IP Library Granted Patent US 12,309,188
Granted Patent B1
US 12,309,188 · App. 17/301,606 · Granted May 20, 2025

Cybersecurity algorithms and tools for supervisory control and data acquisition and industrial control systems

Inventors: Alaa Al Ghazo (Port Jefferson, NY); Ratnesh Kumar (Ames, IA)
Assignee: Iowa State University Research Foundation, Inc.
H04L63/1433G06N7/01H04L41/14H04L63/1425H04L63/1441H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,188
App. No.
17/301,606
Granted
May 20, 2025
Kind
B1
Abstract

A hybrid approach involving the mix of communication patterns and passive fingerprinting is used to identify unknown device types, manufacturers, and models of devices of digital control systems. ANDVI implementation maps the identified devices to their known vulnerabilities. According to one example, to identify how interdependence among existing atomic vulnerabilities may be exploited by an adversary to stitch together an attack that can compromise the system, model-checking based A2G2V is employed. According to another example, an A2G2V algorithm uses existing model-checking tools, an architecture description tool, and code to generate an attack-graph that enumerates the set of all possible sequences in which atomic-level vulnerabilities can be exploited to compromise system security. In yet another example, identification of label-cuts within an attack-graph automatically identifies a set of critical-attacks that, when blocked, renders the system secure. A linear complexity approximation utilizing SCCs helps identify the minimum label-cut representing a critical-attacks set.

Claims (55)

1. A method of providing security in a control system that communicates between a plurality of devices connected to a non-isolated network utilizing a communications protocol, said communications protocol implemented at least in part with data packets each having a header and user data, the method comprising:

a. automatically identifying said devices and security vulnerabilities by:

i. analyzing a communication pattern in the non-isolated network to identify control hierarchy in the network to infer device type of one or more of the plurality of devices;

ii. generating a passive fingerprint for the devices in the non-isolated network by capturing network traffic and analyzing transmitted data packet headers in the network traffic to discriminate between the devices for device recognition by type, manufacturer, and model;

iii. comparing passive fingerprints of unknown devices to a database storing fingerprints of devices with known identities;

iv. using the generated passive fingerprints to identify placement of the devices in the non-isolated network to further discriminate between the devices; and

v. scanning individual devices for said security vulnerabilities based upon an identified type, manufacturer, and/or model of the individual devices.

2. The method of claim 1 further comprising:

b. automatically scanning the control system for global vulnerabilities by:

i. constructing an attack-graph by:

1. utilizing an architecture description language capable of describing:

a. said devices,

b. connectivity of said devices,

c. digital aspects of the control system, and

d. device-level atomic attacks;

2. generating attack-paths in the form of counterexamples;

3. iteratively searching the generated attack-paths to enumerate all acyclic counterexamples; and

4. generating the attack-graph with each attack-path from source to terminal;

ii. identifying with the attack-graph a set of all sequences of atomic attacks exploiting device vulnerability that may compromise the control system.

3. The method of claim 2 further comprising:

c. automatically generating a global vulnerability resolution by analyzing the attack-graphs to identify a minimal number of critical atomic attacks that need to be prevented by:

i. creating an abstract version of the attack-graphs from strongly-connected components (SCCs) of the attack-graphs; and

ii. performing an iterative backward search of the abstract version to find backward-accessible SCCs along with the outgoing edge.

4. The method of claim 1 wherein the communications protocol is Transmission Control Protocol/Internet Protocol (TCP/IP) and the analyzing of the communication pattern comprises extraction of data from a TCP/IP packet.

5. The method of claim 1 wherein the packets have one or more features and the step of analyzing of a communication pattern comprises monitoring the packets for the one or more features, wherein the one or more features allows for identification of the control hierarchy.

6. The method of claim 5 wherein the one or more features of the packets include an indication of a unique device based on its manufacturer's settings, and the step of analyzing comprises comparing the one or more features to a device reference database.

7. The computerized method of claim 1 wherein the passive fingerprints are stored in a feature matrix which is compared to a database of manufacturers and models of devices.

