Interdisciplinary Approaches to Cybervulnerability Impact Assessment for Energy Critical Infrastructure

Honorable Mention
Cybersecurity Training & AwarenessIoT Device PrivacyCybersecurity EngineersEnergy Management Personnel

Document Title

An Interdisciplinary Approach to Assessing the Impact of Cyber Vulnerabilities on Energy Critical Infrastructure

Document Information

  • Domain: Cybersecurity and Energy Critical Infrastructure
  • Keywords: Cybersecurity, Energy Infrastructure, Operational Technology (OT), Computer Security, System Vulnerabilities, Interdisciplinary Collaboration, Impact Assessment, Qualitative Research

Research Background and Problem Statement

  • Problem or Challenge:
    • As energy infrastructure becomes increasingly interconnected, the separation between operational technology (OT) and computer security poses challenges for developing unified security strategies.
    • Cyber vulnerabilities can have significant impacts on grid operations, including outages and cascading effects on other critical sectors such as healthcare, finance, and agriculture.
    • IT security frameworks are often unsuitable for energy OT scenarios due to factors such as legacy systems, high demands for continuous operation, and constraints in economic and human resources.
  • Importance:
    • Securing energy infrastructure is crucial for society, as any disruptions can trigger chain reactions that threaten various aspects of national and public welfare.
    • The current shortage of cybersecurity professionals, especially in resource-constrained small energy facilities, further exacerbates the vulnerability of energy infrastructure.
  • Research Motivation and Related Work:
    • The authors aim to improve security measures for critical infrastructure through an interdisciplinary approach that combines the expertise of energy operations engineers and computer security specialists.
    • Core research topics include bridging the cultural and technical gaps between OT and IT security and fostering effective interdisciplinary collaboration.

Solution

  • Methodology and Approach:
    • Conduct interviews with 18 experts in the field of energy critical infrastructure (9 computer security specialists and 9 energy operational technology experts) to examine their perspectives on the information needed for assessing the impact of cyber vulnerabilities.
    • Analyze strategies proposed by experts, their understanding of each other's domains, and ways to enhance collaboration.
  • Innovative Contributions:
    1. Employ an interdisciplinary perspective that integrates knowledge from computer security and energy operational technology.
    2. Explore subtle differences in thinking and collaboration opportunities between the energy OT and computer security domains.
    3. Propose recommendations for improving interdisciplinary collaboration, such as team integration, red team simulation exercises, and enhancing usable security designs.
  • Implementation Steps and Key Techniques:
    1. Recruit experts from the energy OT and computer security domains and design interview questions addressing impact assessment strategies and cross-domain collaboration.
    2. Use qualitative research methods to code and analyze interview transcripts, identifying patterns and differences in how the two groups assess the impact of cyber vulnerabilities.
    3. Provide practical recommendations to improve the accuracy of impact assessments and interdisciplinary collaboration.

Research Findings

Specific Results

  1. Similarities: Both groups of experts shared similar views on fundamental categories of assessment strategies, such as accessibility, consequence evaluation, and device information.
  2. Differences:
    • Computer security experts focused more on attack methods, access paths within networks, and functional misuse of devices.
    • Energy operational technology experts emphasized cascading effects and operational disruptions in the overall system impact.
  3. Interdisciplinary Insights: Despite some cross-disciplinary experience within the same organization, significant differences in professional motivations and thinking remain, requiring further integrative collaboration.

Advantages Compared to Existing Solutions

  • Provides an in-depth exploration of the cognitive differences between energy OT and computer security, offering a reference framework for interdisciplinary collaboration in other critical infrastructure domains.
  • Highlights the importance of usability in security design, avoiding overly complex solutions that hinder operational staff's routine tasks.

Experimental or Evaluation Results

  • Interviews revealed that collaboration methods based on cross-domain dialogue and exposure learning significantly improve knowledge sharing among experts.
  • Qualitative findings indicate the need for enhanced cross-domain knowledge exchange to achieve comprehensive vulnerability assessments in energy OT and cybersecurity.

Limitations and Future Directions

  • Limitations:
    • The study is based on a small sample size and focuses on a single organization, limiting the generalizability of the results.
    • Experts may already have interdisciplinary experience due to long-term collaboration, which does not fully represent the industry's broader context.
    • Lacks standardized or quantitative validation methods.
  • Future Directions:
    • Expand the sample size to explore interdisciplinary behaviors in more traditional settings.
    • Assess the effectiveness of cross-domain interactions in other critical infrastructure sectors such as healthcare and water resource management.
    • Develop more universal and user-friendly tools and frameworks to enhance energy OT security while meeting interdisciplinary needs.

Conclusion

This study, based on interviews with computer security specialists and energy engineers in the field of energy critical infrastructure, reveals differences in strategies for assessing the impact of cyber vulnerabilities and offers collaboration recommendations. It proposes actionable interdisciplinary methods to improve the security and efficiency of critical infrastructure systems.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/147155/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642493
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
Honorable Mention
group
Authors
5 authors
sell
Subtopics
Cybersecurity Training & Awareness, IoT Device Privacy
work
Professions
Cybersecurity Engineers, Energy Management Personnel
article
Content Status
Full text indexed
hub
Related Papers
0 related papers