<efrbr:recordSet xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:efrbr="http://vfrbr.info/efrbr/1.1" xmlns:efrbr-work="http://vfrbr.info/efrbr/1.1/work" xmlns:efrbr-expression="http://vfrbr.info/efrbr/1.1/expression" xmlns:efrbr-manifestation="http://vfrbr.info/efrbr/1.1/manifestation" xmlns:efrbr-person="http://vfrbr.info/efrbr/1.1/person" xmlns:efrbr-corporateBody="http://vfrbr.info/efrbr/1.1/corporateBody" xmlns:efrbr-concept="http://vfrbr.info/efrbr/1.1/concept" xmlns:efrbr-structure="http://vfrbr.info/efrbr/1.1/structure" xmlns:efrbr-responsible="http://vfrbr.info/efrbr/1.1/responsible" xmlns:efrbr-subject="http://vfrbr.info/efrbr/1.1/subject" xmlns:efrbr-other="http://vfrbr.info/efrbr/1.1/other" xsi:schemaLocation="http://vfrbr.info/efrbr/1.1 http://vfrbr.info/schemas/1.1/efrbr.xsd"><efrbr:entities><efrbr-work:work identifier="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4"><efrbr-work:titleOfTheWork>Towards integrating security in industrial engineering design practices</efrbr-work:titleOfTheWork></efrbr-work:work><efrbr-expression:expression identifier="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4"><efrbr-expression:titleOfTheExpression>Towards integrating security in industrial engineering design practices</efrbr-expression:titleOfTheExpression><efrbr-expression:formOfExpression vocabulary="DIAS:TYPES">
            Δημοσίευση σε Συνέδριο
            Conference Publication
         </efrbr-expression:formOfExpression><efrbr-expression:dateOfExpression type="issued">2023-07-11</efrbr-expression:dateOfExpression><efrbr-expression:dateOfExpression type="published">2021</efrbr-expression:dateOfExpression><efrbr-expression:languageOfExpression vocabulary="iso639-1">en</efrbr-expression:languageOfExpression><efrbr-expression:otherDistinguishingCharacteristic>This work has been partially supported by a grant (“Research in the Cybersecurity Domain: National Cybersecurity Strategy 2020-25”) awarded to the Research Centre of the Athens University of Economics &amp; Business (RC/AUEB). Authors express their sincere appreciation to the Ministry of Digital Governance of Greece.</efrbr-expression:otherDistinguishingCharacteristic><efrbr-expression:summarizationOfContent>During the past decades, and especially since the Stuxnet event, there has being a growing concern around the protection of critical infrastructures. Even though the protection of such systems and services has been an international security priority, still, even after all those years, relevant research either focuses on individual ICS systems security (PLC, RTU and SCADA network protection and attacks), or uses high-level models to perform risk assessments, mostly from a system-of-systems scope that studies interdependencies. From an engineering perspective, current approaches address system resilience from an efficiency perspective (i.e. focusing on the availability of physical processes) while neglecting the security dimension of their components. Still, the availability and reliability requirements of such systems are directly affected by security incidents. To our knowledge, there is currently no process to integrate security-by-design in industrial critical infrastructure engineering. To this end, we present a method to integrate security risk assessment analysis into engineering design practices. We do this by modeling internal dependencies between physical components in critical industrial production processes to identify possible hotspots of system failures that are challenging to handle later in the development lifecycle, especially during operation. To validate our approach, we model and assess the present situation in a portion of an actual oil refining plant, thereby establishing a baseline model. Then we introduce risk mitigation measures by altering the design of the baseline model, resulting in a reduction of the overall cascade risk.</efrbr-expression:summarizationOfContent><efrbr-expression:useRestrictionsOnTheExpression type="creative-commons">http://creativecommons.org/licenses/by-nc-nd/4.0/</efrbr-expression:useRestrictionsOnTheExpression><efrbr-expression:note type="page range">161-172</efrbr-expression:note><efrbr-expression:note type="conference name">18th International Conference on Security and Cryptography</efrbr-expression:note><efrbr-expression:note type="proceedings title">Proceedings of the 18th International Conference on Security and Cryptography</efrbr-expression:note></efrbr-expression:expression><efrbr-manifestation:manifestation identifier="https://dias.library.tuc.gr/view/96416"><efrbr-manifestation:titleOfTheManifestation>Dedousis_et_al_SECRYPT_2021.pdf</efrbr-manifestation:titleOfTheManifestation><efrbr-manifestation:publicationDistribution><efrbr-manifestation:placeOfPublicationDistribution