8. The method of claim 7 wherein the communications protocol comprises communication packets for SCADA/ISC and the features matrix includes one or more features comprising

time to live (TTL),

difference in IP.IDs of two consecutive packets (IP.ID diff ), and

vendor MAC ID (Vendor MAC ).

9. The method of claim 1 wherein the fingerprinting comprises an offline learning stage in which information from device manufacturer datasheets are used to create a reference fingerprint database, and an online recognition stage that captures communication packets from the network, extracts information to create passive fingerprints for unknown devices, and compares the created passive fingerprints to the fingerprints' reference database obtained during the learning stage to identify the devices.

10. The method of claim 1 wherein the fingerprints are augmented with control hierarchy information for refinement/confirmation of the passive fingerprinting.

11. The method of claim 1 wherein the devices are SCADA devices where packets do not travel beyond parent node level and data collection is between a parent/child hierarchy level of each device, and passive fingerprinting minimizes the number of data collection points by collection data at routers rather than at devices.

12. The method of claim 1 wherein the method proceeds in a bottom up fashion by identifying bottom-most devices of the control hierarchy.

13. A computerized method comprising:

a. automatically identifying devices in a non-isolated network by:

i. analyzing a communication pattern in the non-isolated network to identify control hierarchy in the network to infer device type of one or more of the plurality of devices;

ii. generating a passive fingerprint for the devices in the non-isolated network by capturing network traffic and analyzing transmitted data packet headers in the network traffic to discriminate between the devices;

iii. comparing passive fingerprints of unknown devices to a database storing fingerprints of devices with known identities; and

iv. using the generated passive fingerprints to identify placement of the devices in the non-isolated network to further discriminate between the devices and to determine an identified type, manufacturer, and/or model of the unknown devices.

14. The computerized method of claim 13 further comprising automatically scanning the devices for global vulnerabilities based upon the identified type, manufacturer, and/or model.

15. The computerized method of claim 13 further comprising resolving said global vulnerabilities to secure the network and the devices.

16. A computerized method comprising:

a. first identifying type, manufacturer, and/or model of devices in a non-isolated network by:

i. analyzing a communication pattern in the non-isolated network to identify control hierarchy in the network to infer device type of one or more of the devices; and

b. discriminating and/or comparing

i. passive fingerprints generated for unknown devices and fingerprints stored in a database relating to known devices.

17. The computerized method of claim 16 further comprising resolving said global vulnerabilities to secure the network and the devices.

18. A computerized method comprising:

automatically generating a global vulnerability resolution by analyzing attack-graphs to identify a minimal number of critical atomic attacks that need to be prevented by:

i. creating an abstract version of the attack-graphs from strongly connected components (SCCs) of the attack-graphs having a set of vertexes and a set of edges that connect a vertex to another; and

ii. performing an iterative backward search of the abstract version to find backward-accessible SCCs along with an outgoing edge of the set of edges.

19. The computerized method of claim 18 further comprising first identifying a type, manufacturer, and/or model of the devices by analyzing a communication pattern in the non-isolated network and discriminating and/or comparing between passive fingerprints generated for unknown devices and fingerprints stored in a database relating to known devices.

20. The computerized method of claim 19 further comprising scanning the devices for global vulnerabilities based upon the identified type, manufacturer, and/or model.

