A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
The broadening dependency and reliance that modern societies have on essential services provided by Critical Infrastructures is increasing the relevance of their trustworthiness. However, Critical Infrastructures are attractive targets for cyberattacks, due to the potential for considerable impact,...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2024-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/10378648/ |
_version_ | 1797361452345982976 |
---|---|
author | Joao Henriques Filipe Caldeira Tiago Cruz Paulo Simoes |
author_facet | Joao Henriques Filipe Caldeira Tiago Cruz Paulo Simoes |
author_sort | Joao Henriques |
collection | DOAJ |
description | The broadening dependency and reliance that modern societies have on essential services provided by Critical Infrastructures is increasing the relevance of their trustworthiness. However, Critical Infrastructures are attractive targets for cyberattacks, due to the potential for considerable impact, not just at the economic level but also in terms of physical damage and even loss of human life. Complementing traditional security mechanisms, forensics and compliance audit processes play an important role in ensuring Critical Infrastructure trustworthiness. Compliance auditing contributes to checking if security measures are in place and compliant with standards and internal policies. Forensics assist the investigation of past security incidents. Since these two areas significantly overlap, in terms of data sources, tools and techniques, they can be merged into unified Forensics and Compliance Auditing (FCA) frameworks. In this paper, we survey the latest developments, methodologies, challenges, and solutions addressing forensics and compliance auditing in the scope of Critical Infrastructure Protection. This survey focuses on relevant contributions, capable of tackling the requirements imposed by massively distributed and complex Industrial Automation and Control Systems, in terms of handling large volumes of heterogeneous data (that can be noisy, ambiguous, and redundant) for analytic purposes, with adequate performance and reliability. The achieved results produced a taxonomy in the field of FCA whose key categories denote the relevant topics in the literature. Also, the collected knowledge resulted in the establishment of a reference FCA architecture, proposed as a generic template for a converged platform. These results are intended to guide future research on forensics and compliance auditing for Critical Infrastructure Protection. |
first_indexed | 2024-03-08T15:54:55Z |
format | Article |
id | doaj.art-b675a42ef0ca47519c0cb0f389340d9f |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-03-08T15:54:55Z |
publishDate | 2024-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-b675a42ef0ca47519c0cb0f389340d9f2024-01-09T00:04:23ZengIEEEIEEE Access2169-35362024-01-01122409244410.1109/ACCESS.2023.334855210378648A Survey on Forensics and Compliance Auditing for Critical Infrastructure ProtectionJoao Henriques0https://orcid.org/0000-0001-7380-9511Filipe Caldeira1https://orcid.org/0000-0001-7558-2330Tiago Cruz2https://orcid.org/0000-0001-9278-6503Paulo Simoes3https://orcid.org/0000-0002-5079-8327Department of Informatics Engineering, Centre for Informatics and Systems of the University of Coimbra, University of Coimbra, Coimbra, PortugalCISeD—Research Centre in Digital Services, Polytechnic Institute of Viseu, Viseu, PortugalDepartment of Informatics Engineering, Centre for Informatics and Systems of the University of Coimbra, University of Coimbra, Coimbra, PortugalDepartment of Informatics Engineering, Centre for Informatics and Systems of the University of Coimbra, University of Coimbra, Coimbra, PortugalThe broadening dependency and reliance that modern societies have on essential services provided by Critical Infrastructures is increasing the relevance of their trustworthiness. However, Critical Infrastructures are attractive targets for cyberattacks, due to the potential for considerable impact, not just at the economic level but also in terms of physical damage and even loss of human life. Complementing traditional security mechanisms, forensics and compliance audit processes play an important role in ensuring Critical Infrastructure trustworthiness. Compliance auditing contributes to checking if security measures are in place and compliant with standards and internal policies. Forensics assist the investigation of past security incidents. Since these two areas significantly overlap, in terms of data sources, tools and techniques, they can be merged into unified Forensics and Compliance Auditing (FCA) frameworks. In this paper, we survey the latest developments, methodologies, challenges, and solutions addressing forensics and compliance auditing in the scope of Critical Infrastructure Protection. This survey focuses on relevant contributions, capable of tackling the requirements imposed by massively distributed and complex Industrial Automation and Control Systems, in terms of handling large volumes of heterogeneous data (that can be noisy, ambiguous, and redundant) for analytic purposes, with adequate performance and reliability. The achieved results produced a taxonomy in the field of FCA whose key categories denote the relevant topics in the literature. Also, the collected knowledge resulted in the establishment of a reference FCA architecture, proposed as a generic template for a converged platform. These results are intended to guide future research on forensics and compliance auditing for Critical Infrastructure Protection.https://ieeexplore.ieee.org/document/10378648/Critical infrastructure protectionindustrial automation and control systemscybersecurityforensicscompliance auditing |
spellingShingle | Joao Henriques Filipe Caldeira Tiago Cruz Paulo Simoes A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection IEEE Access Critical infrastructure protection industrial automation and control systems cybersecurity forensics compliance auditing |
title | A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection |
title_full | A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection |
title_fullStr | A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection |
title_full_unstemmed | A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection |
title_short | A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection |
title_sort | survey on forensics and compliance auditing for critical infrastructure protection |
topic | Critical infrastructure protection industrial automation and control systems cybersecurity forensics compliance auditing |
url | https://ieeexplore.ieee.org/document/10378648/ |
work_keys_str_mv | AT joaohenriques asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection AT filipecaldeira asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection AT tiagocruz asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection AT paulosimoes asurveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection AT joaohenriques surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection AT filipecaldeira surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection AT tiagocruz surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection AT paulosimoes surveyonforensicsandcomplianceauditingforcriticalinfrastructureprotection |