A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical Attacks

Transportation networks are fundamental to the efficient and safe functioning of modern societies. In the past, physical and cyber space were treated as isolated environments, resulting in transportation network being considered vulnerable only to threats from the physical space (e.g., natural hazar...

Full description

Bibliographic Details
Main Authors: Konstantinos Ntafloukas, Liliana Pasquale, Beatriz Martinez-Pastor, Daniel P. McCrum
Format: Article
Language:English
Published: MDPI AG 2023-02-01
Series:Future Internet
Subjects:
Online Access:https://www.mdpi.com/1999-5903/15/3/100
_version_ 1797611587217915904
author Konstantinos Ntafloukas
Liliana Pasquale
Beatriz Martinez-Pastor
Daniel P. McCrum
author_facet Konstantinos Ntafloukas
Liliana Pasquale
Beatriz Martinez-Pastor
Daniel P. McCrum
author_sort Konstantinos Ntafloukas
collection DOAJ
description Transportation networks are fundamental to the efficient and safe functioning of modern societies. In the past, physical and cyber space were treated as isolated environments, resulting in transportation network being considered vulnerable only to threats from the physical space (e.g., natural hazards). The integration of Internet of Things-based wireless sensor networks into the sensing layer of critical transportation infrastructure has resulted in transportation networks becoming susceptible to cyber–physical attacks due to the inherent vulnerabilities of IoT devices. However, current vulnerability assessment methods lack details related to the integration of the cyber and physical space in transportation networks. In this paper, we propose a new vulnerability assessment approach for transportation networks subjected to cyber–physical attacks at the sensing layer. The novelty of the approach used relies on the combination of the physical and cyber space, using a Bayesian network attack graph that enables the probabilistic modelling of vulnerability states in both spaces. A new probability indicator is proposed to enable the assignment of probability scores to vulnerability states, considering different attacker profile characteristics and control barriers. A probability-based ranking table is developed that details the most vulnerable nodes of the graph. The vulnerability of the transportation network is measured as a drop in network efficiency after the removal of the highest probability-based ranked nodes. We demonstrate the application of the approach by studying the vulnerability of a transportation network case study to a cyber–physical attack at the sensing layer. Monte Carlo simulations and sensitivity analysis are performed as methods to evaluate the results. The results indicate that the vulnerability of the transportation network depends to a large extent on the successful exploitation of vulnerabilities, both in the cyber and physical space. Additionally, we demonstrate the usefulness of the proposed approach by comparing the results with other currently available methods. The approach is of interest to stakeholders who are attempting to incorporate the cyber domain into the vulnerability assessment procedures of their system.
first_indexed 2024-03-11T06:30:48Z
format Article
id doaj.art-30a64abaee0c465c81b4b0b8948b21a0
institution Directory Open Access Journal
issn 1999-5903
language English
last_indexed 2024-03-11T06:30:48Z
publishDate 2023-02-01
publisher MDPI AG
record_format Article
series Future Internet
spelling doaj.art-30a64abaee0c465c81b4b0b8948b21a02023-11-17T11:13:06ZengMDPI AGFuture Internet1999-59032023-02-0115310010.3390/fi15030100A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical AttacksKonstantinos Ntafloukas0Liliana Pasquale1Beatriz Martinez-Pastor2Daniel P. McCrum3School of Civil Engineering, University College Dublin, D07 R2WY Dublin, IrelandSchool of Computer Science, University College Dublin, D07 R2WY Dublin, IrelandSchool of Civil Engineering, University College Dublin, D07 R2WY Dublin, IrelandSchool of Civil Engineering, University College Dublin, D07 R2WY Dublin, IrelandTransportation networks are fundamental to the efficient and safe functioning of modern societies. In the past, physical and cyber space were treated as isolated environments, resulting in transportation network being considered vulnerable only to threats from the physical space (e.g., natural hazards). The integration of Internet of Things-based wireless sensor networks into the sensing layer of critical transportation infrastructure has resulted in transportation networks becoming susceptible to cyber–physical attacks due to the inherent vulnerabilities of IoT devices. However, current vulnerability assessment methods lack details related to the integration of the cyber and physical space in transportation networks. In this paper, we propose a new vulnerability assessment approach for transportation networks subjected to cyber–physical attacks at the sensing layer. The novelty of the approach used relies on the combination of the physical and cyber space, using a Bayesian network attack graph that enables the probabilistic modelling of vulnerability states in both spaces. A new probability indicator is proposed to enable the assignment of probability scores to vulnerability states, considering different attacker profile characteristics and control barriers. A probability-based ranking table is developed that details the most vulnerable nodes of the graph. The vulnerability of the transportation network is measured as a drop in network efficiency after the removal of the highest probability-based ranked nodes. We demonstrate the application of the approach by studying the vulnerability of a transportation network case study to a cyber–physical attack at the sensing layer. Monte Carlo simulations and sensitivity analysis are performed as methods to evaluate the results. The results indicate that the vulnerability of the transportation network depends to a large extent on the successful exploitation of vulnerabilities, both in the cyber and physical space. Additionally, we demonstrate the usefulness of the proposed approach by comparing the results with other currently available methods. The approach is of interest to stakeholders who are attempting to incorporate the cyber domain into the vulnerability assessment procedures of their system.https://www.mdpi.com/1999-5903/15/3/100transportation networkvulnerabilityinternet of thingscyber–physical attacksBayesian network attack graphefficiency
spellingShingle Konstantinos Ntafloukas
Liliana Pasquale
Beatriz Martinez-Pastor
Daniel P. McCrum
A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical Attacks
Future Internet
transportation network
vulnerability
internet of things
cyber–physical attacks
Bayesian network attack graph
efficiency
title A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical Attacks
title_full A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical Attacks
title_fullStr A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical Attacks
title_full_unstemmed A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical Attacks
title_short A Vulnerability Assessment Approach for Transportation Networks Subjected to Cyber–Physical Attacks
title_sort vulnerability assessment approach for transportation networks subjected to cyber physical attacks
topic transportation network
vulnerability
internet of things
cyber–physical attacks
Bayesian network attack graph
efficiency
url https://www.mdpi.com/1999-5903/15/3/100
work_keys_str_mv AT konstantinosntafloukas avulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks
AT lilianapasquale avulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks
AT beatrizmartinezpastor avulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks
AT danielpmccrum avulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks
AT konstantinosntafloukas vulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks
AT lilianapasquale vulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks
AT beatrizmartinezpastor vulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks
AT danielpmccrum vulnerabilityassessmentapproachfortransportationnetworkssubjectedtocyberphysicalattacks