Praetorian Framework For CIIP 3600160.3605030
Stephane Paul, Nicolas Museux Sandra König, Manuel Egger, Stefan Schauer
{stephane.paul,nicolas.museux} {sandra.koenig,manuel.egger,stefan.schauer}
THALES Research and Technology, France Austrian Institute of Technology
ABSTRACT
Combined cyber and physical attacks on Critical Infrastructures York, NY, USA, 6 pages.
have disastrous consequences on economies and in social well-
being. Protection and resilience of CIs under combined attacks is
challenging due to their complexity, reliance on ICT systems and 1 INTRODUCTION
the interdependences between different types of CIs. The PRAE- Combined cyber and physical attacks on Critical Infrastructures
TORIAN framework was designed to address these challenges, by (CIs) have major impact, not only on the owners and operators
integrating components responsible for detecting both cyber and of these CIs, but also on their customers and suppliers. People
physical threats. Additionally, it forecasts how the combined attacks in the vicinity of the attacked CIs, as well as neighboring and
will evolve and their cascading effects on interdependent CIs. The interrelated CIs are also affected, leading to widespread and often
PRAETORIAN framework was demonstrated based on a realistic massive damages in various sectors of the economy and in social
scenario in the Zagreb airport, combining both physical and cyber well-being.
attacks. There are many reasons why combined cyber and physical at-
tacks on CIs are expected to become more common. To mention just
CCS CONCEPTS a few, there is a proliferation of industrial control system malware,
• Security and privacy → Intrusion/anomaly detection and while there is an increased reliance of the industry and CIs on ICT
malware mitigation; Systems security. systems. Additionally, the industrial control system networks are
notoriously difficult to secure, while the cyber criminals have a
KEYWORDS proven business model. The impact of a coordinated physical at-
tack, a deliberate (cyber) disruption of critical automation systems,
Physical threats, Cyber threats, Critical Infrastructure Protection, a natural hazard or even a combined scenario including several
Decision Support System, Security kinds of attacks, can have disastrous consequences for the economy
ACM Reference Format:
Lazaros Papadopoulos, Antonios Karteris, Dimitrios Soudris, Eva Muñoz- Therefore, there is a need of methodologies and tools that meet
Navarro,, Juan José Hernández-Montesinos, Stephane Paul, Nicolas Museux, the expectation needs of the CI operators in addressing the security
Sandra König, Manuel Egger, Stefan Schauer, Javier Hingant Gómez, and Tamara challenges of combined attacks. These tools should extend the
Hadjina. 2023. PRAETORIAN: A Framework for the Protection of Critical capabilities of the typical legacy security systems for detecting
Infrastructures from advanced Combined Cyber and Physical Threats. In various types of threats and enable successful coordinated response
The 18th International Conference on Availability, Reliability and Security
to attacks. Also, they should be effective against combined attacks
including both physical and cyber threats. Finally, since no CI exists
and operates in isolation, the cascading effects of an attack on a
single CI to others should be identified and addressed. There are
The PRAETORIAN framework was designed to address the above (API), the Datagram Delivery Protocol (DDP) [4] and the Advanced
challenges [9]. It was developed in the context of the PRAETORIAN Message Queuing Protocol (AMQP) [6]. About the front-end, the
H2020 EU funded project. The framework targets CI operators and main PRAETORIAN HMI is the CR. However, each component (i.e.
it is an integrated toolset that allows a cooperative communication PSA, CSA and HSA) provides a user-friendly HMI, tailored to the
and effective preventive and mitigation actions among interrelated needs of CI operators.
CIs, before and during emergencies. In contrast to other frame- The following subsections are a detailed description of each
works, PRAETORIAN was designed to be more flexible and scalable, PRAETORIAN component, focusing on the features and the added
with features that allow it to be adapted to different types of CIs. value that each one provides compared to the typical legacy systems.
