Geri Dön

Endüstriyel kontrol sistemlerinde varlık-servis modeline bağlı purdue mimarisine dayalı etki tabanlı bir siber risk değerlendirme yöntemi

An impact-based cyber risk assessment method based on purdue architecture, linked to the asset-service model in industrial control systems

  1. Tez No: 1018677
  2. Yazar: FİRDEVS SEVDE TOKER
  3. Danışmanlar: PROF. DR. İBRAHİM ÖZÇELİK
  4. Tez Türü: Doktora
  5. Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
  6. Anahtar Kelimeler: Belirtilmemiş.
  7. Yıl: 2026
  8. Dil: Türkçe
  9. Üniversite: Sakarya Üniversitesi
  10. Enstitü: Fen Bilimleri Enstitüsü
  11. Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
  12. Bilim Dalı: Bilgisayar Mühendisliği Bilim Dalı
  13. Sayfa Sayısı: Belirtilmemiş.

Özet

Endüstriyel kontrol sistemleri (EKS) kritik altyapılar gibi siber-fiziksel sistemlerin otomasyonu için oluşturulan sistemler bütünüdür. EKS'ler gelişen teknolojiler sayesinde siber alan ile fiziksel alanı birbirine yaklaştırmaktadır. Bu durum kolaylıklarıyla birlikte riskleri de beraberinde getirmektedir. EKS'lerin profesyonel tehditler tarafından hedef alınması halinde operasyonel süreklilik, insan güvenliği, çevresel sürdürülebilirlik ve ulusal güvenlik açısından stratejik öneme sahip durumların kaybı gibi yüksek hasarlı olumsuz etkileri söz konusudur. Bu yüzden saldırı olmadan önce EKS risklerinin doğru ve eksiksiz ölçümü kritik bir öneme sahiptir. Düşük zaman toleransı olan bu sistemlerde gerçek zamanlılık esaslı tasarlanan fiziksel proses verilerinin değerlendirilmesi veya kontrol merkezine iletilmesi, kontrol merkezindeki özel yazılımlar ile proses verisinin toplanması, görselleştirilmesi, ihtiyaç halinde uzaktan mikro-denetleyici cihazlara saha kontrol komutlarının gönderilmesi, cihaz bakım ve programlamalarının sağlanması gibi süreçlerin işletildiği kritik görevleri üstlenen endüstriyel varlıklar bulunmakta ve bu varlıkların iletişiminden oluşan bir endüstriyel ağ mimarisi ortaya çıkmaktadır. EKS mimarilerinin fiziksel prosese yakın seviyesinde proses iletişimi ihtiyaçlarına göre tasarlanmış endüstriyel protokoller kullanılmaktadır. Endüstriyel protokoller, doğası gereği hızlı iletim sağlaması gerektiği için şifreleme yöntemleri entegre edilmediğinden proses verisi gibi kritik veriler herhangi bir şifreleme mekanizması olmadan ağda dolaşır. Yukarıda bahsedildiği üzere EKS çalışma yapısı oldukça karmaşık ve farklı türde çalışma prensibine sahip alt yapılardan oluşmaktadır. Purdue model EKS ortamını farklı işlevsel olarak farklı seviyelere bölerek EKS yapısını varlık ve ağ seviyesinde modüler bölümleme ile bir referans sunmaktadır. Siber-fiziksel sistemlerden oluşan EKS mimarileri, her kritik altyapıda farklı hiyerarşide oluşturulmaktadır. Purdue modeli yaygın referans alınan bir mimari olsa da farklı yorumlamalar ve kısıtlardan dolayı farklı EKS mimarileri ortaya çıkmaktadır. Bu tez çalışmasında EKS mimarilerinin bütüncül olarak risk değerlendirmesinin doğru ve eksiksiz yapılması için etki tabanlı bir yöntem sunulmaktadır. Farklı kritik altyapılarda oluşan EKS ortamlarında tam ve doğru risk değerlendirmesinin yapılması için EKS'lerin sistem analizi yapılmıştır. Böylece risk değerlendirmesi için tüm varlık ve erişim analizleri elde edilmiştir. EKS mimarilerini oluşturan varlıklar detaylı analiz ile varlık-servis modeli oluşturularak varlıkların çalışma yapısının ve varlık