Accurate Attack Preventing System Implementation in Grids
Vishal Sharma, Raman Batra, A Prabhu · 2023
A comprehensive approach to the ongoing and numerical evaluation of cyber risks in conditions involving Internet of the circumstances (IoT)-based electrical power systems, where attempts and protection may target different components, is lacking, despite the long history of risk assessment in a tool for helping decision-making in security investments. This study presents a comprehensive approach that continually evaluates cyber threats to help decision makers make well-informed security protection choices for smart grid systems. The suggested approach focuses on using attack-defense trees that are modeled after the system in conjunction with risk attribute calculation. This method propagates the risk characteristics across the tree nodes, enabling the evaluation of system hazards. By analyzing the sensitivity of system risk to different attack and defensive scenarios, the technique helps to optimize security measures and reduce risks. In order to facilitate security certifications, it promotes the adoption of common security and privacy protection taxonomies from internationally recognized privacy and security control families, which include NIST SP 800–53. The article describes the use of the approach in a real-world smart construction energy-efficiency scenario, integrating many components distributed in IoT and cloud resources, in order to verify it. The scenario that is being described shows that the approach is feasible not only in initial quantitative risk calculations but also for ongoing risk assessment updates based on system operating circumstances.