoy, A.; Wagener, G.; Iklody, A. Misp: The design and implementation of a collaborative threat intelligence sharing platform. In Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security, Vienna, Austria, 24 October 2016; pp. 49–56. [Google Scholar]
- Army, A. Land Warfare Doctrine LWD 2-0 intelligence; The Australian Government Department of Defence: Canberra, Australia, 2014.
- Haji, S.; Tan, Q.; Costa, R.S. A Hybrid Model for Information Security Risk Assessment. Int. J. Adv. Trends Comput. Sci. Eng. 2019, 8, 100–106. [Google Scholar] [CrossRef]
- Ahmed, M.; Panda, S.; Xenakis, C.; Panaousis, E. MITRE ATT&CK-driven cyber risk assessment. In Proceedings of the 17th International Conference on Availability, Reliability and Security, Vienna, Austria, 23–26 August 2022; pp. 1–10. [Google Scholar]
- Lyvas, C.; Maliatsos, K.; Menegatos, A.; Giannakopoulos, T.; Lambrinoudakis, C.; Kalloniatis, C.; Kanatas, A. A hybrid dynamic risk analysis methodology for cyber-physical systems. In Proceedings of the European Symposium on Research in Computer Security; Springer: Berlin/Heidelberg, Germany, 2022; pp. 134–152. [Google Scholar]
- Belfadel, A.; Boyer, M.; Letailleur, J.; Petiot, Y.; Yaich, R. Towards a Security Impact Analysis Framework: A Risk-Based and MITRE Attack Approach. In Proceedings of the European Symposium on Research in Computer Security; Springer: Berlin/Heidelberg, Germany, 2022; pp. 212–227. [Google Scholar]
- Kure, H.; Islam, S. Cyber threat intelligence for improving cybersecurity and risk management in critical infrastructure. J. Univers. Comput. Sci. 2019, 25, 1478–1502. [Google Scholar]
- Janiszewski, M.; Felkner, A.; Lewandowski, P. A novel approach to national-level cyber risk assessment based on vulnerability management and threat intelligence. J. Telecommun. Inf. Technol. 2019, 2, 5–14. [Google Scholar] [CrossRef]
- Dekker, M.; Alevizos, L. A Threat-Intelligence Driven Methodology to Incorporate Uncertainty in Cyber Risk Analysis and Enhance Decision Making. arXiv 2023, arXiv:2302.13082. [Google Scholar] [CrossRef]
- Hevner, A.R.; March, S.T.; Park, J.; Ram, S. Design science in information systems research. MIS Q. 2004, 28, 75–105. [Google Scholar] [CrossRef]
- Alnajim, O.A.; Kautzman, D.M. Towards a conceptual cyber risk assessment framework for healthcare systems. Procedia Comput. Sci. 2017, 121, 785–792. [Google Scholar]
- Buczak, A.L.; Guven, E. A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutor. 2016, 18, 1153–1176. [Google Scholar] [CrossRef]
- ANSSI. EBIOS Risk Manager: Going Further; Technical Report; ANSSI: Paris, France, 2019; Version 1.0.
- Abbass, W.; Baina, A.; Bellafkih, M. Using EBIOS for risk management in critical information infrastructure. In Proceedings of the 2015 5th World Congress on Information and Communication Technologies (WICT), Marrakech, Morocco, 14–16 December 2015; pp. 107–112. [Google Scholar]
- Zahra, B.F.; Abdelhamid, B. Risk analysis in Internet of Things using EBIOS. In Proceedings of the 2017 IEEE 7th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA, 9–11 January 2017; pp. 1–7. [Google Scholar]
Framework | Novelty | Risk Assessment | Threat Assessment | Risk and Threat Monitoring | Integration of Cyber Threat Intelligence | Type of Cyber Threat Intelligence | Capability to Adjust Based on Cyber Threat Information |
---|---|---|---|---|---|---|---|
EBIOS [21] | Workshop-based cyber risk assessment with strategic and operational risk scenarios | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ |
Hybrid Model for Risk Assessment [43,44] | Systematic integration of threat assessment in the cyber risk assessment | ✓ | ✓ | ✗ | ✗ | ✗ | ✗ |
Hybrid Dynamic Risk Analysis [45] | Hybrid dynamic risk analysis to automatically assign new vulnerabilities to assets and evaluate the impact of successful exploitation for cyber–physical systems | ✓ | ✓ | ✗ | ✗ | Technical | ✓ |
SAIF [46] | Integration of a risk-based analysis approach based on EBIOS with the MITRE knowledge base to automate the security impact analysis | ✓ | ✓ | ✗ | ✓ | Strategic, Operational, Technical | ✗ |
Unified Approach [47] | Integrate threat intelligence in cyber risk management focusing on critical infrastructure | ✓ | ✓ | ✗ | ✓ | Operational and Technical | ✗ |
Novel Approach to National-level Cyber Risk Assessment [48] | Evaluation of risk based on technical information with national vulnerability visibility | ✓ | ✗ | ✗ | ✓ | Technical | ✓ |
TIBSA [49] | A cyber threat intelligence driven methodology providing practical guidance for information security leaders to make informed decisions in uncertain situations | ✗ | ✓ | ✓ | ✓ | ✗ | ✓ |
Our proposed framework based on EBIOS | Integration of threat intelligence in cyber risk management with adaption based on new intelligence for critical infrastructure | ✓ | ✓ | ✓ | ✓ | Strategic, Tactical, Operational, and Technical | ✓ |
Scale | Consequences |
---|---|