kritikiliğinin riske olan etkisinin ölçülmesi sağlanmıştır. EKS mimarilerindeki varlıkların erişim analizleri ve siber-fiziksel etkileşimleri sistematik bir şekilde irdelenerek oluşacak etkiye göre risk değerlendirmesinin yapılması sağlanmıştır. Risk sonucunda tek bir değer yerine EKS'deki etkiye göre dört farklı risk değeri oluşturulmuştur. Bu etkiler: Erişilebilirlik, emniyet, kontrol ve görünürlüktür. Dolayısıyla etkiye göre risk değerleri ile stratejik önlemlerin alınmasında kolaylık sağlanmıştır. EKS tehditleri hem varlık hem de ağ seviyesinde değerlendirilmiştir. Tehditler, EKS'ye yönelik geçmişten günümüze kadar siber saldırılarda kullanılan saldırı tekniklerinin detaylı analizi ile varlık-tehdit-etki korelasyonunu oluşturacak şekilde tez çalışmasında gerçekçi bir risk değerlendirme metriği oluşturulmuştur. IEC 62443, NIST 800-82, ISO 27019, NIST 800-53 gibi globalde yaygın kullanılan siber güvenlik standartlarının ortak konusu olan risk değerlendirme başlığı bu tez çalışmasında değerlendirilerek EKS'ye özgü alınması gereken önlemler bilgi veri tabanının oluşturulması sağlanmıştır. Böylece riski azaltmak için kullanılan önlemler bilgi veri tabanı ile EKS alanındaki güvenlik standartlarına uygunluğu da risk değerlendirme seviyesinde büyük ölçüde sağlanmaktadır. EKS'ye özgü risk değerlendirme kriterlerinin oluşturulması, bu tez çalışmasının önemli katkılarından biridir. Risk değerlendirmenin ana bileşenlerinden olan tehdit, gerçekleşme olasılığı, sonuç (etki) ve alınan önlemler ile alakalı veriler EKS özelinde değerlendirilerek bilgi veri tabanları oluşturulmuştur. Böylece farklı EKS proseslerinin otomasyonunda uygulanabilir esnek bir risk değerlendirme yöntemi geliştirilmiştir. Tez çalışmasında önerilen risk değerlendirme yöntemi, EKS kontrol sistemlerinin kullanıldığı prosesten bağımsız çözüm sunmaktadır. Bu durumu test etmek için Sakarya Üniversitesi Bilgisayar ve Bilişim Bilimleri Fakültesi'nde bulunan Kritik Altyapılar Ulusal Test Yatağı Merkezi (CENTER)'nde elektrik iletim/dağıtım ve su yönetimi proseslerinin EKS ortamları sistem analizi ile risk değerlendirmesi yapılmıştır. EKS mimarilerindeki varlıkların konum değişikliği, özellik değişikliği, görev değişikliği gibi farklı durumlarda değişen risklerin ölçülmesi bu prosesler üzerinde test edilmiştir. Risk değerleri ölçeklenmiş olarak (0-1 aralığında) oluşturulmuştur. Buna göre 0 en düşük ve 1 en yüksek risk değerini tanımlamak üzere nitel risk yorumlaması için kullanılmıştır. Toplam gerçek risk değerlendirmesinde ise bir EKS mimarisindeki dört farklı etkinin birbirine göre risk değerleri karşılaştırılarak risk-etki yorumlaması için kullanılmıştır. Bu tez çalışmasında, EKS mimarilerinin etki tabanlı nicel risk değerlendirme yöntemi ile iki farklı endüstriyel proseste dört farklı senaryo ile toplam sekiz EKS mimarisi test edilmiştir. EKS mimarilerindeki değişimlerde önerilen risk değerlendirme kriterlerine göre güvenliğin beklenti doğrultusunda arttığı veya azaldığı sayısal değerler ile ispatlanmıştır. Böylece farklı proseslerde bir EKS mimarisinin varlık özelliklerinin değişimi, varlıkların ağ konumunun değişimi, güvenlik önlemlerinin arttırılması/azaltılması, ağ güvenlik cihazının değişimi durumlarında etki tabanlı risk değerlerinin sayısal olarak ölçülmesi sağlanmıştır. Tezde önerilen yöntem ile ölçülen değerlendirme sonuçlarında riskler beklentiler doğrultusunda elde edilmiştir.

