Abstract
Cyber-attacks on power-related IT and OT infrastructures can have disastrous consequences for individuals, regions, as well as whole nations. In order to respond to these threats, the cyber security assessment of IT and OT infrastructures can foster a higher degree of safety and resilience against cyber-attacks. Therefore, the use of attack simulations based on system architecture models is proposed. To reduce the effort of creating new attack graphs for each system under assessment, domain-specific languages (DSLs) can be employed. DSLs codify the common attack logics of the considered domain. Previously, MAL (the Meta Attack Language) was proposed, which serves as a framework to develop DSLs and generate attack graphs for modeled infrastructures. In this article, powerLang as a MAL-based DSL for modeling IT and OT infrastructures in the power domain is proposed. Further, it allows analyzing weaknesses related to known attacks. To comprise powerLang, two existing MAL-based DSL are combined with a new language focusing on industrial control systems (ICS). Finally, this first version of the language was validated against a known cyber-attack.
Author supplied keywords
Cite
CITATION STYLE
Hacks, S., Katsikeas, S., Ling, E., Lagerström, R., & Ekstedt, M. (2020). powerLang: a probabilistic attack simulation language for the power domain. Energy Informatics, 3(1). https://doi.org/10.1186/s42162-020-00134-4
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.