Research Article

Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities

Volume: 13 Number: 1 March 26, 2024
EN

Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities

Abstract

An increase has been observed in concerns about cyber security threats in smart energy management on a global scale. Industrial Control Systems, or simply ICSs, are frequently present in industries and essential infrastructures, e.g., water treatment facilities, nuclear and thermal plants, heavy industries, power production, and distribution systems. ICS devices are high-risk targets for attacks and exploitation with significant security difficulties for ICS vendors and asset owners. Like many consumer electronics, industrial systems are susceptible to a bevy of vulnerabilities that hackers can exploit to launch cyber attacks. Extensive use of ICSs in Critical Infrastructures (CI) increases the vulnerability of CI to cyber attacks and makes their protection a critical subject. This study first contributes to a novel line of research considering how deception can be used by defenders in strategic terms with the objective of introducing uncertainty into an adversary’s perception of a system patch management process in order to protect ICSs. Thus, we mention the advantages of patch models to improve the vulnerabilities of ICSs. We explore deceptive patch management models for the purpose of providing better insight into developing future cyber security techniques for ICS attacks. We propose deceptive patch management solutions as case studies for common ICS attacks.

Keywords

References

  1. Alladi T, Chamola V, Zeadally S. Industrial control systems: Cyberattack trends and countermeasures. Computer Communications. 2020; 155(22):1–9.
  2. Asghar MR, Hu Q, Zeadally S. Cybersecurity in industrial control systems: Issues, technologies, and challenges. Computer Networks. 2019; (165):1389-1286.
  3. Jeffrey K, Avery. Application of deception to software security patching [dissertation]. Indiana: Purdue University, West Lafayette; 2017.
  4. Mughaid A, Al-Zu’bi S, Al Arjan A, Al-Amrat R, Alajmi R, Zitar RA, et al. An intelligent cybersecurity system for detecting fake news on social media websites. Soft Computing. 2022; 26(12):5577–5591.
  5. Mughaid A, AlZu’bi S, Alnajjar A, AbuElsoud E, Salhi SE, et al. Improved dropping attacks in 5G networks using machine learning and deep learning approaches. Multimedia Tools and Applications. 2022: 82(1): 1–23.
  6. Idrissi OE, Mezrioui A, Belmekki A. Cybersecurity challenges and issues of industrial control systems–some security recommendations. IEEE International Smart Cities Conference (ISC2). Casablanca: April; 2019. p. 330-335.
  7. Yantz M. [Internet]. Importance of patch management to avoid business vulnerabilities; 2023 [cited 2023 March 13]. Available from:https://itsupportguys.com/importance-of-patch-management-to-avoid-business-vulnerabilities.
  8. Hassani P. Implementing patch management process [dissertation]. School of Technology Degree Programme in Information and Communication Technology; 2020.

Details

Primary Language

English

Subjects

Engineering

Journal Section

Research Article

Early Pub Date

March 26, 2024

Publication Date

March 26, 2024

Submission Date

March 30, 2023

Acceptance Date

January 15, 2024

Published in Issue

Year 2024 Volume: 13 Number: 1

APA
Batur Dinler, Ö. (2024). Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities. Turkish Journal of Nature and Science, 13(1), 26-34. https://doi.org/10.46810/tdfd.1273507
AMA
1.Batur Dinler Ö. Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities. TJNS. 2024;13(1):26-34. doi:10.46810/tdfd.1273507
Chicago
Batur Dinler, Özlem. 2024. “Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities”. Turkish Journal of Nature and Science 13 (1): 26-34. https://doi.org/10.46810/tdfd.1273507.
EndNote
Batur Dinler Ö (March 1, 2024) Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities. Turkish Journal of Nature and Science 13 1 26–34.
IEEE
[1]Ö. Batur Dinler, “Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities”, TJNS, vol. 13, no. 1, pp. 26–34, Mar. 2024, doi: 10.46810/tdfd.1273507.
ISNAD
Batur Dinler, Özlem. “Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities”. Turkish Journal of Nature and Science 13/1 (March 1, 2024): 26-34. https://doi.org/10.46810/tdfd.1273507.
JAMA
1.Batur Dinler Ö. Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities. TJNS. 2024;13:26–34.
MLA
Batur Dinler, Özlem. “Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities”. Turkish Journal of Nature and Science, vol. 13, no. 1, Mar. 2024, pp. 26-34, doi:10.46810/tdfd.1273507.
Vancouver
1.Özlem Batur Dinler. Deceptive Patch Solutions for Protecting Industrial Control Systems Based on Discovered Vulnerabilities. TJNS. 2024 Mar. 1;13(1):26-34. doi:10.46810/tdfd.1273507