This paper is an overview of the PRAETORIAN system and
describes each PRAETORIAN component and the data flow between 2.1 Physical Situation Awareness
them. Also, it explains how each component can be used by the The role of the Physical Situation Awareness system (PSA) is to
operator and its added value in the detection and mitigation of collect and display information gathered from the physical domain
combined (i.e. cyber and physical) attacks. and particularly from various sensors installed in the area of the CI
The rest of the paper is organized as follows: Section 2 describes under study.
each PRAETORIAN component: The cyber, the physical, the hy- The PSA stores and retrieves data from the IOP through the DDP.
brid situation awareness and the coordinated response. Section 3 The main front-end is the PSA HMI, which consists of the following
explains how the PRAETORIAN was demonstrated in a realistic sections:
scenario, combining cyber and physical attacks in an airport and
in a medical laboratory. Finally, in Section 4 we draw conclusions. • Map, which is the central PSA HMI and shows the earth
globe with the different items (assets, agents, etc.) placed
on it (Figure 2). It provides many features which allow CI
operators to improve situation awareness with regard to the
Figure 1, shows the main components of the PRAETORIAN frame- physical domain of CIs.
work: • Scenes, which are used to define the areas of CIs on the map.
• The Physical Situation Awareness system (PSA) receives and • Cameras, which allows to watch and manage the camera
processes information from sensors and other IoT devices, streams.
such as object tracking devices and UAVs and generates • Chat, (i.e. a chat application integrated in the PSA), which en-
alarms when intrusion or hostile activity is detected at the ables bidirectional communication between different teams,
physical domain of a CI. as well as the exchange of files, such as videos.
• The Cyber Situation Awareness system (CSA) is responsible Figure 2 shows an example of the PSA map view, for a port CI.
for detecting threats in the cyber domain of the CIs. It relies Sensors in the area of the port are represented as icons on the map.
on novel tools, such a the cyber forecaster engine, which They are green by default. However, they can be configured so
complement existing well-established cyber-security tech- that their color changes depending on the measured value. As an
nologies. example, a sound sensor may change color when the sound of a
• The Hybrid Situation Awareness system (HSA) that analyzes drone is detected. (This is the case for the sound sensor, which has
events, predicts how attacks will evolve and calculates the turned into orange color in Figure 2).
cascading effects of attacks within the same and between CI operators can watch on the PSA HMI sensor real-time mea-
different CIs. surements and video streams. Unmanned vehicles are also visible
• The Coordinated Response system (CR) that integrates infor- on the map. They are shown as 3D models and they leave a trail
mation from all other components, generates security inci- on the map when they move. Additionally, the PSA integrates the
dents which trigger relevant notifications and recommends IDEMIA Augmented Vision Platform [5]. Examples of its capabili-
mitigation actions. Finally, it integrates various tools to fur- ties are the automatic detection of potential physical threats, such as
ther support effective response, enable efficient information intrusion detection, suspicious behavior, as well as face recognition
sharing with first responders, increase situation awareness and object classification.
based on social media and support the interaction with drone The PSA map HMI displays ongoing security incidents. In the
neutralization systems. context of PRAETORIAN, the incidents are defined as events which
Figure 1, highlights the flow of information between the afore- may require immediate action by CI Operators (e.g. smoke/fire or
mentioned components. The HSA receives events and alerts gen- unauthorized drone detection). By clicking on an incident located
erated by the PSA and CSA. The CR receives alerts from all com- on the map, operators can view details. For example, when the
ponents and generates relevant security incidents and proper no- incident is the detection of an unauthorized drone, clicking on it
tifications to operators and first responders, while it recommends will show the live video stream of the camera that has detected it.