Özet (Çeviri)

Industrial control systems (ICS) are a comprehensive set of systems designed to automate cyber-physical systems, including critical infrastructure. Thanks to evolving technologies, ICS is bringing the cyber and physical realms closer together. This situation presents both advantages and risks. If professional threats target ICS, there are significant adverse impacts, including loss of strategically important aspects such as operational continuity, human safety, environmental sustainability, and national security. Therefore, an accurate and complete assessment of ICS risks before an attack occurs is critically important. In these systems with low time tolerance, there are industrial entities that undertake critical tasks such as evaluating physical process data designed on a real-time basis or transmitting it to the control center, collecting and visualizing process data with specialized software in the control center, sending field control commands to microcontroller devices remotely when needed, and providing device maintenance and programming. An industrial network architecture emerges, consisting of communication between these entities. Industrial protocols designed for process communication needs are used at the near-physical process level of ICS architectures. Because industrial protocols inherently require fast transmission, encryption methods are not typically integrated; therefore, critical data, such as process data, circulates on the network without any encryption mechanism. As mentioned above, the ICS operational structure is quite complex and consists of infrastructures with different types of operating principles. The Purdue model serves as a reference for the ICS structure, dividing the ICS environment into distinct functional levels and implementing modular partitioning at both the asset and network levels. ICS architectures, comprising cyber-physical systems, are organized in different hierarchies within each critical infrastructure. Although the Purdue model is a widely referenced architecture, different interpretations and constraints have led to the emergence of various ICS architectures. This thesis presents an impact-based method for conducting a comprehensive and accurate holistic risk assessment of ICS architectures. For this purpose, a layered risk assessment pyramid (LRAP) consisting of four main sections and seven layers has been proposed. The first part, named“System Analysis”consists of two layers: ICS Assets and ICS Network Communication. Asset-service model and asset's network location identification created in the first layer. Network architecture identification is created in the second layer. Purdue-compatible architecture and Process-based firewall rules are outputs of the first part from LRAP. A system analysis of ICS systems was conducted to enable complete and accurate risk assessment in ICS environments across various critical infrastructures. This resulted in the acquisition of all assets and access analyses necessary for risk assessment. The assets comprising the ICS architectures were analyzed in detail to create an asset-service model, enabling the measurement of the operational structure and criticality of the assets, as well as their impact on risk. Network architecture identification is created in the second layer from LRAP. Purdue-compatible architecture and Process-based firewall rules are outputs of the first part from LRAP. The second part is named“Security Analysis”and consists of two layers: Vulnerability assessment and threat modelling. In the vulnerability assessment layer, security vulnerabilities on assets are evaluated. Using the asset-service model from the first layer, a knowledge database for asset-service models is created, incorporating security KPI metrics based on the characteristics and services of the assets. As a result of this layer, asset criticality is determined numerically. At the threat modeling layer, network-threat and asset-threat information databases were created using MITRE ATT&CK matrices for both asset and network-based threat modeling. The third part is named“Risk Analysis”and consists of two layers: impact-based consequences assessments and countermeasures. ICS threats have been assessed at both asset and network levels. Through a detailed analysis of attack techniques used in historical cyberattacks against EKS, a realistic risk assessment metric has been established in this thesis to create an asset-threat-impact correlation. Risk assessment, a common theme in globally used cybersecurity standards such as IEC 62443, NIST 800-82, ISO 27019, and NIST 800-53, is evaluated in this thesis within the context of a countermeasure layer. This study aims to create a database of measures specific to ICS that should be taken. Thus, the compliance of measures used to mitigate risk with security standards in the ICS field is essentially ensured at the risk assessment level through this database. Moreover, the last part of LRAP is“Risk Assessment,”which consists of one layer: risk calculation and scaling. Access analyses and cyber-physical interactions of the assets in the ICS architectures were systematically examined to enable risk assessment based on the resulting impact. Instead of a single risk value, four different risk values have been created based on their impact on the ICS. These impacts are: accessibility, security, control, and visibility. Therefore, the use of risk values based on impact facilitates the implementation of strategic measures. One of the significant contributions of this thesis is the creation of risk assessment criteria specific to the ICS. These criteria were developed using information databases and can be flexibly incorporated into the method in the future if different threat models, security measures, and impact scenarios are desired. The measurement of changing risks in ICS architectures, such as changes in asset location, property, or function, has been tested on these processes. Risk values have been created as scaled risks (in the range of 0-1). Accordingly, 0 is used to define the lowest risk value and 1 the highest risk value for qualitative risk interpretation. In the total actual risk assessment, the risk values of four different effects in ICS architecture are compared with each other for risk-effect interpretation. According to the assessment results obtained using the method proposed in the thesis, the risks were in line with expectations. The risk assessment method proposed in this thesis offers a process-independent solution. To test this, a risk assessment was conducted using system analysis of the electrical transmission and distribution, as well as water management, processes in the ICS environments at the Critical Infrastructures National Testbed Center (CENTER).

