Authors:
Arne Roar Nygård
;
Arvind Sharma
and
Sokratis Katsikas
Affiliation:
Department of Information Security and Communication Technology, Norwegian University of Science and Technology, Gjøvik, Norway
Keyword(s):
Digital Supply Chain, Digital Substation, Critical Infrastructure, Cyber-attack, Cyber Risk, Ethics, Reverse Engineering, Vulnerability Disclosure, Vulnerability Research, Moral Dilemma.
Abstract:
A reverse engineering process includes disassembling to analyse, test, and document the functionality of the target system. In doing so for the purpose of uncovering vulnerabilities intentionally or unintentionally introduced through the digital supply chain in components used in industrial control systems within critical infrastructures, ethical issues arise. This paper addresses such issues, by leveraging a real-life use case in the power infrastructure. A set of principles that should govern an ethical framework geared to reverse engineering for cybersecurity and recommendations on action needed to complement such a framework are proposed.