{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T14:15:06Z","timestamp":1784556906656,"version":"3.55.0"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2023,12,11]],"date-time":"2023-12-11T00:00:00Z","timestamp":1702252800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,12,11]],"date-time":"2023-12-11T00:00:00Z","timestamp":1702252800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100005626","name":"Universit\u00e4t Regensburg","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100005626","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2024,4]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Organizations face attacks on industrial control systems (ICS) as vulnerabilities are pervasive. However, patching vulnerable systems by simply updating to the newest version is often not an option and shifts focus to workarounds. Beyond pure patching, workarounds specify other remediation measures (e.g., firewall or VPN configuration) that must be taken due to system availability requirements, complexity, or heterogeneous devices. In this paper, we introduce vulnerability playbooks based on open standards. Pushing the envelope of cybersecurity playbooks\u2014steps organizations should follow when responding to cybersecurity incidents reactively\u2014for ICS vulnerability management offers organizations a more transparent, repeatable process and faster, possibly automated actions. We have designed a process model to collect and transform security advisories in <jats:italic>Common Security Advisory Framework<\/jats:italic> (CSAF) format and generate <jats:italic>Collaborative Automated Course of Action Operations<\/jats:italic> (CACAO) playbooks based on listed remediation advice. With a proof of concept, we demonstrate that structured CSAF documents can be seamlessly transformed into CACAO playbooks. For our industrial use case, we must also use unstructured security advice highlighting quality differences (compared to CSAF). Our generated 79 standard conformant CACAO playbooks with 485 identified actions hint at imbalanced advice toward patching. Preferably, vendors should include detailed technical remediation advice, provide APIs, and go beyond patching recommendations in their security advisories. Subscribers should structure their assets and use machine learning to normalize, generate, and prioritize CACAO playbooks. With CSAF and CACAO, we see two open standards for handling vulnerabilities.<\/jats:p>","DOI":"10.1007\/s10207-023-00760-5","type":"journal-article","created":{"date-parts":[[2023,12,11]],"date-time":"2023-12-11T18:09:54Z","timestamp":1702318194000},"page":"1215-1230","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Generating ICS vulnerability playbooks with open standards"],"prefix":"10.1007","volume":"23","author":[{"given":"Philip","family":"Empl","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel","family":"Schlette","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lukas","family":"St\u00f6ger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,12,11]]},"reference":[{"key":"760_CR1","unstructured":"Lawson, C., Price, A.: market guide for security orchestration, automation and response solutions (2022)"},{"key":"760_CR2","unstructured":"Biden, J.R.J.: Executive order on improving the nation\u2019s cybersecurity. https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/. Last accessed 2023-06-05 (2022)"},{"key":"760_CR3","unstructured":"Forum of Incident Response and Security Teams (FIRST). Automation sig. https:\/\/www.first.org\/global\/sigs\/automation\/. Last accessed 2023-06-05 (2023)"},{"key":"760_CR4","doi-asserted-by":"publisher","unstructured":"Stevens, R., Votipka, D., Dykstra, J., Tomlinson, F., Quartararo, E., Ahern, C., Mazurek, M.L.: How ready is your ready? Assessing