Intentional threats are a major risk factor related to vulnerabilities in critical infrastructure assets, and an accurate risk assessment is necessary to analyze threats, assess vulnerabilities, and evaluate potential impacts on assets and systems. This research proposes a methodology that can be added as an additional phase in the risk assessment process. The method introduces an extra analytical parameter concerning offensive tool characteristics, improving the understanding of intentional threats. The methodology is presented using clear and accessible language suitable for a broad audience. It is based on an approach described as an "offensive tool determination strategy," summarized by the acronym R.I.D.D.L.E.+C, which refers to the variables used in the analysis: resistance, intrusion timing, damage, disruption timing, latency, efficiency, and cost. These variables are evaluated using open-source intelligence. Each variable is assigned a specific range of values according to its potential impact on the targeted asset. A matrix is then provided for practical application, which can reveal unexpected vulnerabilities and offer a more granular framework for decision-making and security planning.
翻译:蓄意威胁是关乎关键基础设施资产漏洞的主要风险因素,准确的风险评估对于分析威胁、评估漏洞以及衡量对资产和系统的潜在影响至关重要。本研究提出一种可作为风险评估流程附加阶段的方法论。该方法引入了一个关于攻击工具特性的额外分析参数,以提升对蓄意威胁的理解。该方法论采用清晰易懂的语言阐述,适合广泛读者群体。其基于一种称为“攻击工具确定策略”的方法,缩写为 R.I.D.D.L.E.+C,代表分析中使用的变量:抵抗性、入侵时机、破坏程度、中断时机、潜伏性、效率及成本。这些变量通过开源情报进行评估。每个变量根据其对目标资产的潜在影响被赋予特定取值范围。随后提供实用应用矩阵,该矩阵可揭示意外漏洞,并为决策制定与安全规划提供更精细的框架。