Deniz kritik altyapılarında siber-fiziksel güvenlik risklerinin stpa-sec yöntemi ile analizi
Analysis of cyber-physical security risks in critical maritime infrastructures using the stpa-sec method
- Tez No: 1025042
- Danışmanlar: DR. ÖĞR. ÜYESİ FIRAT BOLAT, DOÇ. DR. HASAN BORA USLUER
- Tez Türü: Yüksek Lisans
- Konular: Denizcilik, Marine
- Anahtar Kelimeler: Uluslararası deniz taşımacılığı, International maritime transport
- Yıl: 2026
- Dil: Türkçe
- Üniversite: İstanbul Teknik Üniversitesi
- Enstitü: Lisansüstü Eğitim Enstitüsü
- Ana Bilim Dalı: Denizcilik Çalışmaları Ana Bilim Dalı (disiplinlerarası)
- Bilim Dalı: Denizcilik Çalışmaları Bilim Dalı
- Sayfa Sayısı: Belirtilmemiş.
Özet
Denizcilik sektörü, küresel ticaretin hacimce büyük bölümünü taşıyarak dünya ekonomisinin temel omurgasını oluşturur. Son yıllarda hızlanan dijitalleşme ve otomasyon, gemileri ve limanları birbirine bağlı, karmaşık siber-fiziksel sistemlere dönüştürmüştür. Bu dönüşümle birlikte bilgi teknolojisi ve operasyonel teknoloji katmanları iç içe geçmiş; geçmişte fiziksel olarak yalıtılmış olan seyrüsefer, makine kontrol ve haberleşme sistemleri dış ağlara açılmıştır. Denizcilik ortamı bu tehditler karşısında kendine özgü kırılganlıklar taşır: gemilerin hizmet ömrü uzundur ve bünyelerinde yıllar öncesine ait, güncellenmesi güç operasyonel teknoloji bulunur; uydu bağlantısının yaygınlaşmasıyla eski yalıtım ortadan kalkmış, mürettebatın operasyon için kullandığı taşınabilir cihazlar yeni bir bulaşma yolu haline gelmiştir. Söz konusu bütünleşme operasyonel verimliliği yükseltirken, aynı zamanda siber saldırılara karşı ciddi güvenlik açıkları doğurmaktadır. 2017 yılındaki NotPetya saldırısı ve benzeri olaylar, siber tehditlerin yalnızca veri ya da finansal kayıplarla sınırlı kalmadığını; küresel tedarik zincirinde büyük aksamalara ve fiziksel hasara yol açabildiğini göstermiştir. Bu tabloya paralel olarak, uluslararası denizcilik düzenlemeleri de siber risk yönetimini gemi emniyet yönetim sistemlerinin ayrılmaz bir parçası haline getirmeye başlamış ve konuyu isteğe bağlı bir tedbir olmaktan çıkarıp bir yükümlülüğe dönüştürmüştür. Geleneksel risk analizi yöntemleri çoğunlukla tekil bileşen arızalarına odaklanır ve sistemi oluşturan unsurların güvenliğini birbirinden ayrı değerlendirir. Oysa siber-fiziksel sistemlerde en ciddi tehlikeler, bileşenlerin her biri kendi başına doğru çalışırken dahi, aralarındaki etkileşimlerden ve kontrol ilişkilerindeki kusurlardan doğabilmektedir. Bu tezde, güvenliği bir kontrol problemi olarak ele alan ve sistem teorisine dayanan STPA-Sec (System Theoretic Process Analysis for Security) yöntemi kullanılarak, deniz kritik altyapılarındaki siber-fiziksel güvenlik riskleri sistematik biçimde incelenmektedir. Yöntemin dayandığı temel düşünce, bir kazanın ya da güvenlik ihlalinin çoğu zaman tek bir parçanın bozulmasından değil, sistemin kontrol yapısındaki bir eksiklikten kaynaklandığıdır. Bu nedenle STPA-Sec, bileşen arızası yerine sistem düzeyindeki güvensiz kontrol eylemlerine ve bu eylemlere yol açan nedensel senaryolara