Assignments (1)
CONFIRMATORY LICENSE Recorded Dec 12, 2024
From: IOWA STATE UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 069618/0062 →
Continuity (1)
Provisional Application 63007173 · Apr 8, 2020
References Cited (98)
US 6654802B1 · Oliva et al. · 2003 [cited by applicant]
US 20170286690A1 · Chari · 2017 [cited by examiner]
US 20180048550A1 · Beyah et al. · 2018 [cited by applicant]
US 20200099704A1 · Lee · 2020 [cited by examiner]
A. T. Al Ghazo and R. Kumar, “ICS/SCADA Device Recognition: A Hybrid Communication-Patterns and Passive-Fingerprinting Approach,” 2019 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), Arlington, VA… [cited by examiner]
Barrère, Martín, et al. “Identifying security-critical cyber-physical components in industrial control systems.” arXiv preprint arXiv: 1905.04796 (16 pages). (Year: 2019). [cited by examiner]
Cover sheet for Al Ghazo reference (2 pages) (Year: 2019). [cited by examiner]
Martin Barrere et al. “Assessing Cyber-Physical Security in Industrial Control Systems” 6th International Symposium for ICS & SCADA Cyber Security Research 2019 (ICS-CSR), Sep. 10-12, 2019 (pp. 49-58) (Year: 2019). [cited by examiner]
Aleroud et al., “Queryable Semantics to Detect Cyber-Attacks: A Flow-Based Detection Approach,” IEEE Trans. Syst., Man, Cybern., Syst., vol. 48, No. 2, pp. 207-223, 2018. [cited by applicant]
Alhomidi et al., “Finding the Minimum Cut Set in Attack Graphs Using Genetic Algorithms,” 2013 International Conference on Computer Applications Technology (ICCAT), IEEE, pp. 1-6, 2013. [cited by applicant]
Ammann et al., “A host-based approach to network attack chaining analysis,” Computer Security Applications Conference, 21st Annual, pp. 1-10, 2005. [cited by applicant]
Ammann et al., “Scalable, Graph-Based Network Vulnerability Analysis,” Proceedings of the 9th ACM Conference on Computer and Communications Security, ACM, pp. 217-224, 2002. [cited by applicant]
Baiardi et al., “Hierarchical, Model-Based Risk Management of Critical Infrastructures,” Reliability Engineering & System Safety, vol. 94, No. 9, pp. 1403-1415, 2009. [cited by applicant]
Bangemann et al., “State of the Art in Industrial Automation,” Industrial Cloud-Based Cyber-Physical Systems, Springer, 27 pages, 2014. [cited by applicant]
Bodenheim et al., “Evaluation of the Ability of the Shodan Search Engine to Identify Internet-Facing Industrial Control Devices,” International Journal of Critical Infrastructure Protection, vol. 7, No. 2, pp. 114-123, … [cited by applicant]
Cardenas et al., “Challenges for Securing Cyber Physical Systems,” Workshop on future directions in cyber-physical systems security, pp. 1-4, 2009. [cited by applicant]
Caselli et al., “On the Feasibility of Device Fingerprinting in Industrial Control Systems,” International Workshop on Critical Information Infrastructures Security, Springer, 12 pages, 2013. [cited by applicant]
Chai et al., “Social Network Analysis of the Vulnerabilities of Interdependent Critical Infrastructures,” International journal of critical infrastructures, vol. 4, No. 3, pp. 256-273, 2008. [cited by applicant]
Chittester et al., “Risks of Terrorism to Information Technology and to Critical Interdependent Infrastructures,” J Homel Secur Emerg Manag, vol. 1, No. 4, Article 402, pp. 1-22, 2004. [cited by applicant]
Cho et al., “Cyberphysical Security and Dependability Analysis of Digital Control Systems in Nuclear Power Plants,” IEEE Transactions on Systems, Man, and Cybernetics: Systems, vol. 46, No. 3, pp. 356-369, 2016. [cited by applicant]
