Skip to main navigation Skip to search Skip to main content

Micro Baselines for Operational Technology Environments

Gabriel Arthur Weaver, Samuel Patrick Farnan, Dan Gunter, Samuel Douglas Chanoski

Research output: Contribution to conferencePresentationpeer-review

Abstract

Critical infrastructure stakeholders need to baseline their networks to understand expected communications. Top-down approaches to baselining rely on observables that are generally available but lack properties upon which traditional statistical tools depend. We propose to construct micro-baselines: signatures within operational networks based on observables associated with specific events. Such observables are informed by precursor analysis reports of historical cyber attacks on operational environments developed by Cybersecurity for Operational Technology Environments (CyOTE). Baseline measurements depend upon context beyond the cyber domain. An energy plant's baseline running in the summer may statistically differ from a similar facility in a colder region. Domain knowledge must be integrated to apply general micro-baselining algorithms to a facility-specific context. Therefore, we propose to explore the feasibility of transferring micro baselining algorithms across different facilities. Facilities that implement the same processes in different geographic locations will be compared relative to observable measurements used in micro-baselining for comparable events. One evaluation approach would condition or augment dynamic observables measured within a facility network testbed with additional observables derived from geographic context or infrastructure dependencies such as those provided by the All-Hazards Analysis tool.
Original languageEnglish
StatePublished - Sep 27 2022

Fingerprint

Dive into the research topics of 'Micro Baselines for Operational Technology Environments'. Together they form a unique fingerprint.

Cite this