Benzer Tezler

  1. Indirect force control in 6 dof humanoid robot arm using impedance controller

    Empedans kontrolünü kullanarak 6 serbestlik insansı robot kolunun dolaylı güç kontrolü

    BEHNAZ HOSSEINI

    Yüksek Lisans

    İngilizce

    İngilizce

    2014

    Elektrik ve Elektronik Mühendisliğiİstanbul Teknik Üniversitesi

    Elektrik-Elektronik Mühendisliği Ana Bilim Dalı

    YRD. DOÇ. DR. ALİ FUAT ERGENÇ

    YRD. DOÇ. DR. PINAR BOYRAZ

  2. The role of service design as a driver of innovation in the manufacturing industry

    İmalat sanayiinde inovasyonu tetikleyen etken olarak servis tasarımının rolü

    DENİZ SAYAR

    Doktora

    İngilizce

    İngilizce

    2018

    Endüstri Ürünleri Tasarımıİstanbul Teknik Üniversitesi

    Endüstri Ürünleri Tasarımı Ana Bilim Dalı

    PROF. DR. ÖZLEM ER

  3. İşçilik maliyetleri muhasebesi ve Türkiye Şeker Fabrikaları A.Ş. Ankara makina fabrikası uygulaması

    Başlık çevirisi yok

    GÖKHAN ÖZER

    Yüksek Lisans

    Türkçe

    Türkçe

    1987

    İşletmeGazi Üniversitesi

    DOÇ. DR. KAMİL BÜYÜKMİRZA

  4. Sulak alanların sorunları ve rehabilitasyon önerileri: Akgöl sulak alanı

    Problems of wetlands and rehabilitation proposals: Case study of Akgol wetland

    DUYGU BARAN

    Yüksek Lisans

    Türkçe

    Türkçe

    2018

    Çevre Mühendisliğiİstanbul Teknik Üniversitesi

    Çevre Mühendisliği Ana Bilim Dalı

    PROF. DR. AYŞE GÜL TANIK

  5. Akaryakıtla çalışan endüstriyel tav fırınlarında yanma, sıcaklık ve basıncın optimum kontrolu

    Optimum control of combustion temperature and pressure in industrial tempering furnaces working with fuel-oil

    MEHMET EROĞLU

    Yüksek Lisans

    Türkçe

    Türkçe

    1987

    Makine MühendisliğiGazi Üniversitesi

    Makine Mühendisliği Ana Bilim Dalı

    PROF. DR. YÜCEL ERCAN