
The protection of critical national infrastructures such as drinking water, gas, and electricity is extremely important as nations are dependent on their operation and steadiness. However, despite the value of such utilities their security issues have been poorly addressed which has resulted in a growing number of cyberattacks with increasing impact and huge consequences. There are many machine learning solutions to detect anomalies against this type of infrastructure given the popularity of such an approach in terms of accuracy and success in detecting zero-day attacks. However, machine learning algorithms are prone to adversarial attacks. In this paper, an energy-consumption-based machine learning approach is proposed to detect anomalies in a water treatment system and evaluate its robustness against adversarial attacks using a novel dataset. The evaluations include three popular machine learning algorithms and four categories of adversarial attack set to poison both training and testing data. The captured results show that although some machine learning algorithms are more robust against adversarial confrontations than others, overall, the proposed anomaly detection mechanism which is built on energy consumption metrics and its associated dataset are vulnerable to such attacks. To this end, a blockchain approach to protect the data during the training and testing phases of such machine learning models is proposed. The proposed smart contract is deployed in a public blockchain test network and their costs and mining time are investigated.
Digitalization of the petroleum industry entails a greater interconnection between Information Technology (IT) and Industrial Automation and Control Systems (IACS), and has led to an increased attack surface. To mitigate the consequences of incidents and to ensure a safe operation, the industry uses preparedness exercises. Previously, these exercises have concerned safety-related incidents. Today, digitalization requires the industry to also exercise security incidents, especially incidents that are directed towards IACS. While the need for more detailed guidelines in the area of cyber security and IACS has been explicitly called for by the industry, few guidelines are currently available. We aimed to lessen this shortcoming by investigating descriptions of events to use in exercises, known as scenarios. This project investigated what characterizes a scenario to be realistic and expedient for preparedness exercises on cyber attacks against IACS in the petroleum industry, with a focus on tabletop exercises. Based on data collected through interviews, a list of criteria that characterize such scenarios was created. The list was validated and approved by respondents from two different operator companies. The results highlight the importance of basing the scenario on today's threat landscape, making the scenarios plausible, and design the scenario such that it leads to a challenging tabletop exercise which also gives a sense of empowerment for the participants.
Municipalities are tasked with ensuring the cybersecurity of critical public services and functions in diverse areas such as safe water supply, healthcare, child protective services, and education with vastly different security requirements-all usually served from a common infrastructure with limited technical and organizational cybersecurity capabilities. This literature review identifies recent research on municipal and local government cybersecurity to identify current research areas, state of the art, and research methods used in research so far. We found research in the areas of smart cities, elections, human factors, operational technology, and crisis management. We also give suggestions for further research to develop better models for cybersecurity in cross-disciplinary organizations.
A robust democracy cannot be concn. Therefore, we propose a privacy-preserving, cost-effective and verifiable blockchain-based electronic score voting scheme. Our framework is premised on a watermarked quick response (QR) code-based secure identification mechanism for creating a tamper-resistant biometric voter ID card. Two watermarked image shares, namely, owner and master shares, are created through XOR-based visual cryptography (VC) which are managed by the ID owner and a semi-trusted constituency authority (CA). Election Commission officer (ECO) commences the cryptographic system setup by distributing the secret key shares amongst all the CAs. First, voters show their share for their details verification and biometric authentication. If successful, they use the modified ElGamal homomorphic encryption to enable additive computations on their score votes while ensuring their secrecy. The integrity and validity of the encrypted vote are ensured through a non-interactive partial knowledge range proof (NIPKRP) based on the Pederson commitment protocol. On the counting day, the vote ciphertext en route to CA is subjected to progressive aggregation. This intra-constituency level computation follows the range voting paradigm. Then, CAs decrypt the resultant encrypted ballots and determine the winner for their respective constituencies after comparing the obtained scores. Accordingly, each CA creates and transmits an encrypted binary vector to ECO for pluralistic inter-constituency aggregation. Finally, ECO uses its secret key to decrypt the final encrypted aggregate vector to determine the majority winning party. If at least two maximum scores or seat counts come out to be identical, most significant bit (MSB) is given priority to break the tie. CAs can collaborate to verify the results by using their secret shares. Our proposed scheme facilitates secure, tamperproof and decentralized score aggregation for e-voting with a suitable tie-breaker. The efficacy and usability of the scheme have been reported with experimental results and security proofs.
