Skip to main content

Research Repository

Advanced Search

Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases

Ani, Uchenna P. Daniel; Watson, Jeremy M.; Green, Benjamin; Craggs, Barnaby; Nurse, Jason R. C.

Authors

Jeremy M. Watson

Benjamin Green

Barnaby Craggs

Jason R. C. Nurse



Abstract

This paper presents a mapping framework for design factors and an implementation process for building credible Industrial Control Systems (ICS) security testbeds. The security and resilience of ICSs has become a critical concern to operators and governments following widely publicised cyber security events. The inability to apply conventional Information Technology security practice to ICSs further compounds challenges in adequately securing critical systems. To overcome these challenges, and do so without impacting live environments, testbeds are widely used for the exploration, development, and evaluation of security controls. However, how a testbed is designed and its attributes, can directly impact not only its viability but also its credibility. Combining systematic and thematic analysis, and the mapping of identified ICS security testbed design attributes, we propose a novel relationship map of credibility-supporting design factors (and their associated attributes) and a process implementation flow structure for ICS security testbeds. The framework and implementation process highlight the significance of demonstrating some design factors such as user/experimenter expertise, clearly defined testbed design objectives, simulation implementation approach, covered architectural components, core structural and functional characteristics covered, and evaluations to enhance confidence, trustworthiness and acceptance of ICS security testbeds as credible. These can streamline testbed requirement definition, improve design consistency and quality while reducing implementation costs.

Citation

Ani, U. P. D., Watson, J. M., Green, B., Craggs, B., & Nurse, J. R. C. (2021). Design Considerations for Building Credible Security Testbeds: Perspectives from Industrial Control System Use Cases. Journal of Cyber Security Technology, 5(2), 71-119. https://doi.org/10.1080/23742917.2020.1843822

Journal Article Type Article
Online Publication Date Nov 23, 2020
Publication Date Apr 3, 2021
Deposit Date Jul 6, 2023
Journal Journal of Cyber Security Technology
Print ISSN 2374-2917
Electronic ISSN 2374-2925
Publisher Taylor and Francis Group
Peer Reviewed Peer Reviewed
Volume 5
Issue 2
Pages 71-119
DOI https://doi.org/10.1080/23742917.2020.1843822
Keywords General Medicine
Additional Information Peer Review Statement: The publishing and review policy for this title is described in its Aims & Scope.; Aim & Scope: http://www.tandfonline.com/action/journalInformation?show=aimsScope&journalCode=tsec20; Received: 2020-02-12; Accepted: 2020-10-25; Published: 2020-11-23