Search NASA⌕ Search

Engineering topics

Skelton, Anna Christine

Publications and source records attributed to Skelton, Anna Christine.

Vulnerabilities in Satellite Communications Underscore Threat to Critical Infrastructure

INL analysts assess critical infrastructure sectors leveraging satellite communications (SATCOM) are likely inadvertently increasing the attack surface caused by inherent vulnerabilities in equipment and communications pathways. A lack of ownership regarding security in SATCOM ecosystems creates pervasive information security risk, and the obfuscation of patching responsibility means the mitigation of publicly and privately disclosed vulnerabilities is difficult to track. With these factors in consideration, INL analysts assess the number of attacks against SATCOM is likely to increase in the next decade as threat actors exploit these vulnerabilities.

99 GENERAL AND MISCELLANEOUS↗

CyTRICS Impact-Based Prioritization Process

Cyber Testing for Resilient Industrial Control Systems™ (CyTRICS™) is the Department of Energy’s (DOE’s) program for cybersecurity vulnerability testing, digital subcomponent enumeration, and forensic assessment. CyTRICS leverages best-in-class test facilities and analytic capabilities at six DOE National Laboratories and strategic partnerships with key stakeholders including technology developers, manufacturers, asset owners and operators, and interagency partners. During the program’s development, CyTRICS established a unique methodology for prioritizing digital components within operational technology (OT) and industrial control systems (ICS) in the Energy Sector Industrial Base (ESIB) for cyber vulnerability testing. The CyTRICS prioritization process leverages multiple characteristics of systems, components, and their contextual deployment to calculate a quantification of individual digital components for CyTRICS testing. The initial version of the CyTRICS prioritization process was premised largely upon the impact which could result to an energy sector industrial control system if the digital component under testing was compromised, either through malicious means, faulty engineering, or other modes. CyTRICS has termed this process the “CyTRICS Impact-based Prioritization Process.” This paper describes the factors identified for use in the Impact-based Prioritization process and identifies the rationale for inclusion. During development, three National Laboratories piloted this prioritization process and generated prioritization scores for seven systems. Following the piloting of the process, laboratory subject matter experts (SME) validated that the numerical scores generated by the prioritization process were consistent with their knowledge of the impact that may occur should any of these systems be disrupted. The following document explains how to perform the prioritization process to generate prioritization scores for energy sector systems. After outlining assumptions required to conduct the process, it describes how to identify and elicit data which can be leveraged to evaluate a system and assign numerical values for each factor. The prioritization process uses different weights on different factors; rationale for each weight is included within the paper. Additionally, the paper includes some recommendations for future enhancements to prioritization, including lessons learned from developing and piloting the process. Finally, a comprehensive appendix includes example documents to be leveraged by those looking to execute the prioritization process.

99 GENERAL AND MISCELLANEOUS↗