Recent studies have demonstrated the interest of analyzing GNSS (Global Navigation Satellite System) and AIS (Automatic Id entification System) data to improve the safety of naval infrastructures for a wide spectrum of maritime applications. However, in-depth analyses also underline the sensitivity of these systems to attacks such as jamming and spoofing. In this context, it is essential that researchers, specialized organizations and companies rely on realistic data to improve these types of systems to better detect and cope with potential threats. However, because of the lack of open data sets, or due to financial, technical or operational reasons, the use of simulated data is preferred in most cases over real life data, which can lead to biases. To cope with this challenge, we have developed a prototype called "HAPPINESS" for "Holistic APProach of Integrated Navigation Equipment for Cybersecurity at Sea". The main objective of this dedicated and autonomous embedded system is to collect navigation data in real time without using proprietary or restrictive protocols. The generated open data, then continuously feeds a cyber naval platform able to reproduce the functional and operational systems of a ship. This prototype allows to reproduce the kinematics of a ship in various contexts (like specific maneuvers, long tracks, docking…) in NMEA format in order to design highly realistic scenarios based on real life data and allowing to obtain more complete and richer data (than those freely accessible online) in terms of information, giving additional means to detect anomalies on navigation systems.
This paper presents an empirical study on the need for sector-specific CERT capacity in the Norwegian construction sector. Findings from the interviews demonstrate a need for developing competence in ICT security in this sector. The actors express a desire for a forum for sharing information and learning from other actors within the industry. In our estimation, there is insufficient support in the industry to create a "full-blown" CERT/CSIRT. However, it seems that all the interviewees are positive about the idea of creating an ISAC-like forum.
Cybersecurity in health care is a complex socio-technical problem. In a critical infrastructure context, like hospitals, the risks of cyberthreats do not just result from technical vulnerabilities alone but also from the degradation of working practices over time. This paper argues that organizational, operational vulnerabilities, and governance structures create a pressing need for systematic socio-technical risk analysis for cybersecurity of healthcare organizations. Yet current risk analysis methodologies are not designed to detect these kinds of systemic risks. We address these problems by the use of System-Theoretic Accident Modeling Process (STAMP). In the first case study-WannaCry cyberincident on UK National Health Service (NHS)-we applied the STAMP method to identify socio-technical factors related to the incident. Our analysis shows that the STAMP-based control taxonomies tend to be generic, which provides expressive power, but also makes them hard to apply to the specific circumstances of a cyberincident. We have, therefore, integrated the US National Institute of Science and Technology (NIST) control taxonomies to provide the level of detail required to identify potential mitigations for the control failures identified using the STAMP approach. After WannaCry, governments around the world have adopted national strategies to reduce future risks. However, ransomware threats have continued to emerge, including an attack on the Irish healthcare systems, our second case study. Our results show that the integration of a more detailed taxonomy to support the higher level STAMP analysis can increase consistency between analysts and enables direct comparisons to be made between similar incidents.
