{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T16:42:36Z","timestamp":1780332156186,"version":"3.54.1"},"reference-count":43,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2021,9,30]],"date-time":"2021-09-30T00:00:00Z","timestamp":1632960000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Since Cyber-Physical Systems (CPS) are widely used in critical infrastructures, it is essential to protect their assets from cyber attacks to increase the level of security, safety and trustworthiness, prevent failure developments, and minimize losses. It is necessary to analyze the CPS configuration in an automatic mode to detect the most vulnerable CPS components and reconfigure or replace them promptly. In this paper, we present a methodology to determine the most secure CPS configuration by using a public database of cyber vulnerabilities to identify the most secure CPS components. We also integrate the CPS cyber risk analysis with a Controlled Moving Target Defense, which either replaces the vulnerable CPS components or re-configures the CPS to harden it, while the vulnerable components are being replaced. Our solution helps to design a more secure CPS by updating the configuration of existing CPS to make them more resilient against cyber attacks. In this paper, we will compare cyber risk scores for different CPS configurations and show that the Windows\u00ae 10 build 20H2 operating system is more secure than Linux Ubuntu\u00ae 20.04, while Red Hat\u00ae Enterprise\u00ae Linux is the most secure in some system configurations.<\/jats:p>","DOI":"10.3390\/info12100408","type":"journal-article","created":{"date-parts":[[2021,10,1]],"date-time":"2021-10-01T10:55:40Z","timestamp":1633085740000},"page":"408","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["VERCASM-CPS: Vulnerability Analysis and Cyber Risk Assessment for Cyber-Physical Systems"],"prefix":"10.3390","volume":"12","author":[{"given":"Bradley","family":"Northern","sequence":"first","affiliation":[{"name":"Department of Computer Science, Tennessee Technological University, Cookeville, TN 38505, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Trey","family":"Burks","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Tennessee Technological University, Cookeville, TN 38505, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marlana","family":"Hatcher","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Tennessee Technological University, Cookeville, TN 38505, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Rogers","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Tennessee Technological University, Cookeville, TN 38505, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Denis","family":"Ulybyshev","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Tennessee Technological University, Cookeville, TN 38505, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,9,30]]},"reference":[{"key":"ref_1","unstructured":"Schneider Electric SE (2021, August 28). Schneider Electric Terms of Use. Available online: https:\/\/www.se.com\/us\/en\/about-us\/legal\/terms-of-use.jsp."},{"key":"ref_2","unstructured":"(2021, August 04). Florida Water Plant Hack: Leaked Credentials Found in Breach Database. Available online: https:\/\/threatpost.com\/florida-water-plant-hack-credentials-breach\/163919\/."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Aksu, M.U., Dilek, M.H., Tatl\u0131, E.\u0130., Bicakci, K., Dirik, H.I., Demirezen, M.U., and Ayk\u0131r, T. (2017, January 23\u201326). A quantitative CVSS-based cyber security risk assessment methodology for IT systems. Proceedings of the 2017 International Carnahan Conference on Security Technology (ICCST), Madrid, Spain.","DOI":"10.1109\/CCST.2017.8167819"},{"key":"ref_4","unstructured":"Spring, J., Hatleback, A., Manion, A., and Shic, D. (2021, August 28). Towards Improving CVSS. Available online: https:\/\/resources.sei.cmu.edu\/asset_files\/WhitePaper\/2018_019_001_538372.pdf."},{"key":"ref_5","unstructured":"FIRST.Org, Inc. (2021, June 17). Common Vulnerability Scoring System Version 3.1: Specification Document. Available online: https:\/\/www.first.org\/cvss\/v3-1\/cvss-v31-specification_r1.pdf."