type="distribution">Chania [Greece]</efrbr-manifestation:placeOfPublicationDistribution><efrbr-manifestation:publisherDistributor type="distributor">Library of TUC</efrbr-manifestation:publisherDistributor><efrbr-manifestation:dateOfPublicationDistribution>2023-07-11</efrbr-manifestation:dateOfPublicationDistribution></efrbr-manifestation:publicationDistribution><efrbr-manifestation:formOfCarrier>application/pdf</efrbr-manifestation:formOfCarrier><efrbr-manifestation:extentOfTheCarrier>768.9 kB</efrbr-manifestation:extentOfTheCarrier><efrbr-manifestation:accessRestrictionsOnTheManifestation>free</efrbr-manifestation:accessRestrictionsOnTheManifestation></efrbr-manifestation:manifestation><efrbr-person:person identifier="8124D605-7DCF-45F1-A6E3-2BAC3BB2C56E"><efrbr-person:nameOfPerson vocabulary="">
            Dedousis Panagiotis
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-person:person identifier="0FDAAE0C-DF95-4B17-9CD2-60CB77719E97"><efrbr-person:nameOfPerson vocabulary="">
            Stergiopoulos George
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-person:person identifier="http://users.isc.tuc.gr/~garampatzis"><efrbr-person:nameOfPerson vocabulary="TUC:LDAP">
            Arampatzis Georgios
            Αραμπατζης Γεωργιος
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-person:person identifier="https://viaf.org/viaf/12209857"><efrbr-person:nameOfPerson vocabulary="VIAF">
            Gritzalis, Dimitris
         </efrbr-person:nameOfPerson></efrbr-person:person><efrbr-corporateBody:corporateBody identifier="66D13666-472D-4780-B005-18B45D83B8F6"><efrbr-corporateBody:nameOfTheCorporateBody vocabulary="">
            SciTePress – Science and Technology Publications, Lda
         </efrbr-corporateBody:nameOfTheCorporateBody></efrbr-corporateBody:corporateBody><efrbr-concept:concept identifier="31478771-ADD0-4C54-973D-23789B7D1F06"><efrbr-concept:termForTheConcept>
            Component cascading failures
         </efrbr-concept:termForTheConcept></efrbr-concept:concept><efrbr-concept:concept identifier="C4B63DBA-7127-49C4-A391-D893F5B319AE"><efrbr-concept:termForTheConcept>
            Critical infrastructure protection
         </efrbr-concept:termForTheConcept></efrbr-concept:concept><efrbr-concept:concept identifier="1E25B9D2-5DF6-409E-AD98-E355346BEF89"><efrbr-concept:termForTheConcept>
            Dependency risk graphs
         </efrbr-concept:termForTheConcept></efrbr-concept:concept><efrbr-concept:concept identifier="2D7AF45E-0A76-4E01-BB77-4FF0D855AD69"><efrbr-concept:termForTheConcept>
            Resilience
         </efrbr-concept:termForTheConcept></efrbr-concept:concept></efrbr:entities><efrbr:relationships><efrbr-structure:structureRelations><efrbr-structure:realizedThrough sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="expression" targetURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4"/><efrbr-structure:embodiedIn sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="manifestation" targetURI="http://purl.tuc.gr/dl/dias/659C62DB-444D-4D6F-9B55-4036CEC0C43E"/></efrbr-structure:structureRelations><efrbr-responsible:responsibleRelations><efrbr-responsible:createdBy sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="person" targetURI="8124D605-7DCF-45F1-A6E3-2BAC3BB2C56E"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="person" targetURI="8124D605-7DCF-45F1-A6E3-2BAC3BB2C56E" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="person" targetURI="0FDAAE0C-DF95-4B17-9CD2-60CB77719E97" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="person" targetURI="http://users.isc.tuc.gr/~garampatzis" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="person" targetURI="https://viaf.org/viaf/12209857" role="author"/><efrbr-responsible:realizedBy sourceEntity="expression" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="person" targetURI="66D13666-472D-4780-B005-18B45D83B8F6" role="publisher"/></efrbr-responsible:responsibleRelations><efrbr-subject:subjectRelations><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="concept" targetURI="31478771-ADD0-4C54-973D-23789B7D1F06"/><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="concept" targetURI="C4B63DBA-7127-49C4-A391-D893F5B319AE"/><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="concept" targetURI="1E25B9D2-5DF6-409E-AD98-E355346BEF89"/><efrbr-subject:hasSubject sourceEntity="work" sourceURI="http://purl.tuc.gr/dl/dias/9218562F-E915-4939-806E-C748D8F20DA4" targetEntity="concept" targetURI="2D7AF45E-0A76-4E01-BB77-4FF0D855AD69"/></efrbr-subject:subjectRelations><efrbr-other:otherRelations/></efrbr:relationships></efrbr:recordSet>