Department of Electrical and Computer Engineering, Florida International University, Miami, FL 33174, USA.
Department of Computer Science, Utah Valley University, Orem, UT 84058, USA.
Sensors (Basel). 2023 Apr 17;23(8):4060. doi: 10.3390/s23084060.
Several critical infrastructures are integrating information technology into their operations, and as a result, the cyber attack surface extends over a broad range of these infrastructures. Cyber attacks have been a serious problem for industries since the early 2000s, causing significant interruptions to their ability to produce goods or offer services to their clients. The thriving cybercrime economy encompasses money laundering, black markets, and attacks on cyber-physical systems that result in service disruptions. Furthermore, extensive data breaches have compromised the personally identifiable information of millions of people. This paper aims to summarize some of the major cyber attacks that have occurred in the past 20 years against critical infrastructures. These data are gathered in order to analyze the types of cyber attacks, their consequences, vulnerabilities, as well as the victims and attackers. Cybersecurity standards and tools are tabulated in this paper in order to address this issue. This paper also provides an estimate of the number of major cyber attacks that will occur on critical infrastructure in the future. This estimate predicts a significant increase in such incidents worldwide over the next five years. Based on the study's findings, it is estimated that over the next 5 years, 1100 major cyber attacks will occur on critical infrastructures worldwide, each causing more than USD 1 million in damages.
一些关键基础设施正在将信息技术融入其运营之中,因此,网络攻击面已经扩展到了这些基础设施的广泛领域。自 21 世纪初以来,网络攻击一直是各行业的一个严重问题,严重干扰了它们生产商品或向客户提供服务的能力。蓬勃发展的网络犯罪经济包括洗钱、黑市以及针对网络物理系统的攻击,这些攻击会导致服务中断。此外,大规模的数据泄露已经泄露了数百万人的个人身份信息。本文旨在总结过去 20 年来针对关键基础设施的一些重大网络攻击。这些数据的收集目的是分析网络攻击的类型、其后果、漏洞,以及受害者和攻击者。本文还列出了一些网络安全标准和工具,以解决这一问题。本文还对未来关键基础设施将发生的重大网络攻击数量进行了估计。这一估计预测,未来五年全球此类事件将显著增加。根据研究结果,预计未来 5 年,全球将有 1100 起针对关键基础设施的重大网络攻击,每次攻击造成的损失超过 100 万美元。