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Chang, Y.Y., Zavarsky, P., Ruhl, R., and Lindskog, D. (2011, January 9\u201311). Trend analysis of the cve for software vulnerability management. Proceedings of the 2011 IEEE Third International Conference on Privacy, Security, Risk and Trust and 2011 IEEE Third International Conference On Social Computing, Boston, MA, USA.","DOI":"10.1109\/PASSAT\/SocialCom.2011.184"},{"key":"ref_7","unstructured":"Tripathi, A., and Singh, U.K. (December, January 29). On prioritization of vulnerability categories based on CVSS scores. Proceedings of the 2011 6th International Conference on Computer Sciences and Convergence Information Technology (ICCIT), Seogwipo, Korea."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Allodi, L., and Massacci, F. (2012, January 15). A preliminary analysis of vulnerability scores for attacks in wild: The ekits and sym datasets. Proceedings of the 2012 ACM Workshop on Building Analysis Datasets and Gathering Experience Returns for Security, New York, NY, USA.","DOI":"10.1145\/2382416.2382427"},{"key":"ref_9","unstructured":"Tenable, Inc. (2021, August 20). Legal Information. Available online: https:\/\/www.tenable.com\/legal."},{"key":"ref_10","unstructured":"Tenable (2021, August 20). Calculating Known and Unknown Risk: The Math behind the Cyber Exposure Score. Available online: https:\/\/www.tenable.com\/whitepapers\/calculating-known-and-unknown-risk-the-math-behind-the-cyber-exposure-score."},{"key":"ref_11","unstructured":"(2021, August 18). Vulnerability Assessment Platform. Available online: https:\/\/vulners.com."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Singhal, A., and Vaidya, J. (2020). Security Enumerations for Cyber-Physical Systems. Data and Applications Security and Privacy XXXIV, Springer International Publishing.","DOI":"10.1007\/978-3-030-49669-2"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"tyaa015","DOI":"10.1093\/cybsec\/tyaa015","article-title":"Improving vulnerability remediation through better exploit prediction","volume":"6","author":"Jacobs","year":"2020","journal-title":"J. Cybersecur."},{"key":"ref_14","unstructured":"FIRST.Org, Inc. (2021, September 08). Exploit Prediction Scoring System (EPSS). Available online: https:\/\/www.first.org\/epss\/model."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Nikoloudakis, Y., Kefaloukos, I., Klados, S., Panagiotakis, S., Pallis, E., Skianis, C., and Markakis, E.K. (2021). Towards a Machine Learning Based Situational Awareness Framework for Cybersecurity: An SDN Implementation. Sensors, 21.","DOI":"10.3390\/s21144939"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Chavez, A.R. (2019). Moving Target Defense to Improve Industrial Control System Resiliency. Industrial Control Systems Security and Resiliency, Springer.","DOI":"10.1007\/978-3-030-18214-4_8"},{"key":"ref_17","unstructured":"Sengupta, S. (2021, September 08). Moving Target Defense: A Symbiotic Framework for AI & Security (Doctoral Consortium). Available online: http:\/\/www.public.asu.edu\/~ssengu15\/files\/AAMAS_DC.pdf."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Markakis, E., Nikoloudakis, Y., Pallis, E., and Manso, M. (2019, January 15\u201318). Security assessment as a service cross-layered system for the adoption of digital, personalised and trusted healthcare. Proceedings of the 2019 IEEE 5th World Forum on Internet of Things (WF-IoT), Limerick, Ireland.","DOI":"10.1109\/WF-IoT.2019.8767249"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/MCOM.2019.1800506","article-title":"Acceleration at the edge for supporting smes security: The fortika paradigm","volume":"57","author":"Markakis","year":"2019","journal-title":"IEEE Commun. Mag."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Toupas, P., Chamou, D., Giannoutakis, K.M., Drosou, A., and Tzovaras, D. (2019, January 16\u201319). An Intrusion Detection System for Multi-class Classification Based on Deep Neural Networks. Proceedings of the 2019 18th IEEE International Conference On Machine Learning and Applications (ICMLA), Boca Raton, FL, USA.","DOI":"10.1109\/ICMLA.2019.00206"},{"key":"ref_21","unstructured":"Fielding, R.T., and Taylor, R.N. (2000). Architectural Styles and the Design of Network-Based Software Architectures, University of California."},{"key":"ref_22","unstructured":"Netflix (2021, August 20). Eureka. Available online: https:\/\/github.com\/Netflix\/eureka."},{"key":"ref_23","unstructured":"Public Interest Inc. (2021, August 27). Debian Trademarks. Available online: https:\/\/www.debian.org\/trademark."},{"key":"ref_24","unstructured":"(2021, June 13). Inductive Automation, Maker Edition. Available online: https:\/\/docs.inductiveautomation.com\/display\/DOC81\/Maker+Edition."},{"key":"ref_25","unstructured":"PHP Group (2021, August 21). Website Copyright. Available online: https:\/\/www.php.net\/copyright.php."},{"key":"ref_26","unstructured":"(2021, August 25). Oracle Legal: Copyright Information. Available online: https:\/\/www.oracle.com\/legal\/copyright.html."},{"key":"ref_27","unstructured":"PostgreSQL Community Association of Canada (2021, August 22). Trademark Policy. Available online: https:\/\/www.postgresql.org\/about\/policies\/trademarks\/."},{"key":"ref_28","unstructured":"Red Hat (2021, August 20). Trademark Guidelines and Policies. Available online: https:\/\/www.redhat.com\/en\/about\/trademark-guidelines-and-policies."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Clark-Carter, D. (2010). Measures of Central Tendency, Elsevier.","DOI":"10.1016\/B978-0-08-044894-7.01343-9"},{"key":"ref_30","unstructured":"(2021, July 26). Salt Project. Available online: https:\/\/saltproject.io\/."},{"key":"ref_31","unstructured":"Intel Inc. (2021, April 24). Intel\u00ae Trademark & Company Name Usage Guidelines. Available online: www.intel.com\/content\/www\/us\/en\/trademarks\/intel.html."},{"key":"ref_32","unstructured":"Arm Trademarks (2021, June 12). Available online: https:\/\/www.arm.com\/company\/policies\/trademarks."},{"key":"ref_33","unstructured":"Macgill, C. (2021, March 08). Cartesian Products and Relations. Available online: https:\/\/www.math.uvic.ca\/faculty\/gmacgill\/guide\/RF.pdf."},{"key":"ref_34","unstructured":"Advanced Micro Devices (2021, August 27). Trademark Information. Available online: https:\/\/www.amd.com\/en\/corporate\/trademarks."},{"key":"ref_35","unstructured":"The Apache Software Foundation (2021, August 25). Frequently Asked Questions about the ASF\u2019s Trademarks and Their Allowable Uses. Available online: www.apache.org\/foundation\/marks\/faq\/."},{"key":"ref_36","unstructured":"F5 Networks, Inc. (2021, August 20). Trademarks. Available online: https:\/\/www.f5.com\/company\/policies\/trademarks."},{"key":"ref_37","unstructured":"Google (2021, August 27). Trademark List. Available online: https:\/\/about.google\/brand-resource-center\/trademark-list\/."},{"key":"ref_38","unstructured":"(2021, August 20). Advantech WebAccess\/SCADA. Available online: https:\/\/www.advantech.com\/industrial-automation\/webaccess\/webaccessscada."},{"key":"ref_39","unstructured":"(2021, June 11). Free OPC-UA Library. Available online: https:\/\/github.com\/FreeOpcUa."},{"key":"ref_40","unstructured":"(2021, July 28). OPC UA Basic256Sha256 Security Policy. Available online: https:\/\/reference.opcfoundation.org\/Core\/docs\/Part7\/6.6.165\/."},{"key":"ref_41","unstructured":"(2021, July 28). Bash\u2014GNU Project. Available online: https:\/\/www.gnu.org\/software\/bash\/."},{"key":"ref_42","unstructured":"(2021, June 12). Raspberry Pi Trademark Rules and Brand Guidelines. Available online: https:\/\/www.raspberrypi.org\/trademark-rules\/."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Ulybyshev, D., Bare, C., Bellisario, K., Kholodilo, V., Northern, B., Solanki, A., and O\u2019Donnell, T. (2020, January 28\u201330). Protecting Electronic Health Records in Transit and at Rest. Proceedings of the 2020 IEEE 33rd International Symposium on Computer-Based Medical Systems (CBMS), Rochester, MN, USA.","DOI":"10.1109\/CBMS49503.2020.00091"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/10\/408\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:08:17Z","timestamp":1760166497000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/10\/408"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,30]]},"references-count":43,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2021,10]]}},"alternative-id":["info12100408"],"URL":"https:\/\/doi.org\/10.3390\/info12100408","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,30]]}}}