Vol. 9 4, 2019 p 458-466


Article name, authors, abstract and keyword


Organizing the monitoring of vulnerabilities in the CPCS software and hardware

Tatyana V. Khozyainova a, Ivan A. Shechev a, Dmitry . Kobzev b, Zakhar S. Bengart a, Elvina G. Kutlubaeva a

a Industrial Automation CentreBranch of Transneft Upper Volga, JSC, 4a Komsomolskoe Shosse, Nizhny Novgorod, 603950, Russian Federation
b Transneft, 4, bldg 2, Presnenskaya Embankment, Moscow, 123112, Russian Federation

DOI: 10.28999/2541-9595-2019-9-4-458-466

Abstract: The approach to organizing the monitoring of vulnerabilities in software and hardware of Computerized Process Control Systems (CPCS) for Transneft subsidiaries facilities is considered. The developed process allows you to: 1) determine the data contents necessary for a qualified description of the vulnerability and deciding on how to respond to it; 2) identify the ways to obtain reliable data about the operating software; 3) develop a balanced set of vulnerability data sources, which allows to receive the most comprehensive vulnerability data in a timely manner and track changes in vulnerability characteristics; 4) formulate the rules for determining the current vulnerability based on the values of its characteristics correlated with the threat model.
In implementing the monitoring process, an information system was developed that allows to account vulnerabilities and track changes in their characteristics, to develop consolidated reporting and to accompany the process of creating technical information security service bulletins.

Keywords: computerized process control systems, software, cyberattack, vulnerability, information system.

For citation:
Khozyainova T. V., Shechev I. A., Kobzev D. ., Bengart Z. S., Kutlubaeva E. G. Organizing the monitoring of vulnerabilities in the CPCS software and hardware. Nauka i tehnologii truboprovodnogo transporta nefti i nefteproduktovScience &Technologies: Oil and Oil Products Pipeline Transportation. 2019;9(4):458466.

