DOE OSTI · 1891892
CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure
Abstract
Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Kleinheider, Hannah Pearson. 2022-10-08. CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure. https://www.osti.gov/biblio/1891892
Cite the original work for its findings. Save a collection to share your selection of sources.