yönelir; geleneksel yaklaşımların gözden kaçırdığı, etkileşim kaynaklı zafiyetlerin ortaya çıkarılmasına imkân tanır. Çalışmanın temel amacı, bu yöntemin denizcilik kritik altyapılarına uygulanabilirliğini göstermek ve nitel analiz çıktısını nicel bir risk değerlendirmesiyle birleştirerek karar vericilere uygulanabilir bir çerçeve sunmaktır. Analiz dört adımda yürütülmüştür. İlk aşamada, sistemin önlemesi gereken kabul edilemez kayıplar ve bunlara yol açabilecek tehlikeli durumlar tanımlanmıştır. İkinci aşamada, kontrolörleri, aktüatörleri, sensörleri ve bunlar arasındaki komut ile geri bildirim yollarını içeren kontrol yapısı modellenmiştir. Üçüncü aşamada güvensiz kontrol eylemleri belirlenmiştir; bu belirleme, bir kontrol eyleminin hangi biçimlerde tehlikeye dönüşebileceği göz önüne alınarak yapılır: gerekli bir komutun hiç verilmemesi, tehlikeli bir komutun verilmesi, komutun yanlış zamanda ya da yanlış sırada verilmesi ve komutun yanlış süre boyunca uygulanması. Dördüncü aşamada ise bu eylemlerin kök nedenleri ile olası siber saldırı senaryoları türetilmiş; bir saldırganın bileşeni devre dışı bırakmaktan çok, kontrol döngüsünü nasıl manipüle edebileceğine odaklanılmıştır. Nitel analizin çıktıları, ISO 31000 risk yönetimi standardı ve NIST siber güvenlik çerçevesi temel alınarak kurulan bir risk matrisine aktarılmış, her senaryonun risk skoru gerçekleşme olasılığı ile etkisinin çarpımı olarak hesaplanmış ve senaryolar ortak bir ölçekte önceliklendirilmiştir. İnceleme üç vaka çalışması üzerinde gerçekleştirilmiştir. Birincisi, seyrüsefer, makine kontrol ve elektronik harita sistemleriyle donatılmış bir yük gemisidir. İkincisi, otomatik yükleme-boşaltma ve saha trafiği yönetimi işlevlerini barındıran bir liman otomasyon sistemidir. Üçüncüsü ise seyrüseferini ve kararlarını insan müdahalesi olmadan yürüten bir otonom gemidir. Yük gemisi vakası, yöntemin tüm adımlarıyla ayrıntılı biçimde işlenen temsili vaka olarak seçilmiş; liman otomasyonu ve otonom gemi ise yöntemin farklı altyapı türlerine genellenebilirliğini göstermek üzere karşılaştırmalı olarak ele alınmıştır. Saldırıların fiziksel sonuçlarını değerlendirmek amacıyla, geminin ileri hareketini ve sapma davranışını temsil eden basitleştirilmiş bir matematiksel model kurulmuştur. Bu model, geminin tüm hidrodinamik davranışını yeniden üretmeyi değil, incelenen tehditlerin ilgili olduğu boyutları temsil etmeyi amaçlar. Örneğin sahte fakat inandırıcı bir konum bilgisinin sisteme aktarıldığı bir seyrüsefer aldatma senaryosunda, geminin rotasından yavaş ve fark edilmeyecek biçimde saparak zamanla kayda değer bir sapmaya ulaştığı görülmüştür. Yöntemin özgünlüğünü ve sınırlarını değerlendirmek için STPA-Sec; STRIDE, CORAS ve Attack Trees yöntemleriyle karşılaştırılmış ve öne çıkan güvenlik önlemleri için bir maliyet-fayda analizi yapılmıştır. Yük gemisi vakasında dokuz siber saldırı senaryosu tanımlanmış ve risk seviyelerine göre sınıflandırılmıştır; bu senaryolardan üçü kritik, üçü yüksek, biri orta ve ikisi düşük risk düzeyinde değerlendirilmiştir. Senaryolar niteliklerine göre