CVE, “Siemens Common Vulnerabilities,” https://cve.mitre.org/cgi-bin/cvekey. cgi?keyword=siemens, accessed: May 25, 2018, pp. 1-27, 2018. [cited by applicant]
Dutta, et al., “Labeled Cuts in Graphs,” Theoretical Computer Science, vol. 648, pp. 34-39, 2016. [cited by applicant]
Francois et al., “PTF: Passive Temporal Fingerprinting,” in 12th IFIP/IEEE International Symposium on Integrated Network Management (IM 2011) and Workshops, IEEE, pp. 289-296, 2011. [cited by applicant]
Gacek et al., “The JKind Model Checker,” http://loonwerks.com/tools/jkind.html, accessed: Jan. 11, 2018, pp. 1-7, 2016. [cited by applicant]
Gadyatskaya, “How to Generate Security Cameras: Towards Defence Generation for Socio-Technical Systems,” International Workshop on Graphical Models for Security, Springer, pp. 50-65, 2015. [cited by applicant]
Ghazo et al., “ICS/SCADA Device Recognition: A Hybrid Communication-Patterns and Passive-Fingerprinting Approach,” 2019 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), pp. 19-24, 2019. [cited by applicant]
Ghazo et al., “A2G2V: Automatic Attack Graph Generation and Visualization and Its Applications to Computer and SCADA Networks,” IEEE Transactions on Systems, Man, and Cybernetics: Systems, pp. 1-11, 2019. [cited by applicant]
Ghazo et al., “Identification of Critical-Attacks Set in an Attack-Graph,” 2019 IEEE 10th Annual Ubiquitous Computing, Electronics Mobile Communication Conference (UEMCON), pp. 1-7, 2019. [cited by applicant]
Gillmann, “0/1-polytopes: Typical and Extremal Properties,” pp. 1-131, 2007. [cited by applicant]
Gordeychik et al., “SCADA Strange Love or: How I Learned to Start Worrying and Love Nuclear plants,” http://scadastrangelove.blogspot.ru/2012/11/plcscan.html, pp. 1-74, 2013. [cited by applicant]
Haidar et al., “Vulnerability Assessment of Power System Using Various Vulnerability Indices,” 4th Student Conference on Research and Development, SCOReD 2006, IEEE, pp. 224-229, 2006. [cited by applicant]
Hassanzadeh et al., “Towards Effective Security Control Assignment in the Industrial Internet of Things,” Internet of Things (WF-IoT), 2015 IEEE 2nd World Forum, pp. 795-800, 2015. [cited by applicant]
Hassin et al., “Approximation Algorithms and Hardness Results for Labeled Connectivity Problems,” Journal of Combinatorial Optimization, vol. 14, No. 4, pp. 437-453, 2007. [cited by applicant]
Henry et al., “A Comprehensive Network Security Risk Model for Process Control Networks,” Risk Analysis, vol. 29, No. 2, pp. 223-248 2009. [cited by applicant]
Henry et al., “Evaluating the Risk of Cyber Attacks on SCADA Systems Via Petri Net Analysis with Application to Hazardous Liquid Loading Operations,” Technologies for Homeland Security, HST'09 IEEE Conference, pp. 607-6… [cited by applicant]
Hewett et al., “Cyber-Security Analysis of Smart Grid SCADA Systems with Game Models,” Proceedings of the 9th Annual Cyber and Information Security Research Conference, ACM, pp. 109-112, 2014. [cited by applicant]
Hong et al., “Scalable Attack Representation Model Using Logic Reduction Techniques,” Trust, Security and Privacy in Computing and Communications (TrustCom), 2013 12th IEEE International Conference, IEEE, pp. 404-411, 2… [cited by applicant]
Huang et al., “Cyber-Physical System Security for Networked Industrial Processes,” International Journal of Automation and Computing, vol. 12, No. 6, pp. 567-578, 2015. [cited by applicant]
Yardley, ICS PCAPs, https://github.com/ITI/ICS-Security-Tools/tree/master/pcaps, accessed: Sep. 4, 2018, pp. 1-3, 2018. [cited by applicant]
N. ICS-Cert, ICS-Cert Year in Review, pp. 1-9, 2015. [cited by applicant]