G4 Critical | Inability of the organization to deliver connectivity services, with possible serious impacts on the safety of assets. The organization will most likely not overcome the situation (its survival is threatened). |
G3 Serious | High degradation in the performance of the connectivity services, with possible significant impacts on the safety of assets and reputation. The organization will overcome the situation with serious difficulties but with impact on its image (operations in a highly degraded mode). |
G2 Significant | Degradation in the performance of the Internet connectivity services, with no impact on the safety of assets. The organization will overcome the situation despite a few difficulties (operations in degraded mode). |
G1 Minor | No impact on operations or the performance of the Internet connectivity services or on the safety of assets. The organization will overcome the situation without too many difficulties (margins will be consumed). |
Scale | Description |
---|---|
V4 Nearly certain | The risk origin will certainly reach its target objective by one of the considered methods of attack. The likelihood of the scenario is very high. |
V3 Very likely | The risk origin will probably reach its target objective by one of the considered methods of attack. The likelihood of the scenario is high. |
V2 Likely | The risk origin could reach its target objective by one of the considered methods of attack. The likelihood of the scenario is significant. |
V1 Rather unlikely | The risk origin has little chance of reaching its objective by one of the considered methods of attack. The likelihood of the scenario is low. |
Mission | International Internet Services | ||||
---|---|---|---|---|---|
Business asset | International Internet services | Transport network services | Contract management | ||
Nature of the asset | Process | Process | Process | ||
Description | Ensure Internet connectivity with the peer international gateways through applying secure and compliant policies and processes matching the international standards and recommendations. This includes: - Router configuration and maintenance - IP assignment and management tables - Access credentials | Ensure that all the physical connectivities are operational and protected topology-wise and hardware-redundancy-wise. This includes: - Equipment configuration - Equipment interconnectivity | Manage, monitor, and control of network performance compliance with the terms and conditions of SLAs signed. | ||
Responsible entity | Network and IT Departments | Network Department | Management and IT Departments | ||
Supporting asset | Network Equipment | Safety and Physical Security | Fiber-Optic Components | Partnership Agreements | SLA Contracts |
Description | Ensure gateway connectivity, security, and availability. This includes: - Firewalls - Media gateway - Routers - Switches | Processes and devices in place to ensure the service operational, functional, and physical safety. This includes: - Backup electric power sources - Surveillance system - Access control and notification system - Fire safety system | Fiber-optic components configuration, operations, and maintenance management | All partnership agreements with internal and external stakeholders. | Ensuring all service-level agreements management are met and satisfied by monitoring and managing all required components. |
Entity in charge | Equipment Suppliers and External Private Contractor | Safety and Security Department | Equipment Suppliers and Network Department | Management Department and External Private Contractor | Management Department and External Private Contractor |
Business Asset | Feared Events | Categories of Impact | Severity |
---|---|---|---|
International Internet services | Total physical destruction of network gateway components, leading to a total cut-off from the Internet | Mission, Equipment, Human, Governance, Financial, Legal, Image, and Trust | G4 |
Manipulation of network components configuration, leading to a total loss of traffic | Mission, Financial, Legal, Image, and Trust | G3 | |
Hijacking the network components, leading to a total disruption in the network traffic | Mission, Financial, Legal, Image, and Trust | G3 | |
Transport network services | Total physical destruction of the fiber-optic network, leading to a total cut-off from the Internet | Mission, Equipment, Human, Governance Financial, Legal, Image, and Trust | G4 |
Mirroring of traffic to perform espionage and spying acts | Governance, Financial, Legal, Image, and Trust | G3 | |
Contracts management | Breaching of contracts terms and conditions | Mission, Financial, Legal, Image, and Trust | G3 |
Reference | Type | Target Objectives (TOs) | Motivation | Resources |
---|---|---|---|---|
RO-01 | State Sponsored | Sabotage Internet connectivity | Highly motivated | Unlimited |
RO-02 | State Sponsored | Espionage and spying activities | Highly motivated | Unlimited |