Cybersecurity is a multidisciplinary field that requires understanding of human behavior. To reinforce this idea and encourage non-technical students to participate in cybersecurity, an experiential learning project was implemented in an upper-level undergraduate criminal justice class. This paper is focused on that proof-of-concept class project in which groups of students mapped a social engineering case study onto the MITRE ATT&CK framework to understand the adversarial mindset. The paper provides background information on the ATT&CK framework, compares groups' mappings to others within the class as well as against a mapping done by an ATT&CK representative, and it offers a discussion on the lessons learned and opportunities to expand our application and understanding of educational cybersecurity principles. This paper emphasizes that while someone with more knowledge and experience using a framework that focuses on the technical aspects of cybersecurity may map a SE case study differently than multidisciplinary students who are experiencing it for the first time, there is not a single correct way to interpret and correspondingly defend adversary behaviors. Having students experience this mapping project allows them to understand the breakdown of an adversary's behavior and contextualize key tactics and techniques in a way that fits their perspective and skillset. This paper also demonstrates how a SE case study can be mapped onto the ATT&CK framework despite SE not being the focus of the framework, and that SE uses tactics and techniques that are also prevalent within more technical cyber campaigns. The authors hope to encourage more interdisciplinary cybersecurity education by sharing this experiential learning course project.
Machine Learning (ML) and Artificial Intelligence (AI) have not only transformed the way we work (i.e. how we integrate information, analyse data, and how we make decisions) but also how organisations operate (i.e. adding new business processes and services etc.). In fact, many private, public and even third sector organisations are now capitalising on the true value of having systems that can learn on their own without any human intervention. However, with these benefits also come challenges regarding project productivity and collaboration. In detail, the need to explain how these systems work and how organisations interpret their output to achieve transparency and trust. This paper details the potential of using Extended reality (XR) as a way for enabling Explainable AI (XAI) focusing on the design and development of a novel XAI XR solution. The paper also highlights the 'positive' responses from an initial solution evaluation study noting participant's impressions of the solution. It then makes recommendations for further research and development into the effectiveness of XR for explainable AI.
Web servers are targets for cyberattacks because they contain valuable information, which could facilitate interactions with another system or damage an organization's reputation. In the last two decades, Moving Target Defense (MTD) research has gained attention as a cyber resilient technique to mitigate cyber threats. However, most MTD work focuses on the network layer, and there is not much work to support the service layer. This research is an experimental evaluation of Dynamic Application Rotational Environment (DARE) and Dare IMproved (DIM). DIM is an enhanced version ofDARE that leverages a host-based firewall to rotate between web servers located on the same host. The main contribution of this work is furthering the understanding of implementing a centralized host-based MTD architecture for web servers. Results show that DIM can maintain availability while thwarting attacks, whereas DARE limits the availability of the web server.
Threats associated with the consumer Internet of Things (IoT) may particularly inhibit the work and wellbeing of journalists, especially because of the danger of technological surveillance and the imperative to protect confidential sources. These issues may have knock-on effects on societal stability and democratic processes if press freedom is eroded. Still, journalists remain unaware of potential IoT threats, and so are unable to incorporate them into risk assessments or to advise their sources. This shows a clear gap in the literature, requiring immediate attention. This article therefore identifies and organises distinctive and novel threats to journalism from the consumer IoT. The article presents a novel conceptualisation of threats to the press in six categories: regulatory gaps, legal threats, profiling threats, tracking threats, data and device modification threats and networked device threats. Each of the threats in these categories includes a description and hypothetical consequences that include real-life ways in which IoT devices can be used to inhibit journalistic work, building on interdisciplinary literature analysis and expert interviews. In so doing, this article synthesises technical information about IoT device capabilities with human security and privacy requirements tailored to a specific at-risk population: journalists. It is therefore important for cyber science scholarship to address the contemporary and emerging risks associated with IoT devices to vulnerable groups such as journalists. This exploratory conceptualisation enables the evidence-based conceptual evolution of understandings of cyber security risks to journalists.
A common challenge for organisations managing confidential customer information is to respect obligations due to legal requirements while advocating the privacy of their users' data. In the context of digital forensics and cyber security scenarios, we define cyber evidence sharing as the task of verifying that mutual knowledge exists about confidential information or digital evidence, without revealing or disclosing the information itself. An attractive cryptographic solution to this problem is the concept of Zero-Knowledge Proofs (ZKPs). In this paper, we propose a flexible and efficient approach for sharing cyber evidence based on using ZKPs. We present a protocol that allows a verifier to establish the proof of knowledge of hash digest information. This provides computational security and can be implemented efficiently using a Merkle-tree data structure. The protocol has been implemented, the resulting proof-of-concept system is evaluated, and its efficiency is demonstrated. We believe that it could be a valuable tool for use in practical real-world applications.