PLCopen, “International Standard IEC 61131 Applies to Programmable Controllers (PLC)”, http://www.plcopen.org/pages/tc1_standards/iec61131-1/, accessed: Sep. 4, 2018, pp. 1-4, 2018. [cited by applicant]
I. E. C. (IEC), “IEC 62264-2 Enterprise-Control System Integration,” http://www. plcopen.org/pages/tc1_standards/iec61131-1/, accessed: Sep. 4, 2018, pp. 1-21, 2018. [cited by applicant]
Ingols et al., “Practical Attack Graph Generation for Network Defense,” Computer Security Applications Conference, ACSAC 06 22nd Annual, IEEE, pp. 121-130, 2006. [cited by applicant]
Ivanova et al., “Transforming Graphical System Models to Graphical Attack Models,” International Workshop on Graphical Models for Security, Springer, pp. 82-96, 2015. [cited by applicant]
Jeon et al., “Passive Fingerprinting of SCADA in Critical Infrastructure Network Without Deep Packet Inspection,” arXiv preprint arXiv:1608.07679, pp. 1-8, 2016. [cited by applicant]
Jha et al., “Two Formal Analyses of Attack Graphs,” Computer Security Foundations Workshop, Proceedings. 15th IEEE, pp. 49-63, 2002. [cited by applicant]
Kaynar, “A Taxonomy for Attack Graph Generation and Usage in Network Security,” J. Inf. Security Appl., vol. 29, pp. 27-56, 2016. [cited by applicant]
Kaynar et al., “Distributed Attack Graph Generation,” IEEE Transactions on Dependable and Secure Computing, vol. 13, No. 5, pp. 519-532, 2016. [cited by applicant]
Keliris et al., “Remote Field Device Fingerprinting Using Device-Specific Modbus Information,” 2016 IEEE 59th International Midwest Symposium on Circuits and Systems (MWSCAS), IEEE, pp. 1-4, 2016. [cited by applicant]
Kiravuo et al., “Peeking Under the Skirts of a Nation: Finding ICS Vulnerabilities in the Critical Digital Infrastructure,” European Conference on Cyber Warfare and Security, Academic Conferences International Limited, … [cited by applicant]
Kriaa et al., “Modeling the Stuxnet Attack with BDMP: Towards More Formal Risk Assessments,” Risk and Security of Internet and Systems (CRISIS), 2012 7th International Conference on, IEEE, pp. 1-8, 2012. [cited by applicant]
Lemay et al., “Adversary-Driven State-Based System Security Evaluation,” Proceedings of the 6th International Workshop on Security Measurements and Metrics, ACM, pp. 1-8, 2010. [cited by applicant]
Ma et al., “A Scalable, Bidirectional-Based Search Strategy to Generate Attack Graphs,” Computer and Information Technology (CIT), 2010 IEEE 10th International Conference, IEEE, pp. 2976-2981, 2010. [cited by applicant]
“Masters-Thesis-Ellipsoid,” https://github.com/mrflory/masters-thesis-ellipsoid, accessed: Sep. 18, 2019, pp. 1-11, 2019. [cited by applicant]
Mcqueen et al., “Quantitative Cyber Risk Reduction Estimation Methodology for a Small SCADA Control System,” System Sciences, HICSS'06, Proceedings of the 39th Annual Hawaii International Conference on System Sciences, … [cited by applicant]
Nash, Geoff, “Modbus Register Mapping for the PLC IO Interface for GE Genius IO,” M. T. LLC, https://www.mynah.com/content/ge-legacy-rio-interface-module-memory-map, Accessed: Oct. 17, 2019, pp. 1-41, 2017. [cited by applicant]
NCCIC/ICS-CERT, “Year in Review 2016 Incident Response Pie Charts,” https://uscert.cisa.gov/sites/default/files/Annual_Reports/Year_in_Review_FY2016_IR_Pie_Chart_S508C.pdf., pp. 1-24, 2016. [cited by applicant]
Hansson, Netresec, “Capture Files from 4sics Geek Lounge,” https://www.netresec.com/ index.ashx?page=PCAP4SICS, accessed: Sep. 4, 2018, pp. 1-2, 2018. [cited by applicant]
Kaspersky et al., “Year in Review 2016 Incident Response Pie Charts,” https://uscert.cisa.gov/sites/default/files/Annual_Reports/Year_in_Review_FY2016_IR_Pie_Chart_S508C.pdf., pp. 1-2, 2016. [cited by applicant]
