학술논문

Towards Smarter Security Orchestration and Automatic Response for CPS and IoT
Document Type
Conference
Source
2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom) CLOUDCOM Cloud Computing Technology and Science (CloudCom), 2023 IEEE International Conference on. :298-302 Dec, 2023
Subject
Communication, Networking and Broadcast Technologies
Computing and Processing
Surveys
Data privacy
Cloud computing
Automation
Systematics
Security management
Decision making
Security Orchestration
CPS
IoT
Machine Learning
VR
CTI
Language
ISSN
2380-8004
Abstract
Current security orchestration and response (SOAR) approaches have primarily focused on specific layers of systems, such as Intrusion Detection Systems, the network layer, or the application layer. We aim to find the gaps in the existing SOAR approaches for IoT/CPS-based systems, especially critical infrastructures, and propose some directions to fill in these gaps. This paper presents a literature survey and future research directions for advancing SOAR towards increased automation and more holistic operation, especially for the cyber-physical security of critical infrastructures. We have found 14 primary SOAR studies and discussed the gaps in general. There is a significant gap when it comes to a comprehensive and systematic approach to SOAR for multi-layered systems using IoT/CPS and considering the computing continuum perspective. To address the gap, we present our on-going work on a framework of multi-layer SOAR decision-making methods and orchestration tools that leverage Reinforcement Learning (RL)-based adaptation intelligence, virtual reality, avatar-human interaction and advanced Cyber Threat Intelligence (CTI) tools.