In modern society introduced Industrial 4.0, Information and Communication Technology (ICT) such as Supervisory Control and Data Acquisition (SCADA) is applied to industrial control systems (ICS) applied to various fields such as power, factory, and financial is applied. Especially, in the field of power systems, ICT such as Industrial Internet of Things (IoT) is applied for efficient radio measurement. As a result, existing stand-alone systems have increased contact points with external networks. However, in case of most ICS, there is a lack of security guideline and operation guidance for a newly changed environment. Accordingly, various countermeasures have been developed to protect ICT-based ICS from cyber attacks. However, it is difficult to cope with cyber attacks that are evolving, such as potential security threats or Advanced Persistent Threat (APT). In order to effectively and proactively respond to new security threats including APT attacks, it is needed to understand and inspect the current security status of the system. It is necessary to identify the security requirements on the basis of the checked contents and establish an appropriate security response structure accordingly, thereby improving the security of the intelligent and open ICS and ensuring social safety.
In this paper, we propose an Integrated Security Framework consisting of three steps to improve the security level of ICS environment using Industrial IoT technology. The first step is the 'vulnerability inspection' stage to check for potential security threats using the OSINT technique preemptively. The second step is the 'security architecture modeling' stage, where security functions are deployed by analyzing the security requirements necessary to mitigate the threats of the ICS environment. The third step is a 'system assessment' stage to evaluate the security vulnerability of the system using the security vulnerability quantification technique based on Game theory. And a case study showing that the security of ICS environment can be improved by verifying the proposed framework for ICS network composed of the analysis of reference models.