🤖 AI Summary
This work addresses the weak isolation and difficulty in identifying security risks in Operational Technology (OT) environments, where container deployments often require elevated privileges. To tackle this challenge, the paper proposes Container Security Risk Ontology (CSRO), the first ontology-driven approach specifically designed for OT container security. CSRO integrates five key domains—adversarial behaviors, contextual assumptions, attack scenarios, risk assessment rules, and container security artifacts—to enable end-to-end formal modeling and automated reasoning from deployment metadata to quantified risk levels. The ontology is designed with modularity, reproducibility, cross-context interpretability, and seamless integration with deployment artifacts, allowing straightforward extension to host and organizational layers. A case study demonstrates CSRO’s effectiveness in automatically identifying security risks within hybrid IT/OT architectures.
📝 Abstract
In operational technology (OT) contexts, containerised applications often require elevated privileges to access low-level network interfaces or perform administrative tasks such as application monitoring. These privileges reduce the default isolation provided by containers and introduce significant security risks. Security risk identification for OT container deployments is challenged by hybrid IT/OT architectures, fragmented stakeholder knowledge, and continuous system changes. Existing approaches lack reproducibility, interpretability across contexts, and technical integration with deployment artefacts. We propose a model-based approach, implemented as the Container Security Risk Ontology (CSRO), which integrates five key domains: adversarial behaviour, contextual assumptions, attack scenarios, risk assessment rules, and container security artefacts. Our evaluation of CSRO in a case study demonstrates that the end-to-end formalisation of risk calculation, from artefact to risk level, enables automated and reproducible risk identification. While CSRO currently focuses on technical, container-level treatment measures, its modular and flexible design provides a solid foundation for extending the approach to host-level and organisational risk factors.