Hide metadata

dc.date.accessioned2020-07-03T19:28:25Z
dc.date.available2020-07-03T19:28:25Z
dc.date.created2020-02-29T18:21:21Z
dc.date.issued2020
dc.identifier.citationShrestha, Manish Johansen, Christian Noll, Josef Roverso, Davide . A Methodology for Security Classification applied to Smart Grid Infrastructures. International Journal of Critical Infrastructure Protection. 2020, 28, 100342
dc.identifier.urihttp://hdl.handle.net/10852/77471
dc.description.abstractThe electricity grid is an important critical infrastructure that is undergoing major changes, due to the Internet of Things (IoT) and renewable energy, heading towards the smart grid. However, besides the many good promises of the smart grid, such as better peak control, cheaper maintenance, and more open energy markets, there are many new security threats evolving, especially from the IoT side, and also from the diversification of the systems and practices that the smart grid brings. We thus see the need for more light-weight and dynamic methods for conducting security analyses of systems applicable at (re)design time, intended to help system engineers build secure systems from the start. As a consequence, the methods should also look more at the functionalities (exposure/protection) of the system than at the possible attacks. In this paper we propose a methodology called Smart Grid Security Classification (SGSC) developed for complex systems like the smart grid, focusing on the specifics of Advanced Metering Infrastructure (AMI) systems. Our methodology is built upon the Agence nationale de la sécurité des systémes d’information (ANSSI) standard methodology for security classification of general Information and Communication Systems (ICS). Analyses performed following our method easily translate into ANSSI valid reports. Our SGSC is related to methods of risk analysis with the difference that our classification method has the purpose to assign a system to a security class, based on (combinations of) scores given to the various exposure aspects of the system and the respective protection mechanisms implemented; without looking at attackers. There are multiple uses of SGSC, such as offering indications to decision-makers about the security aspects of a system and for deciding purchasing strategies, for regulatory bodies to certify various complex infrastructure systems, but also for system/security designers to make easier choices of correct functionalities that would allow to reach a desired level of security. Particularly useful for smart grid systems is the discussion and mapping that we do of the SGSC methodology to a complex AMI infrastructure description derived from real deployments being done in ongoing Norwegian smart grid upgrades.
dc.languageEN
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.titleA Methodology for Security Classification applied to Smart Grid Infrastructures
dc.typeJournal article
dc.creator.authorShrestha, Manish
dc.creator.authorJohansen, Christian
dc.creator.authorNoll, Josef
dc.creator.authorRoverso, Davide
cristin.unitcode185,15,30,30
cristin.unitnameSeksjon for autonome systemer og sensorteknologier
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1
dc.identifier.cristin1798658
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.jtitle=International Journal of Critical Infrastructure Protection&rft.volume=28&rft.spage=100342&rft.date=2020
dc.identifier.jtitleInternational Journal of Critical Infrastructure Protection
dc.identifier.volume28
dc.identifier.doihttps://doi.org/10.1016/j.ijcip.2020.100342
dc.identifier.urnURN:NBN:no-80568
dc.type.documentTidsskriftartikkel
dc.type.peerreviewedPeer reviewed
dc.source.issn1874-5482
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/77471/4/1-s2.0-S1874548220300068-main.pdf
dc.type.versionPublishedVersion
cristin.articleid100342
dc.relation.projectNFR/248113


Files in this item

Appears in the following Collection

Hide metadata

Attribution-NonCommercial-NoDerivatives 4.0 International
This item's license is: Attribution-NonCommercial-NoDerivatives 4.0 International