Replies: 1 comment
-
From my perspective, we should consider the following (according to the perdue model) :
The ontology "Embedded Computer" is ok for describing the Level 0 (physical process) components. To add for describing level 1 and level 2 components:
Network Node \ Host \ Client Computer
Digital Event \ Ressource Access \ Industrial Controler
Software
Software \ Applications Softwares \ Firmware
Network Traffic
Open topics due to my current weak knowledge on the framework:
|
Beta Was this translation helpful? Give feedback.
-
Model ATT&CK for ICS in the D3FEND Ontology
The goal of this discussion is to identify the requirements, challenges, and solution ideas for incorporating ATT&CK for ICS into the D3FEND ontology.
Digital Artifacts
D3FEND contains most of the necessary digital artifacts for this work in the upcoming 0.12.0 release. There will need to be some additions to the ontology including the various types of PLCs and the physical things they control.
Countermeasures
Additionally, we will have to add specific hardening and detection techniques related to those artifacts, though many of the existing countermeasures will also apply.
User Interface
We will also have to add some specific UI elements to help filter the D3FEND ontology and inference views based on offensive framework. We will likely have to create an additional data property on d3f:OffensiveTechnique to enable this.
Next Steps
Once we have this work further defined, we can create specific issues to add things to the ontology.
Beta Was this translation helpful? Give feedback.
All reactions