Home > Research > Publications & Outputs > Design Considerations for Building Credible Sec...

Electronic data

  • Credibility Paper

    Rights statement: This is an Accepted Manuscript of an article published by Taylor & Francis in Journal of Cyber Security Technology on 23 Nov 2020, available online: https://www.tandfonline.com/doi/abs/10.1080/23742917.2020.1843822

    Accepted author manuscript, 716 KB, PDF document

    Available under license: CC BY-NC: Creative Commons Attribution-NonCommercial 4.0 International License

Links

Text available via DOI:

View graph of relations

Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases

Research output: Contribution to Journal/MagazineJournal articlepeer-review

Published

Standard

Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases. / Ani, Uchenna D; Watson, Jeremy M; Green, Benjamin et al.
In: Journal of Cyber Security Technology, Vol. 5, No. 2, 23.11.2021, p. 71-119.

Research output: Contribution to Journal/MagazineJournal articlepeer-review

Harvard

Ani, UD, Watson, JM, Green, B, Craggs, B & Nurse, J 2021, 'Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases', Journal of Cyber Security Technology, vol. 5, no. 2, pp. 71-119. https://doi.org/10.1080/23742917.2020.1843822

APA

Ani, U. D., Watson, J. M., Green, B., Craggs, B., & Nurse, J. (2021). Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases. Journal of Cyber Security Technology, 5(2), 71-119. https://doi.org/10.1080/23742917.2020.1843822

Vancouver

Ani UD, Watson JM, Green B, Craggs B, Nurse J. Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases. Journal of Cyber Security Technology. 2021 Nov 23;5(2): 71-119. Epub 2020 Nov 23. doi: 10.1080/23742917.2020.1843822

Author

Ani, Uchenna D ; Watson, Jeremy M ; Green, Benjamin et al. / Design Considerations for Building Credible Security Testbeds : Perspectives from Industrial Control System Use Cases. In: Journal of Cyber Security Technology. 2021 ; Vol. 5, No. 2. pp. 71-119.

Bibtex

@article{3880d80c7e2b4463bfab891895c812a9,
title = "Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases",
abstract = "This paper presents a mapping framework for design factors and an implementation process for building credible Industrial Control Systems (ICS) security testbeds. The security and resilience of ICSs has become a critical concern to operators and governments following widely publicised cyber security events. The inability to apply conventional Information Technology security practice to ICSs further compounds challenges in adequately securing critical systems. To overcome these challenges, and do so without impacting live environments, testbeds are widely used for the exploration, development, and evaluation of security controls. However, how a testbed is designed and its attributes, can directly impact not only its viability but also its credibility. Combining systematic and thematic analysis, and the mapping of identified ICS security testbed design attributes, we propose a novel relationship map of credibility-supporting design factors (and their associated attributes) and a process implementation flow structure for ICS security testbeds. The framework and implementation process highlight the significance of demonstrating some design factors such as user/experimenter expertise, clearly defined testbed design objectives, simulation implementation approach, covered architectural components, core structural and functional characteristics covered, and evaluations to enhance confidence, trustworthiness and acceptance of ICS security testbeds as credible. These can streamline testbed requirement definition, improve design consistency and quality while reducing implementation costs.",
author = "Ani, {Uchenna D} and Watson, {Jeremy M} and Benjamin Green and Barnaby Craggs and Jason Nurse",
note = "This is an Accepted Manuscript of an article published by Taylor & Francis in Journal of Cyber Security Technology on 23 Nov 2020, available online: https://www.tandfonline.com/doi/abs/10.1080/23742917.2020.1843822",
year = "2021",
month = nov,
day = "23",
doi = "10.1080/23742917.2020.1843822",
language = "English",
volume = "5",
pages = " 71--119",
journal = "Journal of Cyber Security Technology",
publisher = "Taylor & Francis",
number = "2",

}

RIS

TY - JOUR

T1 - Design Considerations for Building Credible Security Testbeds

T2 - Perspectives from Industrial Control System Use Cases

AU - Ani, Uchenna D

AU - Watson, Jeremy M

AU - Green, Benjamin

AU - Craggs, Barnaby

AU - Nurse, Jason

N1 - This is an Accepted Manuscript of an article published by Taylor & Francis in Journal of Cyber Security Technology on 23 Nov 2020, available online: https://www.tandfonline.com/doi/abs/10.1080/23742917.2020.1843822

PY - 2021/11/23

Y1 - 2021/11/23

N2 - This paper presents a mapping framework for design factors and an implementation process for building credible Industrial Control Systems (ICS) security testbeds. The security and resilience of ICSs has become a critical concern to operators and governments following widely publicised cyber security events. The inability to apply conventional Information Technology security practice to ICSs further compounds challenges in adequately securing critical systems. To overcome these challenges, and do so without impacting live environments, testbeds are widely used for the exploration, development, and evaluation of security controls. However, how a testbed is designed and its attributes, can directly impact not only its viability but also its credibility. Combining systematic and thematic analysis, and the mapping of identified ICS security testbed design attributes, we propose a novel relationship map of credibility-supporting design factors (and their associated attributes) and a process implementation flow structure for ICS security testbeds. The framework and implementation process highlight the significance of demonstrating some design factors such as user/experimenter expertise, clearly defined testbed design objectives, simulation implementation approach, covered architectural components, core structural and functional characteristics covered, and evaluations to enhance confidence, trustworthiness and acceptance of ICS security testbeds as credible. These can streamline testbed requirement definition, improve design consistency and quality while reducing implementation costs.

AB - This paper presents a mapping framework for design factors and an implementation process for building credible Industrial Control Systems (ICS) security testbeds. The security and resilience of ICSs has become a critical concern to operators and governments following widely publicised cyber security events. The inability to apply conventional Information Technology security practice to ICSs further compounds challenges in adequately securing critical systems. To overcome these challenges, and do so without impacting live environments, testbeds are widely used for the exploration, development, and evaluation of security controls. However, how a testbed is designed and its attributes, can directly impact not only its viability but also its credibility. Combining systematic and thematic analysis, and the mapping of identified ICS security testbed design attributes, we propose a novel relationship map of credibility-supporting design factors (and their associated attributes) and a process implementation flow structure for ICS security testbeds. The framework and implementation process highlight the significance of demonstrating some design factors such as user/experimenter expertise, clearly defined testbed design objectives, simulation implementation approach, covered architectural components, core structural and functional characteristics covered, and evaluations to enhance confidence, trustworthiness and acceptance of ICS security testbeds as credible. These can streamline testbed requirement definition, improve design consistency and quality while reducing implementation costs.

U2 - 10.1080/23742917.2020.1843822

DO - 10.1080/23742917.2020.1843822

M3 - Journal article

VL - 5

SP - 71

EP - 119

JO - Journal of Cyber Security Technology

JF - Journal of Cyber Security Technology

IS - 2

ER -