The ICS-SEC KG: An Integrated Cybersecurity Resource for Industrial Control Systems
摘要
The convergence of Information Technology (IT) and Operational Technology (OT) in Industrial Control System (ICS) comes with severe cybersecurity challenges that increasingly pose threats to critical infrastructures. In this challenging environment, numerous standards and data sources exist that aim to facilitate the exchange of information and guide security assessment, detection, and mitigation. Despite this wealth of information, the relevant data is currently fragmented and not available as an integrated knowledge base. Existing approaches to link and integrate Cyber Threat Intelligence (CTI) across sources and represent them in a machine interpretable and interoperable manner mainly focus on IT security in general, leaving the ICS domain largely unexplored. To fill this critical gap, we present an integrated ICS-SEC Knowledge Graph (ICS-SEC KG) to support analyzing and managing the security of ICSs. We describe the conceptualization and pipeline to construct the KG from a broad range of ICS cybersecurity data sources as well as the underlying processes and infrastructure to continually update it. To ensure quality and consistency, we apply ontology validation and a set of SHACL constraints. We validate our approach in two application scenarios derived from real-world security incidents in the industrial domain and demonstrate its usefulness for threat intelligence exploration and vulnerability assessment. All materials and links for this paper are available at https://github.com/sepses/ics-sec-kg .