EDBT 2026 Demo / reviewers in the wild / expert
Pushparaj Bhosale
dblp:308/0949 · also Pushparaj Rajaram Bhosale
· DBLP profile ↗
8ranked-venue papers
8as first author
8since 2021 · last 2024
0000-0001-5760-2342ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 7 first-author · 7 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Modeling Human Error Factors with Security Incidents in Industrial Control Systems: A Bayesian Belief Network ApproachabstractIndustrial Control Systems (ICSs) are critical in automating and controlling industrial processes. Human errors within ICSs can significantly impact the system’s underlying processes and users’ safety. Thus, it is essential to understand the factors contributing to human errors and implement targeted interventions. Various factors that influence and mitigate human errors must be explored, including organizational, supervisory, personal, and technical factors. In parallel, the impact of a security incident also needs consideration. The paper presents a Bayesian Belief Network (BBN) model developed to model these factors comprehensively and demonstrate their impact, especially in the context of security incidents. Probability distributions are employed with practical assumptions to overcome data limitations, emphasizing the model’s utility in risk assessment. The model’s complexity is addressed using multiple interconnected sub-models, enhancing accuracy and avoiding unnecessary intricacies. Despite challenges in identifying all relevant factors, a sincere effort is made to incorporate diverse research findings. This paper highlights the essential role of BBN models in understanding and mitigating human errors, contributing to the resilience of ICS processes. The use of BBN and probabilistic distributions enables quantitative and probabilistic analysis of the impact of human errors, aiding in developing more robust risk management strategies to improve system resilience in ICSs. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ARES | 1 |
| 2024 | Comparative Analysis of AAS and AML as a Data Source for Integrated Risk Assessment in ICSabstractIntegrated risk assessment is important to identify, evaluate, and mitigate potential risks in Industrial Control Systems (ICS). It is necessary for safety and security within the organization. The safety and security data necessary for integrated risk assessment are obtained from various data sources that structure and manage information. In this paper, we look into information models as a potential single source of data. We compare different information models: Asset Administration Shell (AAS) and Automation Markup Language (AML). The comparison highlights the strengths and weaknesses, commonalities and differences of each data source in terms of data integration, real-time capability, standardization, design capability, automation possibility, and practical application in risk assessment processes. The findings underscore the importance of selecting appropriate data sources to enhance the accuracy, provide the possibility of updates, and enhance the efficiency of risk assessments in ICS. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 1 |
| 2024 | Mapping ICS Vulnerabilities: Prioritization and Risk Propagation Analysis with MITRE ATT&CK Framework and Bayesian Belief NetworksabstractThe introduction of Industry 4.0 and the integration of Information Technology (IT) with Operational Technology (OT) have brought significant advancements to Industrial Control Systems (ICS). With the convergence of IT/OT, ICS not only have to counteract against faults for safety reasons, but also have to encounter new challenges stemming from the security realm with an impact on safety issues. Ensuring the security of ICS has gained importance as any breach can cause disruption in industrial processes, leading to system downtime, production loss, and endangering human lives. Vulnerability assessment has become a crucial aspect of security research in ICS. The MITRE ATT&CK framework is one of the knowledge bases used for vulnerability management. It can be used to map identified vulnerabilities to a specific tactic provided by the framework. This mapping provides organizations with a structured approach focusing on identifying potential entry points for attackers and their progression through the system. The attacker's control of ICS could lead to a safety impact on people, processes, and the environment. This paper uses the mapping as a tool to prioritize the vulnerabilities and attacker's propagation through the network and thus help in building an effective risk propagation network using the Bayesian Belief Network (BBN). The implementation of the methodology is done using a Modular Production System (MPS) as a use case. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 1 |