RO-03 | Organized Crime | Disrupt Internet connectivity for lucrative purposes | Rather motivated | Significant |
RO-04 | Competitor | Breach contracts’ terms and conditions along with the service-level agreements to reduce competition | Rather motivated | Significant |
ID | Category | Stakeholder | Role | Dependency | Penetration | Maturity | Trust | Exposure | Cyber Reliability | Threat Level |
---|---|---|---|---|---|---|---|---|---|---|
PR-01 | Equipment Supplier | Network gateway provider | Provides routing solutions | 3 | 4 | 3 | 3 | 12 | 9 | 1.33 |
PR-02 | Equipment Supplier | Fiber-optic equipment provider | Provides transmission connectivity | 3 | 4 | 3 | 3 | 12 | 6 | 1.33 |
PR-03 | Equipment Supplier | Security equipment supplier | Provides network security and protection products | 3 | 3 | 3 | 2 | 9 | 6 | 1.50 |
PR-04 | Equipment Supplier | Access control and surveillance supplier | Provides access control, logging, and monitoring to sites | 2 | 2 | 3 | 2 | 4 | 6 | 0.67 |
SP-01 | Service Provider | External service provider | Provides external Internet services | 3 | 1 | 3 | 3 | 3 | 9 | 0.33 |
SP-02 | Service Provider | Cable provider | Provides fiber connectivity | 4 | 3 | 2 | 2 | 12 | 4 | 3.00 |
CL-01 | Client | Internet service provider | Clients | 1 | 1 | 3 | 2 | 1 | 6 | 0.17 |
CL-02 | Client | Governmental agencies | Clients | 1 | 1 | 2 | 3 | 1 | 6 | 0.17 |
ST-01 | Staff | External staff | Staff members | 3 | 4 | 2 | 3 | 12 | 6 | 2.00 |
ID | Risk | Likelihood | Impact |
---|---|---|---|
R-01 | A state-sponsored threat actor sabotages Internet services by exploiting a zero-day vulnerability. | V2 | G4 |
R-02 | A state-sponsored threat actor sabotages Internet services by obtaining the access of one of stakeholders (ST-01). | V3 | G4 |
R-03 | A state-sponsored threat actor sabotages Internet services by obtaining the access of one of stakeholders (SP-02). | V1 | G4 |
R-04 | A state-sponsored threat actor steals information by mirroring the Internet traffic. | V2 | G3 |
ID | Treatment | Affected Risks | Priority |
---|---|---|---|
TR-01 | Establish proper incident response, cyber crisis management, and business continuity procedures. | All | High |
TR-02 | Perform regular penetration tests on a yearly basis. | All | Medium |
TR-03 | Implement security information event management (SIEM) solution along with a security operations center (SOC). | All | Medium |
TR-04 | Require stakeholders to raise cybersecurity awareness among employees. | R-03 | Medium |
TR-05 | Establish a change management policy. | R-04 | Medium |
TR-06 | Enhance the efficiency of vulnerability management and patch management processes already in place. | R-01, R-02 | Low |
TR-07 | Implement a privilege access management (PAM) solution to better control user accesses. | R-01, R-04 | Low |
Workshop | Proposed Enhancements |
---|---|
Scope and Security Baseline | Determination of the necessary cyber threat intelligence information. |
Threat Assessment Risk Origins | Relevant threats identification and assessment based on threat intelligence information. |
Strategic Scenarios | Strategic scenarios built based on the organization context, stakeholders, and the identified threats and their corresponding strategic threat intelligence information. |
Operational Scenarios | Operational scenarios built based on the organization context, vulnerabilities, and the identified threats and their corresponding operational and technical threat intelligence information. |
Risk Treatment | Same as EBIOS. |
Risks and Threat Monitoring | Newly introduced workshop. Timely and agile re-execution of the risk management process based on new threat intelligence information. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
El Amin, H.; Samhat, A.E.; Chamoun, M.; Oueidat, L.; Feghali, A. An Integrated Approach to Cyber Risk Management with Cyber Threat Intelligence Framework to Secure Critical Infrastructure. J. Cybersecur. Priv. 2024, 4, 357-381. https://doi.org/10.3390/jcp4020018
El Amin H, Samhat AE, Chamoun M, Oueidat L, Feghali A. An Integrated Approach to Cyber Risk Management with Cyber Threat Intelligence Framework to Secure Critical Infrastructure. Journal of Cybersecurity and Privacy. 2024; 4(2):357-381. https://doi.org/10.3390/jcp4020018
Chicago/Turabian StyleEl Amin, Habib, Abed Ellatif Samhat, Maroun Chamoun, Lina Oueidat, and Antoine Feghali. 2024. "An Integrated Approach to Cyber Risk Management with Cyber Threat Intelligence Framework to Secure Critical Infrastructure" Journal of Cybersecurity and Privacy 4, no. 2: 357-381. https://doi.org/10.3390/jcp4020018
APA StyleEl Amin, H., Samhat, A. E., Chamoun, M., Oueidat, L., & Feghali, A. (2024). An Integrated Approach to Cyber Risk Management with Cyber Threat Intelligence Framework to Secure Critical Infrastructure. Journal of Cybersecurity and Privacy, 4(2), 357-381. https://doi.org/10.3390/jcp4020018