Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Resilient Security Architecture for Operational Technology Environments Under Advanced Persistent Threat Conditions: A Layered Defense Model for Critical Infrastructure Protection

Beloved D. Smart, MSc, Demilade Jooda

Abstract

Abstract not found

References

[1] K. Stouffer, V. Pillitteri, S. Lightman, M. Abrams, and A. Hahn, 'Guide to Operational Technology (OT) Security,' NIST SP 800-82, Rev. 3, Sep. 2023. [2] K. Stouffer, S. Lightman, V. Pillitteri, M. Abrams, and A. Hahn, 'Guide to Industrial Control Systems Security,' NIST SP 800-82, Rev. 2, May 2015. [3] International Electrotechnical Commission, 'Security for Industrial Automation and Control Systems — System Security Requirements and Security Levels,' IEC 62443-3-3, 2013. [4] W. Stallings, Cryptography and Network Security: Principles and Practice, 7th ed. Hoboken, NJ: Pearson, 2017. [5] A. Cherepanov and R. Lipovsky, 'INDUSTROYER: Biggest Threat to Industrial Control Systems Since Stuxnet,' ESET Research, Jun. 2017. [6] Dragos, Inc., 'TRISIS Malware: Analysis of Safety System Targeted Attack,' Dragos Intelligence, Dec. 2017. [7] National Institute of Standards and Technology, 'Risk Management Framework for Information Systems and Organizations,' NIST SP 800-37, Rev. 2, Dec. 2018. [8] National Institute of Standards and Technology, 'Security and Privacy Controls for Information Systems and Organizations,' NIST SP 800-53, Rev. 5, Sep. 2020. [9] National Institute of Standards and Technology, 'Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1,' NIST, Apr. 2018. [10] National Institute of Standards and Technology, 'The NIST Cybersecurity Framework 2.0,' NIST, Feb. 2024. [11] Office of the Federal Register, '32 CFR Part 170 — Cybersecurity Maturity Model Certification Program,' DoD Final Rule, Oct. 2024. [12] Presidential Policy Directive 21 — Critical Infrastructure Security and Resilience, Feb. 12, 2013. [13] Cybersecurity and Infrastructure Security Agency, 'Volt Typhoon: PRC State-Sponsored Actors Compromising U.S. Critical Infrastructure,' Joint Advisory, Feb. 2024. [14] U.S. House of Representatives, Committee on Homeland Security, 'A Review of the Colonial Pipeline Cyber Attack,' Staff Report, Nov. 2021. [15] Cybersecurity and Infrastructure Security Agency, 'Compromise of U.S. Water Treatment Facility,' Alert AA21-042A, Feb. 2021. [16] Defense Counterintelligence and Security Agency, 'Supply Chain Risk Management Guidance,' DCSA, 2020. [17] Cybersecurity and Infrastructure Security Agency, 'AR21-196B: Kaseya VSA Supply-Chain Ransomware Attack,' Alert, Jul. 2021. [18] MITRE Corporation, 'ATT&CK for Enterprise,' Version 14, 2023. [19] MITRE Corporation, 'ATT&CK for ICS,' Version 14, 2023. [20] Ponemon Institute, '2023 Cost of Cyber Crime Study: United States,' Accenture, 2023. [21] U.S. Department of Energy, 'Cybersecurity Capability Maturity Model (C2M2),' Version 2.1, Jun. 2022. [22] N. Papernot, P. McDaniel, A. Sinha, and M. P. Wellman, 'SoK: Security and privacy in machine learning,' in Proc. IEEE EuroS&P, 2018, pp. 399-414. [23] Q. Yang, Y. Zhang, W. Dai, and S. J. Pan, Transfer Learning. Cambridge, UK: Cambridge Univ. Press, 2020. [24] R. Anderson, Security Engineering: A Guide to Building Dependable Distributed Systems, 3rd ed. Hoboken, NJ: Wiley, 2020. [25] O. Elebe, 'Enterprise cybersecurity trends and threat evolution, advances and emerging research directions,' 2024. [26] O. Elebe, 'Conceptual model for incident-driven security transformation and organizational reporting effectiveness,' 2024. [27] A. D. Bello, O. Elebe, N. I. Hammed, G. O. Omoegun, and O. Fadayomi, 'A cybersecurity risk management and regulatory compliance framework for financial institutions,' Iconic Res. Eng. J., vol. 8, no. 2, pp. 1180-1193, 2024, doi: 10.64388/IREV8I2-1713553. [28] O. Fadayomi, A. D. Bello, O. Elebe, N. I. Hammed, and