D1 Cyber Secure Supply Chain – Requirements Specification
Total Page:16
File Type:pdf, Size:1020Kb
Project acronym: SECURED BY BLOCKCHAIN Project title: Secured by Blockchain: Developing cyber risk free supply chains Funding Scheme: Ateneo 2019 D1 Cyber Secure Supply Chain – Requirements Specification Submission date: 23/01/2020 Start date of project: 01/07/2019 Duration: 6M Organisation name of lead contractor for this deliverable: LIUC First Outline Dissemination Level Restricted to a group specified by the consortium (including the Commission RE Services) RE* RESTREINT Project partners and Advisory Board Members SECURED BY BLOCKCHAIN D1 – LIUC UNIVERSITÀ CARLO CATTANEO - 20.01.2020 - ITALY Document summary Information Authors and contributors Initial Name Organisation Role YBG Yari Borbon Galvez LIUC Partner AC Alessandro Creazza LIUC Partner CC Claudia Colicchia POLI Partner FS Fernanda Strozzi LIUC Partner NE Niloofar Etemadi LIUC Partner RO Riccardo Occa LIUC Partner DM David Menachof FAU Partner Revision history Revision Date Who Comment Draft v0.1 20/01/2020 LIUC team Draft v0.2 21/01/2020 LIUC team Draft v0.3 24/01/2020 Draft v0.4 31/01/2020 V1.0 07/02/2020 Final 14/02/2020 LIUC library LIUC research work in progress website Quality control Role Who Date Project manager Fabrizio Dallari 21/01/2020 Disclaimer The content of the publication herein is the sole responsibility of the publishers and it does not necessarily represent the views expressed by LIUC Università Carlo Cattaneo or its services. While the information contained in the documents is believed to be accurate, the authors(s) or any other participant in the SECURED BY BLOCKCHAIN consortium make no warranty of any kind with regard to this material including, but not limited to the implied warranties of merchantability and fitness for a particular purpose. Neither the SECURED BY BLOCKCHAIN Consortium nor any of its members, their officers, employees or agents shall be responsible or liable in negligence or otherwise howsoever in respect of any inaccuracy or omission herein. Without derogating from the generality of the foregoing neither the SECURED BY BLOCKCHAIN Consortium nor any of its members, their officers, employees or agents shall be liable for any direct or indirect or consequential loss or damage caused by or arising from any information advice or inaccuracy or omission herein. Page 2 of 54 SECURED BY BLOCKCHAIN D1 – LIUC UNIVERSITÀ CARLO CATTANEO - 20.01.2020 - ITALY Contents D1 CYBER SECURE SUPPLY CHAIN – REQUIREMENTS SPECIFICATION ............................................................... 1 1 EXECUTIVE SUMMARY ............................................................................................................................. 4 2 BACKGROUND ......................................................................................................................................... 5 2.1 INTRODUCTION .......................................................................................................................................... 5 2.2 CYBER SUPPLY CHAIN RISK MANAGEMENT (CSCRM) ......................................................................................... 7 2.3 BLOCKCHAIN AND SUPPLY CHAIN MANAGEMENT ............................................................................................... 8 3 DEFINITION OF THE SCOPE OF THE SECURED BY BLOCKCHAIN PROJECT ................................................ 10 3.1 APPROACH .............................................................................................................................................. 10 3.2 TESTING ................................................................................................................................................. 11 3.3 ASSESSMENT ........................................................................................................................................... 11 4 REQUIREMENTS AND SPECIFICATIONS .................................................................................................. 12 4.1 INTRODUCTION ........................................................................................................................................ 12 4.2 META-ANALYSIS: SUPPLY CHAIN CYBERSECURITY & BLOCKCHAIN RESEARCH ......................................................... 15 4.2.1 SYSTEMATIC LITERATURE ANALYSIS .............................................................................................................. 16 4.2.1.1 IDENTIFY, SELECT IN AND OUT, AND CLASSIFY THE LITERATURE ....................................................................... 17 4.2.2 ASSOCIATION ANALYSIS (CONTINGENCY TABLES AND PEARSON’S CHI-SQUARE TEST) .............................................. 