Cybersecurity assessment method for ship assets and computing device for performing same
In a cybersecurity assessment method for ship assets, a risk level of each asset on a ship is automatically evaluated using asset-related information as input, and for an asset whose risk level exceeds a preset threshold, a security-control configuration set is generated and output. Accordingly, even when assets on the ship or network configurations change, a risk state can be rapidly re-evaluated and necessary security measures can be consistently derived.
1 . A method performed by a computing device comprising one or more processors and a memory storing one or more programs to be executed by the one or more processors, the method comprising:
obtaining asset inventory data comprising asset-related information for each asset existing in a ship that is a target of cybersecurity assessment, the asset inventory data comprising at least one of identification information of an asset, network-connection information, network-interface information, an installation location of the asset, an operating system (OS) version, a firmware version, a software version, a communication protocol, an IP/MAC address, a certificate, and an update log;
verifying whether any required field is missing in the asset inventory data and normalizing the asset-related information by converting the asset inventory data into a preset standard format;
for each asset, automatically calculating a basic assessment-factor index comprising a complexity index, a connectivity index, and a threat index by inputting the asset-related information into an algorithm or rule set defined for each basic assessment factor;
calculating, based on the calculated complexity index, connectivity index, and threat index, security-factor scores comprising a Confidentiality score, an Integrity score, and an Availability score;
calculating, for each asset, a vulnerability index based on user answers to a vulnerability checklist for assets on the ship;
evaluating a risk level of each asset on the ship based on the basic assessment-factor index, the security-factor scores, and the vulnerability index;
generating, for an asset whose risk level exceeds a preset threshold, a security-control configuration set comprising at least one of a network segmentation policy, an access control list (ACL), a firewall rule, a monitoring target, and hardening configuration items; and
transmitting the security-control configuration set to a security management system of the ship.
2 . The method of claim 1 , wherein calculating the security-factor scores comprises:
expressing each of the Confidentiality score, the Integrity score, and the Availability score as a weighted sum of the complexity index, the connectivity index, and the threat index;
applying a first weight to the complexity index, applying a second weight to the connectivity index, and applying a third weight to the threat index; and
setting the first weight, the second weight, and the third weight differently for the calculation of the Confidentiality score, the Integrity score, and the Availability score.
3 . The method of claim 2 , wherein:
for the calculation of the Confidentiality score, the weights are set in an order of second weight>first weight>third weight;
for the calculation of the Integrity score, the weights are set in an order of third weight>second weight>first weight; and
for the calculation of the Availability score, the third weight is higher than the first weight and the second weight.
4 . The method of claim 2 , further comprising:
collecting event logs related to incidents, failures, and pre-incident indicators occurring in each asset during operation of the ship;
estimating correlation coefficients between types of security factors and the basic assessment-factor indices based on the collected event logs; and
automatically calibrating, as operating data accumulates, sensitivity of security-factor score calculation by adjusting the first weight, the second weight, and the third weight based on the estimated correlation coefficients.
5 . The method of claim 1 , wherein the automatically calculating of the complexity index comprises:
determining whether the asset-related information comprises software-related information of the asset;
when the asset-related information comprises the software-related information, determining whether the asset-related information comprises external-network connection information;
when the asset-related information comprises the external-network connection information, setting the complexity index for the asset to a third level;
when the asset-related information does not comprise the software-related information, determining whether the asset-related information comprises network-connection information;
when the asset-related information does not comprise the network-connection information, setting the complexity index for the asset to a first level; and
when the asset-related information comprises the network-connection information but the network-connection information is not external-network connection information, setting the complexity index for the asset to a second level.
6 . The method of claim 1 , wherein the calculating of the connectivity index comprises:
determining, based on the asset-related information, whether the asset is connected to an untrusted network;
when the asset is connected to the untrusted network, setting the connectivity index for the asset to a fifth level;
when the asset is not connected to the untrusted network, determining whether the asset is connected to another trusted network;
when the asset is not connected to the other trusted network, setting the connectivity index for the asset to a first level;
when the asset is connected to the other trusted network, when a physical interface connected to the other trusted network is serial-based communication, setting the connectivity index for the asset to a second level; and
when the physical interface connected to the other trusted network is Ethernet-based communication, when a destination address of the Ethernet-based communication is an internal-range IP address, setting the connectivity index for the asset to a third level, and when the destination address is an external-range IP address, setting the connectivity index for the asset to a fourth level.
