Abstract

In the past few years, maritime vessels have become computerized and connected to the internet. However, with this technology, critical systems based on-board ships that manage the vessel’s navigation system, radar, cargo management system, etc have become more prone to cyber-attacks. Moreover, attackers are now becoming aware of the vulnerabilities associated with such maritime vessel systems. As a result, it is of vital importance to manage and secure the maritime vessel networks against cyber-attacks, but there is a lack of capabilities to efficiently manage the identifications of vulnerabilities, security risk assessment, and evaluate the effectiveness of countermeasures. Hence, we propose a novel framework and security risk modeling and assessment method to evaluate the security of maritime vessel networks. We develop (1) a security model for maritime vessels to capture probabilistic events, vulnerabilities, and network configurations of vessel components; (2) propose an approach to assess the network with a single function, multiple functions, and the inter-dependencies between the functions as attack goal(s); (3) adopt three well-defined security metrics with the proposed model to evaluate possible attacks and/or threats; and (4) compare the effectiveness of cyber-defense strategies based on different attack scenarios on the maritime vessel network. Besides, we perform sensitivity analysis based on temporal and permanent connections that are associated with the vessels’ systems to understand the effect of the connections on security. Our results demonstrate the applicability and usability of the proposed model for finding potential attack paths, assessing security, and mitigating the impact of cyber-attacks and threats on a vessel network.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.