Recent ransomware attacks against critical infrastructure have stressed the need for a deeper understanding of the threat landscape and trends. Yet, this is hard to do due to limited data availability and sharing in open source. This paper provides the justification for, and overview of, the creation and dissemination of a Critical Infrastructure RansomWare (CIRW) dataset. It provides an overview of the CIRW dataset requesters and how they intend to use it. The paper also offers dataset changes over time based on self-assessments and community recommendations. The paper concludes by sharing the many benefits of maintaining an open dialog with the community and its recommendations in the hopes that it will inspire other researchers to take on new and innovative research agendas.
This paper explores the jurisdictional challenges that arise from the transnational dimension of cybersecurity, by analysing and comparing the jurisdictional rules applicable to cross-border actors under the NIS Directive and the NIS 2 Proposal. It also comparatively examines the jurisdictional rules of two other EU regulatory instruments applicable to digital services—the GDPR and the DSA Proposal—that rely on the ‘main establishment’ connecting factor to allocate jurisdiction to one Member State over the others (one-stop-shop mechanisms). Lastly, it assesses whether the NIS 2 Proposal represents a step forward in addressing the complex jurisdictional challenges created by cybersecurity cases with cross-border elements.
The NIS Directive (NISD) and sector-specific cybersecurity regulations require the security incident reporting to supervisory authorities. Following the risk-based approach adopted in the NISD 1.0, the European Commission’s Proposal for an NISD 2.0 requires the reporting of incidents that have caused/have the potential to cause substantial or considerable harm, as well as cyberthreats to the competent national authorities in order to acquire a full picture of the threat landscape. The European Parliament strongly opposes any extension of reporting obligations beyond actual security incidents, whereas the European Council’s compromise approach supports at least the mandatory reporting of incidents with the potential to cause significant harm. This paper outlines and analyses the concepts utilized in the trilogue negotiation—‘significant incident’, ‘near miss’ and ‘cyberthreat’—from a legal perspective. Further, the distinct reporting processes and timelines proposed are addressed. In consideration of the increased attack surface and threat scenario, deficits of the NISD identified before the mitigation measures by the NISD 2.0 Proposal are assessed.
Blockchain and smart contract technology have led to the creation of an alternative financial system called Decentralised Finance (DeFi) which has grown exponentially in the last year alone to a current value of $76B. Without a central custodian or regulator, non-technical users may find it difficult to assess the security of their favourite projects. In this trustless environment, can the current state-of-the-art smart contract analysis tools be used by non-technical users to protect investors from incurring losses and improving the security in the space? In the paper, we review the literature focusing on well-known vulnerabilities of financial smart contracts and show the scale of successful DeFi attacks. By analysing the root cause of recent exploits of contracts, we assess the feasibility of detecting these vulnerabilities by automatic verification. We investigate 21 analysis tools for detecting vulnerabilities in smart contracts with an in-depth evaluation of six tools: Slither, Mythril, DerScanner, Manticore, Oyente and Securify v2. The tools were evaluated for their efficiency and accuracy against a custom dataset containing 28 vulnerable and 16 healthy smart contracts and are ultimately rated based on how useful they may be from a DeFi user perspective. The results indicate that, while Slither received the highest rating, none of the existing tools can successfully assist DeFi users at present due to lack of reliability or lack of simplicity for the targeted market.