23 4.2.2.1 DISCUSSION OF THE PEARSON’S CHI-SQUARE TEST’S RESULTS ........................................................................ 23 4.2.3 REQUIREMENTS SPECIFICATIONS ANALYSIS ..................................................................................................... 25 4.2.3.1 SPECIFICATIONS ................................................................................................................................... 25 4.2.3.2 Scope .......................................................................................................................................... 25 4.2.3.3 Cybersecurity and blockchain solutions ...................................................................................... 25 4.2.3.4 Requirements specification ........................................................................................................ 37 5 REFERENCES .......................................................................................................................................... 40 Page 3 of 54 SECURED BY BLOCKCHAIN D1 – LIUC UNIVERSITÀ CARLO CATTANEO - 20.01.2020 - ITALY 1 Executive summary This deliverable captures the SECURED BY BLOCKCHAIN project Requirements Specifications. It is a core specification document describing the project scope, approach and initial requirements specifications for developing a blockchain architecture in WP2. The purpose of the document is to provide the initial specifications of a cyber secure supply chain blockchain architecture. - T1.1 – Meta-analysis of the supply chain cyber security & and blockchain, - T1.2 – Identification of the cyber security requirements specifications for a blockchain architecture applied to supply chain transactions The document describes the scope, approach, and main components. The initial requirements specifications for SECURED BY BLOCKCHAIN include the following components: - Supply chain functions - Cyber risks - Blockchain security capabilities The document provides a consolidated table of requirement specifications for the above core components. Such specifications will be the ground field for the development of Key Performance Indicators (KPIs) in WP2. Page 4 of 54 SECURED BY BLOCKCHAIN D1 – LIUC UNIVERSITÀ CARLO CATTANEO - 20.01.2020 - ITALY 2 BACKGROUND 2.1 Introduction The fragility of international supply chains is evidenced with cyber-attacks like the one to Norsk Hydro’s operations in the U.S. and Europe in 2019 which left the company without automated production lines and running on manual production processes (Burton & Cho Walsgard, 2019). Cyber-attacks have costly consequences, for instance, it is reported an average cost of 3 million Euro for each cyber-attacks to Italian companies’ data in 2018 (Resilience360, 2018). The sources of cyber threat evolve over time. Hinde (2000) reported several cyberattacks leading to denial of services over the internet, like system’s failures, incompatibilities, uncertainty of safety of the systems for the users, internal threats, and so on. He also described the first large scale cyberattack to corporations like eBay, Amazon, CNN, latimes.com, with a computer virus ‘Stacheldraht’, which allows hackers to launch data traffic to targeted sites to saturate and block the websites. Surprisingly, although the cybersecurity community was aware of external threats, Vavra and Hromada (2015) explained how the protection of ‘Industrial Control Systems’ was still focused on insider threats and accidental malware introductions. It was only after the damage caused by the computer worm ‘Stuxnet’ in 2010, that the approach to cybersecurity changed radically to external threats because of information and communication systems’ growing openness (Langner, 2011). Solutions to cyber threats also evolve over time. Early cybersecurity consisted in authentication methods like passwords and PINs, access controls like firewalls, intrusion detection methods like exceeding number of users, and as reported by Yesberg and Henderson (2001) the cybersecurity community was much focused on the access to network components. Cybersecurity changed in early 2000’s to include real time threat analyses to network components (Chi, Park, Jung, & Lee, 2001). In mid2000’s operations research methods started playing a role for network survivability, intrusion detection, countering denial of service attacks, risk assessments, limit access to confidential data, legitimate access, and so on (Wright, Liberatore, & Nydick, 2006). In the early 2010’s the Supply chain cybersecurity made its great debut, with the inclusion three key factors: governance and organizational relationships tier, it and cyber-physical systems integration tier, and the operations and protocols tier (Boyson, 2014). Page 5 of 54 SECURED BY BLOCKCHAIN D1 – LIUC UNIVERSITÀ CARLO CATTANEO - 20.01.2020 - ITALY New technologies come with new risks,