the usability of incident response playbook frameworks. In: Proceedings of the 2022 SIGCHI Conference on Human Factors in Computing Systems (CHI \u201922) (ACM), pp. 1\u201318. https:\/\/doi.org\/10.1145\/3491102.3517559 (2022)","DOI":"10.1145\/3491102.3517559"},{"key":"760_CR5","unstructured":"OASIS. Cacao security playbooks version 1.0\u2014committee specification 02. https:\/\/docs.oasis-open.org\/cacao\/security-playbooks\/v1.0\/security-playbooks-v1.0.html. Last accessed 2023-06-05 (2021)"},{"key":"760_CR6","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA), Federal government cybersecurity incident and vulnerability response playbooks. Tech. rep., Cybersecurity and Infrastructure Security Agency (CISA) (2021)"},{"key":"760_CR7","doi-asserted-by":"publisher","unstructured":"Wang, B., Li, X., de\u00a0Aguiar, L.P., Menasche, D.S., Shafiq, Z.: Characterizing and modeling patching practices of industrial control systems. In: Proceedings of the 2017 ACM on Measurement and Analysis of Computing Systems (POMACS \u201917), vol. 1(1), p. 1. https:\/\/doi.org\/10.1145\/3078505.3078524 (2017)","DOI":"10.1145\/3078505.3078524"},{"key":"760_CR8","unstructured":"Cybersecurity & Infrastructure Security Agency (CISA). Ics-cert advisories. https:\/\/www.cisa.gov\/uscert\/ics\/advisories. Last accessed 2023-06-05 (2023)"},{"key":"760_CR9","unstructured":"OASIS. Common security advisory framework version 2.0\u2014committee specification 03. https:\/\/docs.oasis-open.org\/csaf\/csaf\/v2.0\/csaf-v2.0.html. Last accessed 2023-06-05 (2022)"},{"key":"760_CR10","unstructured":"National Vulnerability Database (NVD). Cve-2022-34819 detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-34819. Last accessed 2023-06-05 (2022)"},{"key":"760_CR11","unstructured":"Common Vulnerabilities and Exposures (CVE). https:\/\/cve.mitre.org\/. Accessed 20 July 2023 (2023)"},{"key":"760_CR12","unstructured":"National Vulnerability Database (NVD) Common Platform Enumeration (CPE). https:\/\/nvd.nist.gov\/products\/cpe. Accessed 20 July 2023 (2023)"},{"key":"760_CR13","unstructured":"Common Vulnerability Scoring System (CVSS). https:\/\/www.first.org\/cvss\/. Accessed 20 July 2023 (2023)"},{"key":"760_CR14","unstructured":"OASIS Common Security Advisory Framework (CSAF) Technical Committee. https:\/\/www.oasis-open.org\/committees\/tc_home.php?wg_abbrev=csaf. Accessed 20 July 2023 (2023)"},{"key":"760_CR15","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1016\/j.cose.2016.04.003","volume":"60","author":"F Skopik","year":"2016","unstructured":"Skopik, F., Settanni, G., Fiedler, R.: A problem shared is a problem halved: a survey on the dimensions of collective cyber defense through security information sharing. Comput. Secur. 60, 154 (2016). https:\/\/doi.org\/10.1016\/j.cose.2016.04.003","journal-title":"Comput. Secur."},{"key":"760_CR16","doi-asserted-by":"publisher","unstructured":"Gascon, H., Grobauer, B., Schreck, T., Rist, L., Arp, D., Rieck, K.: Mining attributed graphs for threat intelligence. In: Proceedings of the 7th ACM on Conference on Data and Application Security and Privacy (CODASPY \u201917) (ACM, 2017), pp. 15\u201322. https:\/\/doi.org\/10.1145\/3029806.3029811","DOI":"10.1145\/3029806.3029811"},{"issue":"4","key":"760_CR17","doi-asserted-by":"publisher","first-page":"2525","DOI":"10.1109\/COMST.2021.3117338","volume":"23","author":"D Schlette","year":"2021","unstructured":"Schlette, D., Caselli, M., Pernul, G.: A comparative study on cyber threat intelligence: the security incident response perspective. IEEE Commun. Surv. Tutor. 