A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection

The broadening dependency and reliance that modern societies have on essential services provided by Critical Infrastructures is increasing the relevance of their trustworthiness. However, Critical Infrastructures are attractive targets for cyberattacks, due to the potential for considerable impact,...

Full description

Bibliographic Details
Main Authors: Joao Henriques, Filipe Caldeira, Tiago Cruz, Paulo Simoes
Format: Article
Language:English
Published: IEEE 2024-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/10378648/
_version_ 1797361452345982976
author Joao Henriques
Filipe Caldeira
Tiago Cruz
Paulo Simoes
author_facet Joao Henriques
Filipe Caldeira
Tiago Cruz
Paulo Simoes
author_sort Joao Henriques
collection DOAJ
description The broadening dependency and reliance that modern societies have on essential services provided by Critical Infrastructures is increasing the relevance of their trustworthiness. However, Critical Infrastructures are attractive targets for cyberattacks, due to the potential for considerable impact, not just at the economic level but also in terms of physical damage and even loss of human life. Complementing traditional security mechanisms, forensics and compliance audit processes play an important role in ensuring Critical Infrastructure trustworthiness. Compliance auditing contributes to checking if security measures are in place and compliant with standards and internal policies. Forensics assist the investigation of past security incidents. Since these two areas significantly overlap, in terms of data sources, tools and techniques, they can be merged into unified Forensics and Compliance Auditing (FCA) frameworks. In this paper, we survey the latest developments, methodologies, challenges, and solutions addressing forensics and compliance auditing in the scope of Critical Infrastructure Protection. This survey focuses on relevant contributions, capable of tackling the requirements imposed by massively distributed and complex Industrial Automation and Control Systems, in terms of handling large volumes of heterogeneous data (that can be noisy, ambiguous, and redundant) for analytic purposes, with adequate performance and reliability. The achieved results produced a taxonomy in the field of FCA whose key categories denote the relevant topics in the literature. Also, the collected knowledge resulted in the establishment of a reference FCA architecture, proposed as a generic template for a converged platform. These results are intended to guide future research on forensics and compliance auditing for Critical Infrastructure Protection.
first_indexed 2024-03-08T15:54:55Z
format Article
id doaj.art-b675a42ef0ca47519c0cb0f389340d9f
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-03-08T15:54:55Z
publishDate 2024-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-b675a42ef0ca47519c0cb0f389340d9f2024-01-09T00:04:23ZengIEEEIEEE Access2169-35362024-01-01122409244410.1109/ACCESS.2023.334855210378648A Survey on Forensics and Compliance Auditing for Critical Infrastructure ProtectionJoao Henriques0https://orcid.org/0000-0001-7380-9511Filipe Caldeira1https://orcid.org/0000-0001-7558-2330Tiago Cruz2https://orcid.org/0000-0001-9278-6503Paulo Simoes3https://orcid.org/0000-0002-5079-8327Department of Informatics Engineering, Centre for Informatics and Systems of the University of Coimbra, University of Coimbra, Coimbra, PortugalCISeD—Research Centre in Digital Services, Polytechnic Institute of Viseu, Viseu, PortugalDepartment of Informatics Engineering, Centre for Informatics and Systems of the University of Coimbra, University of Coimbra, Coimbra, PortugalDepartment of Informatics Engineering, Centre for Informatics and Systems of the University of Coimbra, University of Coimbra, Coimbra, PortugalThe broadening dependency and reliance that modern societies have on essential services provided by Critical Infrastructures is increasing the relevance of their trustworthiness. However, Critical Infrastructures are attractive targets for cyberattacks, due to the potential for considerable impact, not just at the economic level but also in terms of physical damage and even loss of human life. Complementing traditional security mechanisms, forensics and compliance audit processes play an important role in ensuring Critical Infrastructure trustworthiness. Compliance auditing contributes to checking if security measures are in place and compliant with standards and internal policies. Forensics assist the investigation of past security incidents. Since these two areas significantly overlap, in terms of data sources, tools and techniques, they can be merged into unified Forensics and Compliance Auditing (FCA) frameworks. In this paper, we survey the latest developments, methodologies, challenges, and solutions addressing forensics and compliance auditing in the scope of Critical Infrastructure Protection. This survey focuses on relevant contributions, capable of tackling the requirements imposed by massively distributed and complex Industrial Automation and Control Systems, in terms of handling large volumes of heterogeneous data (that can be noisy, ambiguous, and redundant) for analytic purposes, with adequate performance and reliability. The achieved results produced a taxonomy in the field of FCA whose key categories denote the relevant topics in the literature. Also, the collected knowledge resulted in the establishment of a reference FCA architecture, proposed as a generic template for a converged platform. These results are intended to guide future research on forensics and compliance auditing for Critical Infrastructure Protection.https://ieeexplore.ieee.org/document/10378648/Critical infrastructure protectionindustrial automation and control systemscybersecurityforensicscompliance auditing
spellingShingle Joao Henriques
Filipe Caldeira
Tiago Cruz
Paulo Simoes
A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
IEEE Access
Critical infrastructure protection
industrial automation and control systems
cybersecurity
forensics
compliance auditing
title A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
title_full A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
title_fullStr A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
title_full_unstemmed A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
title_short A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
title_sort survey on forensics and compliance auditing for critical infrastructure protection
topic Critical infrastructure protection
industrial automation and control systems
cybersecurity
forensics
compliance auditing
url https://ieeexplore.ieee.org/document/10378648/
work_keys_str_mv AT joaohenriques asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection
AT filipecaldeira asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection
AT tiagocruz asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection
AT paulosimoes asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection
AT joaohenriques surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection
AT filipecaldeira surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection
AT tiagocruz surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection
AT paulosimoes surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection