SecLab, Department of Informatics, University of Piraeus, Karaoli & Dimitriou 80, 18534 Piraeus, Greece.
Institut de Recherche en Informatique de Toulouse (IRIT), Université Paul Sabatier, 31062 Toulouse, France.
Sensors (Basel). 2021 Dec 29;22(1):238. doi: 10.3390/s22010238.
Maritime processes involve actors and systems that continuously change their underlying environment, location and threat exposure. Thus, risk mitigation requires a dynamic risk assessment process, coupled with an adaptive, event driven security enforcement mechanism, to efficiently deal with dynamically evolving risks in a cost efficient manner. In this paper, we propose an adaptive security framework that covers both situational risk assessment and situational driven security policy deployment. We extend MITIGATE, a maritime-specific risk assessment methodology, to capture situations in the risk assessment process and thus produce fine-grained and situation-specific, dynamic risk estimations. Then, we integrate DynSMAUG, a situation-driven security management system, to enforce adaptive security policies that dynamically implement security controls specific to each situation. To validate the proposed framework, we test it based on maritime cargo transfer service. We utilize various maritime specific and generic systems employed during cargo transfer, to produce dynamic risks for various situations. Our results show that the proposed framework can effectively assess dynamic risks per situation and automate the enforcement of adaptive security controls per situation. This is an important improvement in contrast to static and situation-agnostic risk assessment frameworks, where security controls always default to worst-case risks, with a consequent impact on the cost and the applicability of proper security controls.
海上活动涉及不断改变其底层环境、位置和威胁暴露的行为体和系统。因此,风险缓解需要一个动态风险评估过程,以及一个自适应的、事件驱动的安全执行机制,以便以高效和具有成本效益的方式处理动态演变的风险。在本文中,我们提出了一个涵盖情境风险评估和情境驱动的安全策略部署的自适应安全框架。我们扩展了专门针对海上活动的风险评估方法 MITIGATE,以捕获风险评估过程中的情境,从而生成细粒度和情境特定的动态风险估计。然后,我们集成了情境驱动的安全管理系统 DynSMAUG,以执行自适应安全策略,根据每个情境动态实施特定的安全控制。为了验证所提出的框架,我们基于海上货物转运服务对其进行了测试。我们利用货物转运过程中使用的各种特定于海上活动的和通用的系统,为各种情境生成动态风险。我们的结果表明,所提出的框架可以有效地评估每个情境的动态风险,并自动执行每个情境的自适应安全控制。与静态和情境无关的风险评估框架相比,这是一个重要的改进,因为静态和情境无关的风险评估框架中的安全控制总是默认采用最坏情况的风险,从而对成本和适当安全控制的适用性产生影响。