23(4), 2525 (2021). https:\/\/doi.org\/10.1109\/COMST.2021.3117338","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"760_CR18","unstructured":"OASIS. Open command and control (OpenC2) language specification version 1.0\u2014committee specification 02. https:\/\/docs.oasis-open.org\/openc2\/oc2ls\/v1.0\/oc2ls-v1.0.html. Last accessed 2023-06-05 (2019)"},{"key":"760_CR19","unstructured":"MITRE. Detection, denial, and disruption framework empowering network defense (D3FEND). https:\/\/d3fend.mitre.org\/. Last accessed 2023-06-05 (2023)"},{"key":"760_CR20","unstructured":"ATC Project. RE &CT framework documentation. https:\/\/atc-project.github.io\/atc-react\/. Last accessed 2023-06-05 (2020)"},{"key":"760_CR21","doi-asserted-by":"publisher","unstructured":"West-Brown, M.J., Stikvoort, D., Kossakowski, K.P., Killcrece, G., Ruefle, R., Zajicek, M.: Handbook for computer security incident response teams (CSIRTs). Tech. rep., Defense Technical Information Center. https:\/\/doi.org\/10.21236\/ada413778 (2003)","DOI":"10.21236\/ada413778"},{"key":"760_CR22","doi-asserted-by":"publisher","unstructured":"Senthivel, S., Dhungana, S., Yoo, H., Ahmed, I., Roussev, V.: Denial of engineering operations attacks in industrial control systems. In: Proceedings of the 8th ACM Conference on Data and Application Security and Privacy (CODASPY \u201922) (ACM), CODASPY \u201918, pp. 319\u2013329. https:\/\/doi.org\/10.1145\/3176258.3176319 (2018)","DOI":"10.1145\/3176258.3176319"},{"key":"760_CR23","unstructured":"Ghena, B., Beyer, W., Hillaker, A., Pevarnek, J., Halderman, J.A.: Green lights forever: Analyzing the security of traffic infrastructure. In: Bratus, S., Lindner, F.F. (eds.), Proceedings of the 8th USENIX Workshop on Offensive Technologies (WOOT \u201914). USENIX Association (2014)"},{"key":"760_CR24","unstructured":"Li, F., Durumeric, Z., Czyz, J., Karami, M., Bailey, M., McCoy, D., Savage, S., Paxson, V.: You\u2019ve got vulnerability: exploring effective vulnerability notifications. In: Holz, T., Savage, S. (eds.), Proceedings of the 25th USENIX Security Symposium (USENIX Security \u201916). USENIX Association, pp. 1033\u20131050 (2016)"},{"key":"760_CR25","doi-asserted-by":"publisher","unstructured":"Allodi, L., Banescu, S., Femmer, H., Beckers, K.: Identifying relevant information cues for vulnerability assessment using CVSS. In: Proceedings of the 8th ACM Conference on Data and Application Security and Privacy (CODASPY \u201918) (ACM), CODASPY \u201918, pp. 119\u2013126 (2018). https:\/\/doi.org\/10.1145\/3176258.3176340","DOI":"10.1145\/3176258.3176340"},{"key":"760_CR26","unstructured":"Fenz, S., Ekelhart, A., Weippl, E.: Semantic potential of existing security advisory standards. In: Proceedings of the FIRST 2008 Conference-Forum of Incident Response and Security Teams (FIRST \u201908) (2008)"},{"key":"760_CR27","doi-asserted-by":"publisher","unstructured":"Fenz, S., Ekelhart, A., Weippl, E.: Fortification of IT security by automatic security advisory processing. In: Proceedings of the 22nd International Conference on Advanced Information Networking and Applications (AINA \u201908) (IEEE), pp. 575\u2013582. https:\/\/doi.org\/10.1109\/aina.2008.69 (2008)","DOI":"10.1109\/aina.2008.69"},{"key":"760_CR28","doi-asserted-by":"publisher","unstructured":"Challande, A., David, R., Renault, G.: Building a commit-level dataset of real-world vulnerabilities. In: Proceedings of the 12th ACM Conference on Data and Application Security and Privacy (CODASPY \u201922) (ACM), CODASPY \u201922, pp. 101\u2013106. https:\/\/doi.org\/10.1145\/3508398.3511495 (2022)","DOI":"10.1145\/3508398.3511495"},{"key":"760_CR29","doi-asserted-by":"publisher","unstructured":"Mavroeidis, V., Eis, P., Zadnik, M., Caselli, M., Jordan, B.: On the integration of course of action playbooks into shareable cyber threat intelligence. In: Proceedings of the 2021 IEEE International Conference on Big Data (Big Data \u201921) (IEEE), pp. 2104\u20132108. https:\/\/doi.org\/10.1109\/bigdata52589.2021.9671893 (2021)","DOI":"10.1109\/bigdata52589.2021.9671893"},{"key":"760_CR30","doi-asserted-by":"publisher","unstructured":"Akbari\u00a0Gurabi, M., Mandal, A., Popanda, J., Rapp, R., Decker, S.: SASP: a semantic web-based approach for management of sharable cybersecurity playbooks. In: Proceedings of the 17th International Conference on Availability, Reliability and Security (ARES \u201922) (ACM), pp. 1\u20138. https:\/\/doi.org\/10.1145\/3538969.3544478 (2022)","DOI":"10.1145\/3538969.3544478"},{"key":"760_CR31","doi-asserted-by":"publisher","unstructured":"Shaked, A., Cherdantseva, Y., Burnap, P.: Model-based incident response playbooks. In: Proceedings of the 17th International Conference on Availability, Reliability and Security (ARES \u201922) (ACM), pp. 1\u20137. https:\/\/doi.org\/10.1145\/3538969.3538976 (2022)","DOI":"10.1145\/3538969.3538976"},{"issue":"2","key":"760_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3305268","volume":"52","author":"C Islam","year":"2019","unstructured":"Islam, C., Babar, M.A., Nepal, S.: A multi-vocal review of security orchestration. ACM Comput. Surv. 52(2), 1 (2019). https:\/\/doi.org\/10.1145\/3305268","journal-title":"ACM Comput. Surv."},{"key":"760_CR33","doi-asserted-by":"publisher","unstructured":"Empl, P., Schlette, D., Zupfer, D., Pernul, G.: SOAR4IoT: securing IoT assets with digital twins. In: Proceedings of the 17th International Conference on Availability, Reliability and Security (ARES \u201922) (ACM), pp. 1\u201310. https:\/\/doi.org\/10.1145\/3538969.3538975 (2022)","DOI":"10.1145\/3538969.3538975"},{"issue":"3","key":"760_CR34","doi-asserted-by":"publisher","first-page":"45","DOI":"10.2753\/MIS0742-1222240302","volume":"24","author":"K Peffers","year":"2007","unstructured":"Peffers, K., Tuunanen, T., Rothenberger, M.A., Chatterjee, S.: A design science research methodology for information systems research. J. Manag. Inf. Syst. 24(3), 45 (2007). https:\/\/doi.org\/10.2753\/MIS0742-1222240302","journal-title":"J. Manag. Inf. Syst."},{"issue":"2","key":"760_CR35","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/s12599-019-00624-0","volume":"62","author":"M Dietz","year":"2020","unstructured":"Dietz, M., Pernul, G.: Digital twin: empowering enterprises towards a system-of-systems approach. Bus. Inf. Syst. Eng. 62(2), 179 (2020). https:\/\/doi.org\/10.1007\/s12599-019-00624-0","journal-title":"Bus. Inf. Syst. Eng."},{"key":"760_CR36","doi-asserted-by":"publisher","unstructured":"Schlette, D., Menges, F., Baumer, T., Pernul, G.: Security enumerations for cyber-physical systems. In: Singhal, A., Vaidya, J. (eds.), Data and Applications Security and Privacy XXXIV\u201434th Annual IFIP WG 11.3 Conference, DBSec: Regensburg, Germany, June 25\u201326, 2020, Proceedings, Lecture Notes in Computer Science, vol. 12122, pp. 64\u201376. Springer (2020). https:\/\/doi.org\/10.1007\/978-3-030-49669-2","DOI":"10.1007\/978-3-030-49669-2"},{"key":"760_CR37","unstructured":"National vulnerability database. https:\/\/nvd.nist.gov\/. Accessed on 20 Jul 2023"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-023-00760-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-023-00760-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-023-00760-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,27]],"date-time":"2024-03-27T07:41:30Z","timestamp":1711525290000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-023-00760-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,11]]},"references-count":37,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,4]]}},"alternative-id":["760"],"URL":"https:\/\/doi.org\/10.1007\/s10207-023-00760-5","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,11]]},"assertion":[{"value":"11 December 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}