Authors:
Steve Taylor
1
;
Norbert Goetze
2
;
Joerg Abendroth
2
;
Jens Kuhr
3
;
Rosella Mancilla
4
;
Bernd Ludwig Wenning
5
;
Pasindu Kuruppuarachchi
5
;
Aida Omerovic
6
;
Ravishankar Borgaonkar
6
;
Andrea Neverdal Skytterholm
6
;
Antonios Mpantis
7
;
George Triantafyllou
7
;
Oscar Garcia
8
and
Oleh Zaritskyi
9
Affiliations:
1
IT Innovation Centre, University of Southampton, Southampton, U.K.
;
2
Nokia Bell Labs, Munich Germany
;
3
Nokia Solutions and Networks, Munich, Germany
;
4
Ingegneria Informatica Spa, Rome, Italy
;
5
Munster Technological University, Cork, Ireland
;
6
SINTEF AS, Trondheim, Norway
;
7
Athens Technology Center, Athens, Greece
;
8
Data Analytics for Industries 4 0 SL, Xàtiva, Spain
;
9
World Research Center of Vortex Energy, Zaporizhzhya, Ukraine
Keyword(s):
Cybersecurity, Cybersecurity Testing, Intrusion and Anomaly Detection, Cybersecurity Indicators, Device Under Test (DUT), System Under Test (SUT), Decision Support, Risk Assessment.
Abstract:
This paper describes the concept and use of Indicators for cybersecurity decision support. We define an Indicator as observable information about a Device Under Test (DUT) or System Under Test (SUT) that potentially can underpin insight on its cybersecurity posture. We describe different types of Indicators, how they are generated by tools and components in a cybersecurity testing and monitoring framework, how they may be transformed to increase their utility and illustrate their use via an exemplary case in smart manufacturing. We summarise key observations and properties of Indicators based on collaborative multidisciplinary work that has brought together developers of tools that generate Indicators, tools that consume and analyse indicators, and representatives of users who have motivating scenarios where Indicators may inform about their cybersecurity posture.