论文标题
使用建模和模拟来改善关键国家基础设施的网络安全性
Improving the Cybersecurity of Critical National Infrastructure using Modelling and Simulation
论文作者
论文摘要
英国关键国家基础设施在非常依赖于提供通信,监视,控制和决策支持功能的数字技术。数字技术正在逐步提高基础架构的效率,可靠性和可用性,并实现了以前无法获得的新福利。这些好处可以通过数字系统启用的连接性引入漏洞,因此,对于经常使用社会技术方法的可能攻击者而言,它使可能的攻击者更容易,从而利用了人类的人来闯入并破坏组织。因此,最小化和管理风险的政策和策略必须包括对操作员和公司行为以及技术要素以及他们与人之间的界面的理解。如果得到政府努力的支持,包括适当的政策干预措施,可以通过社会技术安全建模和模拟进行更好的安全性。政府通过其部门和机构可以通过签名和塑造有关网络安全的决策环境来做出贡献,以表明它们如何为增强现代关键关键基础设施系统的安全性做出贡献。
The UK Critical National Infrastructure is critically dependent on digital technologies that provide communications, monitoring, control, and decision-support functionalities. Digital technologies are progressively enhancing efficiency, reliability, and availability of infrastructure, and enabling new benefits not previously available. These benefits can introduce vulnerabilities through the connectivity enabled by the digital systems, thus, making it easier for would-be attackers, who frequently use socio-technical approaches, exploiting humans-in-the-loop to break in and sabotage an organization. Therefore, policies and strategies that minimize and manage risks must include an understanding of operator and corporate behaviors, as well as technical elements and the interfaces between them and humans. Better security via socio-technical security Modelling and Simulation can be achieved if backed by government effort, including appropriate policy interventions. Government, through its departments and agencies, can contribute by sign-posting and shaping the decision-making environment concerning cybersecurity M&S approaches and tools, showing how they can contribute to enhancing security in Modern Critical Infrastructure Systems.