mitigation actions. Finally, the PSA supports the creation of Emergency Population
The PRAETORIAN framework back-end is based on the InterOp- Warning System (EPWS) EU alerts. Operators can select an area
erability Platform (IOP), a database in which the generated data are around the incident. After selecting a message from existing tem-
stored and retrieved. It serves as a data sharing infrastructure for plates, the operator can potentially edit the message and send it to
all PRAETORIAN components. It offers a variety of connectivity the cell phones of the population in the area. As shown in Figure 3,
methods, including a RESTful Application Programming Interface a colored grid on the map indicates the number of cell phones in
PRAETORIAN: A Framework for the Protection of Critical Infrastructures from advanced Combined Cyber
each adjacent node. Then, the adjacent nodes may themselves react
to the incoming notification. They may change their state, and, in
turn, inform their own adjacent nodes. Thus, the GDT models the
cascading effects within a CI and between different interconnected
Based on the GDT, the Threat Propagation Engine (TPE) de-
scribes the direct and indirect consequences of alerts generated by
the PSA and the CSA, over time. In particular, for each alert for- Figure 9: A tool for security threat detection in social me-
warded to the HSA, the TPE is triggered and a set of interdependent dia. The text of the post is displayed. The keywords and the
threat propagation simulations is run. The simulation results are crawling rules are highlighted with red and yellow color, re-
used to estimate the potential consequences of the threat on the spectively, to provide explainable identifications.
overall network of interconnected CIs. The output of the TPE is
a prediction of the propagation of the cascading effects, which is
displayed on the HSA HMI.
Aside from the DSS, the PRAETORIAN system provides more
The HSA HMI displays on a map the predicted cascading effects,
options for the effective communication between operators and
as calculated by the TPE simulations, on a map (Figure 7). A graph-
first responders, through the Information Sharing & Communication
based representation is used, in which each node corresponds to
with FRs (ISC-FR) module. It relies on the theoretical concept of
a cyber or physical asset of a CI and each link corresponds to
of attribute trees in order to gather all of the information available
an interdependency. Different colors in each node indicate the
on the PRAETORIAN platform and discern the parts that are rele-
corresponding impact of the threat (i.e., the degree by which the
vant for each type of first responder, for a particular incident type.
asset was affected). Other features of the HMI include historical
Subsequently, the module uses the chat application as a channel
information of simulations for past alerts, filtering options, and
for bidirectional communication. More details about the ISC-FR
step-by-step display of the simulation results.
module can be found in [7].
Finally, the CR system offers connectivity with Twitter through
2.4 Coordinated Response the Social Media Security Threat Detection (SMSTD) and Integra-
The main CR module is the Decision Support System (DSS). It acts tion with Social Media (IWSM) modules. The SMSTD utilizes text
as a hub, as it collects all alerts and events generated by the PSA, crawling techniques in order to monitor the entirety of the global
CSA and HSA. Through a set of predefined rules, a sample of which Twitter stream and discern tweets that are potentially critical to the
can be seen in figure 8, the DSS generates events (i.e. information security of the CI, including tweets that mention data leaks, new
potentially useful to operators) and security incidents (i.e. infor- vulnerabilities and cyber attacks. A screenshot with an identified
mation that may require immediate action by operators). Once an tweet indicating a security threat is shown in Figure 9. The module
incident is created, responsible operators can be notified in a variety is customizable to the requirements of type of CI, as it prioratizes
of ways, including email, SMS or through a chat application, all posts which are potentially more relevant to the particular CI. The
of which are configurable through the notifiers page of the DSS. latter module (IWSM) offers a number of tweet templates that allow
Finally, in order to assist the operators in taking the appropriate the CI operators to generate messages for the public and share them
actions once an incident is generated, the DSS offers a configurable on the social media platform with the press of a button. Finally, a
list of recommended mitigation actions that the CI operator can third module provides a real-time feed of Twitter posts by the public
take. The mitigation actions proposed by the PRAETORIAN DSS during a crisis. The tool relies on machine learning techniques and
were obtained through interviews with the CI security operators. identifies relevant informative-only tweets which can enhance the
ARES 2023, August 29–September 01, 2023, Benevento, Italy L. Papadopoulos, et al.