7 . The method of claim 1 , wherein the calculating of the threat index comprises:
classifying, based on the asset-related information, a functional group of each asset on the ship;
classifying, based on the asset-related information, a control level of each asset;
classifying, based on the asset-related information, whether each asset is risk-linked; and
calculating the threat index of each asset based on the functional group, the control level, and whether the asset is risk-linked.
8 . The method of claim 1 , further comprising:
providing, based on the vulnerability checklist, a list of protective measures applicable by a user;
re-evaluating the risk level of the asset by reflecting, when a protective measure is applied, a risk-reduction score assigned to the protective measure; and
updating and outputting the security-control configuration set based on a result of the re-evaluating.
9 . The method of claim 8 , further comprising determining an application priority among protective measures included in the list of protective measures, wherein the application priority is determined based on at least one of an implementation cost, urgency, and difficulty for each protective measure.
10 . The method of claim 9 , wherein the determining of the application priority comprises:
assigning a first priority score according to an implementation cost of each protective measure;
assigning a second priority score according to urgency of each protective measure;
assigning a third priority score according to difficulty of each protective measure; and
summing the first, second, and third priority scores for each protective measure to obtain a total priority score and determining the application priority according to the total priority score.
11 . A computing device comprising:
a processor; and
a memory storing one or more programs to be executed by the processor,
wherein, when executed, the one or more programs cause the processor to:
obtain asset inventory data comprising asset-related information for each asset existing in a ship that is a target of cybersecurity assessment, the asset inventory data comprising at least one of identification information of an asset, network-connection information, network-interface information, an installation location of the asset, an operating system (OS) version, a firmware version, a software version, a communication protocol, an IP/MAC address, a certificate, and an update log;
verify whether any required field is missing in the asset inventory data and normalize the asset-related information by converting the asset inventory data into a preset standard format;
for each asset, automatically calculate a basic assessment-factor index comprising a complexity index, a connectivity index, and a threat index by inputting the asset-related information into an algorithm or rule set defined for each basic assessment factor;
calculate, based on the calculated complexity index, connectivity index, and threat index, security-factor scores comprising a Confidentiality score, an Integrity score, and an Availability score;
calculate, for each asset, a vulnerability index based on user answers to a vulnerability checklist for assets on the ship;
evaluate a risk level of each asset on the ship based on the basic assessment-factor index, the security-factor scores, and the vulnerability index;
generate, for an asset whose risk level exceeds a preset threshold, a security-control configuration set comprising at least one of a network segmentation policy, an access control list (ACL), a firewall rule, a monitoring target, and hardening configuration items; and
transmit the security-control configuration set to a security management system of the ship.
12 . A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors of a computing device, cause the computing device to:
obtain asset inventory data comprising asset-related information for each asset existing in a ship that is a target of cybersecurity assessment, the asset inventory data comprising at least one of identification information of an asset, network-connection information, network-interface information, an installation location of the asset, an operating system (OS) version, a firmware version, a software version, a communication protocol, an IP/MAC address, a certificate, and an update log;
verify whether any required field is missing in the asset inventory data and normalize the asset-related information by converting the asset inventory data into a preset standard format;
for each asset, automatically calculate a basic assessment-factor index comprising a complexity index, a connectivity index, and a threat index by inputting the asset-related information into an algorithm or rule set defined for each basic assessment factor;
calculate, based on the calculated complexity index, connectivity index, and threat index, security-factor scores comprising a Confidentiality score, an Integrity score, and an Availability score;
calculate, for each asset, a vulnerability index based on user answers to a vulnerability checklist for assets on the ship;
evaluate a risk level of each asset on the ship based on the basic assessment-factor index, the security-factor scores, and the vulnerability index;
generate, for an asset whose risk level exceeds a preset threshold, a security-control configuration set comprising at least one of a network segmentation policy, an access control list (ACL), a firewall rule, a monitoring target, and hardening configuration items; and
transmit the security-control configuration set to a security management system of the ship.