NCCIC, D. of Homeland Security, “ICS-CERT,” https://search.usa.gov/search?utf8= US-cert-ics&sort_by=&query=siemens, accessed: May 25, 2018, pp. 1-2, 2018. [cited by applicant]
Noel et al., “Efficient Minimum-Cost Network Hardening Via Exploit Dependency Graphs,” 19th Annual Computer Security Applications Conference, 2003 Proceedings., IEEE, pp. 86-95, 2003. [cited by applicant]
Osate, “Open Source AADL Tool Environment for the SAE Architecture Analysis and Design Language (AADL),” Carnegie-Mellon University, http://osate.org/about-osate.html, accessed: Jan. 11, 2018, pp. 1-3, 2018. [cited by applicant]
Patel et al., “Quantitatively Assessing the Vulnerability of Critical Information Systems: A New Method for Evaluating Security Enhancements,” International Journal of Information Management, vol. 28, No. 6, pp. 483-491… [cited by applicant]
Permann et al., “Cyber Assessment Methods for SCADA Security,” 15th annual joint ISA POWID/EPRI controls and Instrumentation conference, Nashville, TN, pp. 1-13, 2005. [cited by applicant]
Peterson, Dale, “Cyber Security Audit and Attack Detection Toolkit,” Digital Bond Incorporated, Tech. Rep., pp. 1-24, 2012. [cited by applicant]
Radvanovsky et al., “Project SHINE: What We Discovered and Why You Should Care,” 10th Sans ICS Security Summit, Orlando, FL, pp. 1-23, 2015. [cited by applicant]
Ren et al., “Verification Using Counterexample Fragment Based Specification Relaxation: Case of Modular/Concurrent Linear Hybrid Automata,” IET Cyber-Physical Systems: Theory & Applications, vol. 2, No. 2, pp. 65-74, 20… [cited by applicant]
Ren et al., “A New Abstraction-Refinement Based Verifier for Modular Linear Hybrid Automata and Its Implementation,” Networking, Sensing and Control (ICNSC), 2014 IEEE 11th International Conference, IEEE, pp. 30-35, 201… [cited by applicant]
Ritchey et al., “Using Model Checking to Analyze Network Vulnerabilities,” Security and Privacy, S&P 2000, Proceedings, 2000 IEEE Symposium, IEEE, pp. 156-165, 2000. [cited by applicant]
Rockwell Collins and University of Minnesota, “The Assume Guarantee Reasoning Environment,” Users Guide, pp. 1-59, 2018. [cited by applicant]
Sajid et al., “Cloud-Assisted IOT-Based SCADA Systems Security: A Review of the State of the Art and Future Challenges,” IEEE Access, vol. 4, pp. 1375-1384, 2016. [cited by applicant]
Sawilla et al., “Identifying Critical Attack Assets in Dependency Attack Graphs,” European Symposium on Research in Computer Security, Springer, pp. 18-34, 2008. [cited by applicant]
Schneider, “Modbus Protocol and Register Map for Ion Devices,” https://www. ccontrol.com/support/dp/ION_Meter_Modbus.pdf, 2011, Accessed: Oct. 17, 2019, pp. 1-86. [cited by applicant]
Schnoebelen, “The Complexity of Temporal Logic Model Checking,” Advances in modal logic, vol. 4, pp. 393-436, 2002. [cited by applicant]
Sheyner et al., “Tools for Generating and Analyzing Attack Graphs,” International Symposium on Formal Methods for Components and Objects, Springer, pp. 344-371, 2003. [cited by applicant]
Sheyner, et al., “Automated Generation and Analysis of Attack Graphs,” Proceedings 2002 IEEE Symposium on Security and Privacy, IEEE, p. 273-284, 2002. [cited by applicant]
Shodan, “The Computer Search Engine for Security,” Available at: http://www. shodanhq.com/help, pp. 1-85, 2009. [cited by applicant]
Siemens, “Simatic S7-PLCSIM v5.4 SP8,” https://support.industry.siemens.com/ cs/document/109750064/trial-software-simatic-s7-plcsim-v5-4-sp8?dti=0& Ic=en-WW, Accessed: Oct. 22, 2019, pp. 1-82. [cited by applicant]