| 2023 | AutomationML use for Safety and Security Risk Assessment in Industrial Control SystemsabstractThe increasing complexity and interconnectedness of Industrial Control Systems (ICSs) necessitate the integration of safety and security measures. Ensuring the protection of both personnel and critical assets has become a necessity. As a result, an integrated risk assessment approach is essential to comprehensively identify and address potential hazards and vulnerabilities. However, the data sources needed for an integrated risk assessment comes in many forms. In this context, Automation Markup Language (AutomationML or AML) emerges as a valuable solution to facilitate data exchange and integration in the risk assessment process. The benefits of utilizing AML include improved interoperability, enhanced documentation, and seamless collaboration between stakeholders. A model, filled with information relevant to integrated risk assessment, is developed to illustrate the effectiveness of AML. Ultimately, this paper showcases how AML serves as a valuable information model in meeting the growing need for comprehensive safety and security risk assessment in ICSs. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 1 |
| 2023 | Integrated Safety-Security Risk Assessment for Industrial Control System: An Ontology-based ApproachabstractIndustrial control systems (ICSs) are critical to the operation of industrial processes and critical infrastructure. Safety and security are crucial in any system or process, particularly in ICSs where failures can lead to severe consequences such as injury, loss of life, and damage to equipment and infrastructure. However, safety and security are often considered separately during the concept and design stages. An integrated risk assessment approach can combine safety and security considerations and provide a holistic evaluation of the overall risk to ICSs. Ontology-based approaches provide a systematic and structured method for representing knowledge and concepts related to risk assessment in industry. The aim of this paper is to develop an ontology based approach and generate a concept for integrating safety and security risk assessment. A case study is analysed using the ontology with a SPARQL query example. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 1 |
| 2023 | Integrated Safety-Security Risk Assessment for Production Systems: A Use Case Using Bayesian Belief NetworksabstractIndustrial control systems (ICSs) are complex networked systems that enable automation of large-scale processes. Depending on the application domain, the risk of the failure of components can have catastrophic repercussions. Up to now, a safety risk assessment is carried out to identify and narrow down possible failures. However, with the recent increase of cybersecurity attacks, a need of an integrated safety and security risk assessment is rising. This encompasses a comprehensive approach to assess the risks associated with ICSs and develop strategies for mitigating those risks. This paper proposes Bayesian Belief Network (BBN) as a representative of a probabilistic method and show its suitability for an integrated safety and security risk assessment. The method is evaluated by means of a use case. It provides risk propagation of functional safety, human safety and shows a propagation path from security to functional safety. The assessment is based on practical vulnerability assessments, technical documentations, manual observation and expert opinions. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
INDIN | 1 |
| 2022 | Automating Safety and Security Risk Assessment in Industrial Control Systems: Challenges and ConstraintsabstractCurrently, risk assessment of industrial control systems is static and performed manually. With the increased convergence of operational technology and information technology, risk assessment has to incorporate a combined safety and security analysis along with their interdependency. This paper investigates the data inputs required for safety and security assessments, also if the collection and utilisation of such data can be automated. A particular focus is put on integrated assessment methods which have the potential for automation. In case the overall process to identify potential hazards and threats and analyze what could happen if they occur can be automated, manual efforts and cost of operation can be reduced, thus also increasing the overall performance of risk assessment. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 1 |
| 2021 | A Centralised or Distributed Risk Assessment using Asset Administration ShellabstractThe application of Industry 4.0 (I4.0) architectures to the conservative nature of present Industrial Control System (ICS) has brought along many challenges. The ever-changing and dynamically altering threat landscape has led to many hazards and risks w.r.t. safe and secure operation of underlying assets. To understand and manage such risks, organizations perform assessments. Risk assessments performed today are typically handled in a centralized manner on a higher layer of the automation pyramid. The concept of the Asset Administration Shell (AAS) for I4.0 component might provide means to access and process data at the component level throughout the lifecycle, thus taking the assessment from a strictly centralized to a distributed manner. This paper, thus, focuses on the possibility of risk assessment either performed centrally or in a distributed manner aiming at highlighting data sources, acquisition, and processing mechanisms for the same relying on the AAS. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 1 |