Ransomware is considered among the top threats that organizations have to face, and one that is not expected to go away anytime soon. Cyber criminals have turned ransomware into a profitable business by targeting environments in which they can maximize the attack's impact and their profits. The Maritime domain is a lucrative environment as it supports many aspects of the supply chain, making it a high priority target for cyber criminals. Recent ransomware incidents in the Maritime domain have demonstrated the necessity to increase the cyber risk awareness and readiness levels, to effectively address this threat. To defend and minimize the risk to get infected and/or recover if impacted by a ransomware, the required cybersecurity capacity needs to be developed. This can be achieved by educating and training all Maritime stakeholders, according to their role and responsibilities, across a strategic, operational, and/or tactical level. The challenge is to determine the capabilities that the Maritime stakeholders need to develop across the different levels, so they can exercise sound judgement and procedures when faced with a ransomware incident. This work presents an innovative training curriculum that was developed to build cybersecurity capacity in the Maritime domain and defend against ransomware attacks. A highlight of the proposed curriculum is that it specifies structured walkthrough practice to promote active learning and make education memorable and actionable. The proposed curriculum targets to provide design directions to the cybersecurity community to develop new training curricula to address future ransomware attacks.
The COVID-19 pandemic has helped amplify the importance of Cyber-hygiene. As the reliance on the Internet and IT services increased during the pandemic, this in turn has introduced a new wave of criminal activities such as cybercrimes. With the emergent of COVID-19 which lead to increase in cyber-attack incidents, the pattern, and sophistication, there is an urgent need to carry out an exploratory study to find out users’ level of cyber-hygiene knowledge and culture based on gender, employment status, and academic discipline. Above this, with many organizations providing for dual mode work pattern or remote and in-person as the pandemic subsides, this study still remains very relevant and hence the aim to investigate the cyber-hygiene knowledge and compliance of university students and employees of the University of Nigeria, Nsukka (UNN). In addition, it attempts to verify the relationship between demographics such as gender, employment status, and academic discipline on cyber-hygiene culture among students and employees. The sample population is made of employees and students of UNN, where the employees are either academic staff or non-academic staff. The sample size consisted of three hundred and sixteen (316) participants, one hundred and eight-seven (187) of whom were females and one hundred and twenty-nine (129) were males. The results offer some useful insight on cyber-hygiene practices at the university.
Containers are a popular technology that helps build portable and scalable applications. They use lightweight virtualization that wraps an application with all its dependencies, binaries and libraries. They are also isolated, and therefore, useful in systems that host multiple applications. The security of these containers is an important, yet widely overlooked, aspect of container deployment and maintenance. Since the use of containers is extensive and only growing, a weak security framework can lead to vulnerable containers and in some cases, vulnerable hosts as well. Though guidelines such as the CIS benchmark exist, they are too broad as they harden the entire container without accounting for the compatibility of the security measures with the functionality of the application. It is often observed that on hardening the container, the functionality is hindered and the container, though now secure, is unable to perform the task it was created for. Thus, selecting which parts of the benchmark to apply and which to skip is a crucial part of developing a hardening policy. This paper deals with hardening containers, specifically those provided by a company that we shall not name. This is done by analyzing the image statically (before it is deployed) and then dynamically (while it is running). The results are then used and analyzed to create a hardening policy for the containers.
Cybersecurity has never been more important than now (during/post-COVID-19 pandemic). In 2020, we experienced a global shift to remote work and many businesses had to adopt new technologies to facilitate this remote operation. With this change, there was not only the increased risk of exposure to new types of cyber attacks but also a lot of questions around how we should deal with these attacks. In particular, how do we present and visualise these new uncertainties and risks to ensure a more heightened cybersecurity awareness. This paper focuses on the use of lines and, in particular, how the advancement in the aesthetic of the line could afford enhanced cybersecurity awareness. The results from a large study showed the influence of design element colour and design principle emphasis to portray intuitive visual warnings of uncertainty. Moreover, we found that the use of unanticipated colours paired with aesthetic qualities can afford a stronger impression of dangers and risks as opposed to those conventionally associated with danger. In terms of cybersecurity visualisations, these findings show that advanced line aesthetics have the power to nurture a heightened cybersecurity awareness. Furthermore, portraying the potential to encode further warnings and information into cybersecurity visualisations that employ the use of lines (i.e. force directed graphs).