Siemens, “S7—Open Modbus / TCP Communication,” https://w3.siemens.com/ mcms/topics/en/siplus/ric-telecontrol/Documents/ric-docu/modbus-tcp_ funktionsbeschreibung_en.pdf, Accessed: Oct. 17, 2019, pp. 1-58. [cited by applicant]
Stouffer et al., “Guide to Industrial Control Systems (ICS) Security,” NIST special publication, vol. 800, No. 82, pp. 1-155, 2011. [cited by applicant]
Trust, “Secure Water Treatment (SWaT) Testbed,” https://itrust.sutd.edu.sg/testbeds/ secure-water-treatment-swat/, accessed: Jun. 5, 2018, pp. 1-16, 2018. [cited by applicant]
Tarjan, Robert, “Depth-First Search and Linear Graph Algorithms,” SIAM Journal on Computing, vol. 1, No. 2, pp. 146-160, 1972. [cited by applicant]
Ten et al., “Cybersecurity for Critical Infrastructures: Attack and Defense Modeling,” IEEE Transactions on Systems, Man, and Cybernetics—Part A: Systems and Humans, vol. 40, No. 4, pp. 853-865, 2010. [cited by applicant]
Wireshark, “Tshark Dump and Analyze Network Traffic,” https://www.wireshark.org/ docs/man-pages/tshark.html, Accessed: Sep. 4, 2018, pp. 1-23, 2018. [cited by applicant]
U. NewsTrack, “Cyber Malfunction Halts Nuclear Plant.” link.galegroup.com/apps/ doc/A179774603/BIC1?u=iastumain&xid=42ee4dce, Accessed: May 15, 2017, 1 pg, 2005. [cited by applicant]
Vigo et al., “Automated Generation of Attack Trees,” Computer Security Foundations Symposium (CSF), 2014 IEEE 27th, pp. 337-350, 2014. [cited by applicant]
Wang et al., “Minimum-Cost Network Hardening Using Attack Graphs,” Computer Communications, vol. 29, No. 18, pp. 3812-3824, 2006. [cited by applicant]
Wireshark, “OUI Lookup Tool,” accessed: Sep. 4, 2018, 1 page, 2018. [cited by applicant]
Yan et al., “A PMU-Based Risk Assessment Framework for Power Control Systems,” Power and Energy Society General Meeting (PES), 2013 IEEE, pp. 1-5, 2013. [cited by applicant]
Zhang et al., “The Label Cut Problem with Respect to Path Length and Label Frequency,” Theoretical Computer Science, vol. 648, pp. 72-83, 2016. [cited by applicant]
Zhang et al., “Approximation and Hardness Results for Label Cut and Related Problems,” Journal of Combinatorial Optimization, vol. 21, No. 2, pp. 192-208, 2011. [cited by applicant]
Zhang et al., “Multimodel-Based Incident Prediction and Risk Assessment in Dynamic Cybersecurity Protection for Industrial Control Systems,” IEEE Transactions on Systems, Man, and Cybernetics: Systems, vol. 46, No. 10, … [cited by applicant]
SAE Int'l., “Architecture Analysis and Design Language” (AADL), AS5506, https:/SAE Int'l., /www.sae.org/standards/content/as5506/, accessed: Jan. 11, 2018, pp. 1-2, 2004. [cited by applicant]
Song et al., “A Cyber Security Risk Assessment for the Design of I&C Systems in Nuclear Power Plants,” Nuclear Engineering and Technology, vol. 44, No. 8, pp. 919-928, 2012. [cited by applicant]
Wiens, “Nettoplcsim Network Extension for PLCSIM,” https://usermanual.wiki/ Document/NetToPLCsimManualen.1468207178/view, Accessed:Oct. 22, 2019, pp. 1-11, 2019. [cited by applicant]
Woo et al., “A Study on Quantitative Methodology to Assess Cyber Security Risk of SCADA Systems,” Advanced Materials Research, vols. 960-961, pp. 1602-1611, 2014. [cited by applicant]
Jiaxi et al., “Cyber Security Vulnerability Assessment of Power Industry”, Power Systems Conference and Exposition, PSCE'06. 2006 IEEE PES, pp. 2200-2205, 2006. [cited by applicant]
Nelson et al., “Common Cybersecurity Vulnerabilities in Industrial Control Systems,” Control Systems Security Program. Washington DC: Department of Homeland Security (DHS), National Cyber Security Division, pp. 1-88, 20… [cited by applicant]
Cited By (5)
US 12,470,594 US 12,495,058 US 12,580,943 US 12,587,562 US 12,695,777