<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="client.xsl" type="text/xsl"?>
<article article-type="other">
<front>
<journal-meta>
<journal-id/>
<issn/>
<banner>
<href>banner.jpg</href>
<size width="100%"/>
</banner>
</journal-meta>
<doi>0597-cd</doi>
<article-meta>
<title-group>
<article-title>ICVSS: A New Methodology for Scoring Industrial Control Systems Vulnerabilities</article-title>
</title-group>

<author>Riad Chemali<sup>a</sup>, Blaise Conrard<sup>b</sup> and Mireille Bayart<sup>c</sup></author>

<aff>Univ. Lille, CNRS, Centrale Lille, UMR 9189 - CRIStAL - Centre de Recherche en Informatique Signal et Automatique de Lille, Lille, France</aff>

<email><a href="mailto:riad.chemali@univ-lille.fr"><sup>a</sup>riad.chemali@univ-lille.fr</a></email>

<email><a href="mailto:Blaise.Conrard@polytech-lille.fr"><sup>b</sup>Blaise.Conrard@polytech-lille.fr</a></email>

<email><a href="mailto:Mireille.Bayart@univ-lille.fr"><sup>c</sup>Mireille.Bayart@univ-lille.fr</a></email>

</article-meta></front>
<body>
<abstract>
<title>ABSTRACT</title>
<p>The modern ICSs (Industrial Control Systems) are based primarily on Operational Technologies (OTs) that have been inherited from a wide variety of Information Technologies (ITs). In order to ensure the ICSs requirements, several of ITs have been designed or adapted. These technologies are sometimes badly adapted or in some cases they are used with their vulnerabilities for cost reasons (use Commercial Off-The-Shelf products). As a result, new vulnerabilities appeared, and most of them have not been considered in the design phase. Therefore, their ranking, prioritizing and mitigating risks are a crucial task for organizations and researchers that are involved with the security and safety of ICSs systems. The open standard for scoring and classifying the vulnerabilities is the Common Vulnerability Scoring System (CVSS). The focus of this research is to show the limits of CVSS, and thereafter, to offer a first scoring system destined particularly for ICSs. In this paper, we introduced a new vulnerability scoring system, called ICVSS (Industrial Control Vulnerability Scoring System). The methodology uses different approaches to score vulnerabilities, depending on characteristics of ICSs to achieve better accuracy.</p>
<p><italic>Keywords: </italic>Cybersecurity, Safety, OT Security, Risk assessment, Risk management, CVSS, ICS.</p>
</abstract>
<fpdf>
<href>pdflogo.jpg</href>
<hpdf>0597</hpdf>
</fpdf>
</body>
</article>