G. O. Omoegun, 'An adaptive fraud risk scoring model for real-time transaction monitoring at scale,' IIARD Int. J. Bank. Finance Res., vol. 10, no. 10, pp. 212-230, 2024, doi: 10.56201/ijbfr.v10.no10.2024.pg212.230. [29] IBM Security, 'Cost of a Data Breach Report 2024,' IBM Corporation, Jul. 2024. [30] Verizon, '2024 Data Breach Investigations Report,' Verizon Communications, 2024. [31] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, 'Zero Trust Architecture,' NIST SP 800- 207, Aug. 2020. [32] Executive Order No. 14028, 'Improving the Nation's Cybersecurity,' 86 Fed. Reg. 26633, May 12, 2021. [33] Department of Defense, 'Defense Federal Acquisition Regulation Supplement Clause 252.204-7012,' 2020. [34] K. Mukasa, 'Establishing next-generation standards for regulatory compliance in Medicare finance,' Int. J. Comput. Appl. Technol. Res., vol. 12, no. 1, pp. 63-70, 2023. [Online]. Available: https://ijcat.com/archieve/volume12/issue1/ijcatr12011011.pdf [35] S. O. Taiwo and C. K. Amoah-Adjei, 'Financial risk optimization in consumer goods using Monte Carlo and machine learning simulations,' World J. Adv. Res. Rev., vol. 14, no. 1, pp. 665-678, 2022, doi: 10.30574/wjarr.2022.14.1.0385. [36] S. O. Taiwo, 'PFAITM: A predictive financial planning and analysis intelligence framework for transforming enterprise decision-making,' Int. J. Sci. Res. Sci. Eng. Technol., vol. 9, no. 6, pp. 472-487, 2022, doi: 10.32628/IJSRSET25122272. [37] S. O. Taiwo, C. K. Amoah-Adjei, and O. O. Aramide, 'Evidence-based consulting frameworks for CPG market resilience post supply-chain crises,' J. Comput. Anal. Appl., 2023. [38] J. T. Luttgens, M. Pepe, and K. Mandia, Incident Response and Computer Forensics, 3rd ed. New York: McGraw-Hill, 2014. [39] FireEye Inc., 'Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor,' FireEye Threat Research, Dec. 2020. [40] Cybersecurity and Infrastructure Security Agency, 'Roadmap for Artificial Intelligence,' CISA, Nov. 2023. [41] National Institute of Standards and Technology, 'Artificial Intelligence Risk Management Framework (AI RMF 1.0),' NIST, Jan. 2023. [42] J. Boyens et al., 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations,' NIST SP 800-161, Rev. 1, May 2022. [43] Cyber Incident Reporting for Critical Infrastructure Act of 2022, Pub. L. No. 117-103, Division Y. [44] D. W. Hubbard and R. Seiersen, How to Measure Anything in Cybersecurity Risk. Hoboken, NJ: Wiley, 2016. [45] K. Mukasa and L. O. Oluwasanya, 'Real-time data integration for healthcare fiscal sustainability,' World J. Adv. Res. Rev., vol. 16, no. 2, pp. 1322-1332, 2022, doi: 10.30574/wjarr.2022.16.2.1198. [46] OASIS CTI Technical Committee, 'STIX Version 2.1,' OASIS Standard, Jun. 2021. [47] M. Whitman and H. Mattord, Principles of Information Security, 5th ed. Stamford, CT: Cengage, 2017. [48] B. Biggio and F. Roli, 'Wild patterns: Ten years after the rise of adversarial machine learning,' Pattern Recognition, vol. 84, pp. 317-331, 2018. [49] Cybersecurity and Infrastructure Security Agency, 'SolarWinds and Active Exploitation of Critical Vulnerability,' Alert AA20-352A, Dec. 2020. [50] B. O. Olaogun, M. O. Adesuyi, O. Akomolafe, V. U. Ndukwe, and J. K. Sakyi, 'Regulatory compliance adaptation model for cross-border payment product redesign,' Int. J. Adv. Multidiscip. Res. Stud., vol. 3, no. 1, pp. 1651-1662, 2023. [51] O. Akomolafe, B. O. Olaogun, M. O. Adesuyi, V. U. Ndukwe, and J. K. Sakyi, 'Smart contract-based dispute resolution model for international supplier transactions,' Int. J. Adv. Multidiscip. Res. Stud., vol. 4, no. 1, pp. 1582-1601, 2024, doi: 10.62225/2583049X.2024.4.1.5282. [52] O. Akomolafe and M. U. Agu, 'A review of data-driven risk evaluation models for emerging market financial institutions,' IRE Journals, vol. 3, no. 6, 2019.

More Articles from INTERNATIONAL JOURNAL OF ENGINEERING AND MODERN TECHNOLOGY