Abstract
Operational technology (OT) systems face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a Bayesian network risk model to enhance the comprehension of observable cyber-events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that characterizes the stages of adversary behavior. The remainder of the model leverages the MITRE ATT CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper demonstrates the use of both historical data and expert knowledge to construct the Bayesian network. The historical data was obtained from open-source reporting of 27 cyber-attacks affecting OT systems. The expert knowledge was obtained from a panel of subject matter experts with experience in a variety of OT cybersecurity roles and responsibilities. Finally, the Bayesian network is demonstrated using two historical case studies: the Darkside ransomware attack on the Colonial Pipeline and the destructive cyber-attack targeting the Thyssenkrupp blast furnace. By using this approach, OT cybersecurity professionals can better identify and characterize adversarial behavior in their systems to enable risk-informed investigations and interruptions before impact occurs.
| Original language | English |
|---|---|
| Pages (from-to) | 10173-10188 |
| Number of pages | 16 |
| Journal | IEEE Transactions on Information Forensics and Security |
| Volume | 20 |
| Early online date | Sep 8 2025 |
| DOIs | |
| State | E-pub ahead of print - Sep 8 2025 |
Keywords
- Cybersecurity
- industrial control systems
- operational technology
INL Publication Number
- INL/JOU-24-77876
- 175706
Fingerprint
Dive into the research topics of 'Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver