{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:38:45Z","timestamp":1786113525222,"version":"3.56.0"},"reference-count":32,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T00:00:00Z","timestamp":1667347200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Department of Energy","award":["DE-OE0000780"],"award-info":[{"award-number":["DE-OE0000780"]}]},{"name":"MIT Energy Initiative (MITei)","award":["DE-OE0000780"],"award-info":[{"award-number":["DE-OE0000780"]}]},{"name":"Fondo Europeo di Sviluppo Regionale Puglia POR Puglia 2014\u20132020\u2014Asse I\u2013Obiettivo specifico 1a\u2014Azione 1.1 (R&amp;S)\u2014Titolo Progetto: Suite prodotti CyberSecurity e SOC","award":["DE-OE0000780"],"award-info":[{"award-number":["DE-OE0000780"]}]},{"name":"BV TECH S.p.A.","award":["DE-OE0000780"],"award-info":[{"award-number":["DE-OE0000780"]}]},{"name":"corporate members of Cybersecurity at MIT Sloan: The Interdisciplinary Consortium for Improving Critical Infrastructure Cybersecurity","award":["DE-OE0000780"],"award-info":[{"award-number":["DE-OE0000780"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Network"],"abstract":"<jats:p>Recent world events and geopolitics have brought the vulnerability of critical infrastructure to cyberattacks to the forefront. While there has been considerable attention to attacks on Information Technology (IT) systems, such as data theft and ransomware, the vulnerabilities and dangers posed by industrial control systems (ICS) have received significantly less attention. What is very different is that industrial control systems can be made to do things that could destroy equipment or even harm people. For example, in 2021 the US encountered a cyberattack on a water treatment plant in Florida that could have resulted in serious injuries or even death. These risks are based on the unique physical characteristics of these industrial systems. In this paper, we present a holistic, integrated safety and security analysis, we call Cybersafety, based on the STAMP (System-Theoretic Accident Model and Processes) framework, for one such industrial system\u2014an industrial chiller plant\u2014as an example. In this analysis, we identify vulnerabilities emerging from interactions between technology, operator actions as well as organizational structure, and provide recommendations to mitigate resulting loss scenarios in a systematic manner.<\/jats:p>","DOI":"10.3390\/network2040035","type":"journal-article","created":{"date-parts":[[2022,11,3]],"date-time":"2022-11-03T03:53:07Z","timestamp":1667447587000},"page":"606-627","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Protecting Chiller Systems from Cyberattack Using a Systems Thinking Approach"],"prefix":"10.3390","volume":"2","author":[{"given":"Shaharyar","family":"Khan","sequence":"first","affiliation":[{"name":"Sloan School of Management, Massachusetts Institute of Technology, Cambridge, MA 02139, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9240-2573","authenticated-orcid":false,"given":"Stuart","family":"Madnick","sequence":"additional","affiliation":[{"name":"Sloan School of Management, Massachusetts Institute of Technology, Cambridge, MA 02139, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,11,2]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"172","DOI":"10.1109\/JPETS.2019.2923970","article-title":"Identifying and Anticipating Cyberattacks That Could Cause Physical Damage to Industrial Control Systems","volume":"6","author":"Angle","year":"2019","journal-title":"IEEE Power Energy Technol. Syst. J."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"123","DOI":"10.3390\/network2010009","article-title":"Cybersecurity Challenges in the Maritime Sector","volume":"2","author":"Akpan","year":"2022","journal-title":"Network"},{"key":"ref_3","unstructured":"Twining, B.G. (2022, August 14). Final Report Type B Accident Investigation Board Report Chiller Line Rupture at Technical Area 35, Building 27 Los Alamos National Laboratory Albuquerque Operations Office, Available online: https:\/\/energy.gov\/sites\/prod\/files\/2014\/04\/f15\/9711lanl.pdf."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Loukas, G. (2015). Cyber-Physical Attacks: A Growing Invisible Threat, Butterworth-Heinemann.","DOI":"10.1016\/B978-0-12-801290-1.00007-2"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Freeman, S.G., St Michel, C., Smith, R., and Assante, M. (2016). Consequence-Driven Cyber-Informed Engineering (CCE), Idaho National Lab.","DOI":"10.2172\/1341416"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"3312","DOI":"10.1109\/TDSC.2021.3093214","article-title":"Cybersafety: A System-Theoretic Approach to Identify Cyber-Vulnerabilities & amp; Mitigation Requirements in Industrial Control Systems","volume":"19","author":"Khan","year":"2021","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Schmittner, C., Gruber, T., Puschner, P., and Schoitsch, E. (2014). Security Application of Failure Mode and Effect Analysis (FMEA), Springer.","DOI":"10.1007\/978-3-319-10506-2_21"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Ericson, C.A. (2005). Hazard Analysis Techniques for System Safety, John Wiley & Sons, Inc.","DOI":"10.1002\/0471739421"},{"key":"ref_9","unstructured":"Steiner, M., and Liggesmeyer, P. (2013, January 14\u201327). Combination of Safety and Security Analysis-Finding Security Problems That Threaten The Safety of a System. Proceedings of the 32nd International Conference on Computer Safety, Reliability and Security, Toulouse, France."},{"key":"ref_10","unstructured":"Watson, H.A. (1961). Launch Control Safety Study, Bell labs."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Altawairqi, A., and Maarek, M. (2017). Attack Modeling for System Security Analysis, Springer.","DOI":"10.1007\/978-3-319-66284-8_8"},{"key":"ref_12","unstructured":"Xu, X., Ulrey, M.L., Brown, J.A., Mast, J., and Lapis, M.B. (2022, August 14). Safety Sufficiency for NextGen Assessment of Selected Existing Safety Methods, Tools, Processes, and Regulations, Available online: https:\/\/ntrs.nasa.gov\/citations\/20130010405."},{"key":"ref_13","first-page":"183","article-title":"STPA-SafeSec: Safety and security analysis for cyber-physical systems","volume":"34","author":"Friedberg","year":"2017","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_14","unstructured":"Leveson, N.G., and Thomas, J.P. (2022, August 14). STPA Handbook, Available online: http:\/\/psas.scripts.mit.edu\/home\/."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Leveson, N. (2012). Engineering a Safer World: Systems Thinking Applied to Safety, The MIT Press.","DOI":"10.7551\/mitpress\/8179.001.0001"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Laracy, J.R., and Leveson, N.G. (2007, January 16\u201317). Apply STAMP to Critical Infrastructure Protection. Proceedings of the 2007 IEEE Conference on Technologies for Homeland Security, Woburn, MA, USA.","DOI":"10.1109\/THS.2007.370048"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1145\/2556938","article-title":"An integrated approach to safety and security based on systems theory","volume":"57","author":"Young","year":"2014","journal-title":"Commun. ACM"},{"key":"ref_18","unstructured":"Salim, H.M. (2014). Cyber Safety: A Systems Thinking and Systems Theory Approach to Managing Cyber Security. [Master\u2019s Thesis, Massachusetts Institute of Technology]."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1109\/TDSC.2015.2509994","article-title":"A Systems Theoretic Approach to the Security Threats in Cyber Physical Systems Applied to Stuxnet","volume":"15","author":"Nourian","year":"2018","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Mailloux, L.O., Lt Span, M., Mills, R.F., and Lb Young, W. (2019, January 8\u201311). A top down approach for eliciting systems security requirements for a notional autonomous space system. Proceedings of the SysCon 2019-13th Annual IEEE International Systems Conference, Orlando, FL, USA.","DOI":"10.1109\/SYSCON.2019.8836929"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"46668","DOI":"10.1109\/ACCESS.2018.2865736","article-title":"Conceptual systems security requirements analysis: Aerial refueling case study","volume":"6","author":"Span","year":"2018","journal-title":"IEEE Access"},{"key":"ref_22","first-page":"102620","article-title":"Extending STPA with STRIDE to identify cybersecurity loss scenarios","volume":"55","author":"Hirata","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_23","unstructured":"(2022, August 14). Daikin, Chiller Application Guide Fundamentals of Water and Air Cooled Chillers. Available online: https:\/\/oslo.daikinapplied.com\/api\/sharepoint\/getdocument\/Doc100\/Daikin_AG_31-003_Chiller_Applicatio_Guide.pdf\/."},{"key":"ref_24","unstructured":"(2022, August 14). Daikin, Centrifugal Chiller Fundamentals. Available online: https:\/\/www.olympicinternational.com\/download.php?file=AG_31_002-centrifugal-chiller-fundamentals.pdf."},{"key":"ref_25","unstructured":"(2022, August 14). Open Security Architecture, \u201cSP-023: Industrial Control Systems\u201d. Available online: https:\/\/www.opensecurityarchitecture.org\/cms\/library\/patternlandscape\/293-sp-023-industrial-control-systems."},{"key":"ref_26","unstructured":"(2022, August 14). Emerson Application Engineering Bulletin Use of Variable Frequency Drives (VFDs) with Copeland Scroll and Copeland Discus in Fixed Capacity Compressors in Refrigeration Applications. Available online: https:\/\/webapps.emerson.com\/online-product-information\/Publication\/LaunchPDF?Index=AEB&PDF=1369."},{"key":"ref_27","unstructured":"Zetter, K. (2022, August 14). An Easy Way for Hackers to Remotely Burn Industrial Motors. Available online: https:\/\/www.wired.com\/2016\/01\/an-easy-way-for-hackers-to-remotely-burn-industrial-motors\/."},{"key":"ref_28","unstructured":"Evans, P. (2022, August 14). Chiller Oil Lubrication Circuit-The Engineering Mindset. Available online: https:\/\/theengineeringmindset.com\/chiller-oil-lubrication-circuit\/."},{"key":"ref_29","unstructured":"(2022, August 14). Centrifugal Compressor Surge Basics, Mechanism. Available online: http:\/\/mechanicalengineeringsite.com\/centrifugal-compressor-surge-basics-mechanism\/."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Schmittner, C., Ma, Z., and Puschner, P. (2016). Limitation and Improvement of STPA-Sec for Safety and Security Co-Analysis. Springer.","DOI":"10.1007\/978-3-319-45480-1_16"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Tu, Y., Rodriguez, A., Rampazzi, S., Fu, K., Hao, B., and Hei, X. (2019, January 11\u201315). Trick or heat? Manipulating critical temperature-based control systems using rectification attacks. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA.","DOI":"10.1145\/3319535.3354195"},{"key":"ref_32","unstructured":"Gordy, F. (2022, August 14). Destroyed A 300 Ton Chiller-Fred Gordy|Episode #45. Available online: https:\/\/waterfall-security.com\/fred-gordy\/."}],"container-title":["Network"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2673-8732\/2\/4\/35\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:09:22Z","timestamp":1760144962000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2673-8732\/2\/4\/35"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,2]]},"references-count":32,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2022,12]]}},"alternative-id":["network2040035"],"URL":"https:\/\/doi.org\/10.3390\/network2040035","relation":{},"ISSN":["2673-8732"],"issn-type":[{"value":"2673-8732","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,2]]}}}