birkaç grupta toplanmaktadır: seyrüsefer sistemlerine yönelik konum ve harita aldatma girişimleri, makine ile dümen kontrolüne yönelik komut manipülasyonları, operasyonel teknoloji ağını hedef alan hizmet engelleme saldırıları ve veri gizliliğini ihlal eden yetkisiz erişimler. En yüksek riskli senaryolar, geminin fiziksel hareketini doğrudan denetleyen sistemleri, özellikle elektronik harita, otopilot ve makine kontrol birimlerini hedef alan senaryolardır. Analiz sonuçları, en kritik zafiyetlerin, harici sistemlerden gelen verilerin yeterli doğrulama yapılmadan kontrol döngülerinde kullanıldığı noktalarda yoğunlaştığını ortaya koymaktadır. Bu ortak kök neden, bileşenlerin tekil güvenliğinden çok, sistemin veri akışına duyduğu doğrulanmamış güvenin bir sonucudur. Yöntemlerin karşılaştırmalı değerlendirmesi, bileşen ve tehdit odaklı yaklaşımların sistem düzeyindeki bu tür etkileşim kaynaklı zafiyetleri yapısal olarak gözden kaçırabildiğini; STPA-Sec'in ise bu zafiyetleri ve fiziksel sonuçlarını görünür kıldığını göstermiştir. Tespit edilen zafiyetleri gidermek amacıyla teknik, operasyonel ve düzenleyici düzeyde güvenlik gereksinimleri türetilmiştir. Teknik gereksinimler, veri bütünlüğünün ve şifrelemenin sağlanmasını, ağın kritik bölümlere ayrıştırılmasını, yazılım bütünlüğünün doğrulanmasını ve birden çok sensörden gelen verinin karşılaştırılarak tutarlılığının denetlenmesini kapsar. Operasyonel gereksinimler, mürettebatın siber güvenlik farkındalığının artırılmasını ve olayların raporlanmasına ilişkin süreçlerin kurulmasını içerir. Düzenleyici gereksinimler ise uluslararası kurallara uyumu ve klas kuruluşlarının denetim mekanizmalarını öne çıkarır. Bu gereksinimlerin önceliklendirilmesinde, her birinin ilişkili olduğu senaryonun risk düzeyi belirleyici olmuştur. Önerilen önlemlerin ekonomik boyutu da incelenmiş; yatırımın kısa bir geri ödeme süresine ve pozitif net bugünkü değere sahip olduğu, dolayısıyla ekonomik olarak gerekçelendirilebilir olduğu görülmüştür. Girdi değerlerindeki belirsizliğe karşı yürütülen duyarlılık değerlendirmesi, önceliklendirme sonuçlarının bu belirsizlikten önemli ölçüde etkilenmediğini ortaya koymuştur. Bulgular bir bütün olarak değerlendirildiğinde, çalışmanın özgün katkısı, nitel STPA-Sec analizi ile nicel risk değerlendirmesini denizcilik siber-fiziksel sistemleri bağlamında birleştiren ve karar vericilere hem önceliklendirme hem de mali gösterge sunan bütünleşik bir çerçeve ortaya koymasıdır. Sonuçlar, belirli sınırlılıklar çerçevesinde yorumlanmalıdır. Kullanılan olasılık ve etki değerleri, sektöre özgü verinin gizlilik ve raporlama eksikliği nedeniyle kıt olması sebebiyle büyük ölçüde eğitimli kestirimlere dayanmaktadır; analiz de gerçek saha verileriyle değil temsili modeller üzerinden yürütülmüştür. Gelecek çalışmalar, bu kestirimleri operasyonel verilerle doğrulayarak ve Bayes ağları gibi olasılıksal yöntemlerden yararlanarak güçlendirebilir; ayrıca yük gemisi için yapılan ayrıntılı çözümlemenin liman ve otonom gemi vakalarına genişletilmesi mümkündür. Bu sınırlılıklara karşın çalışma, STPA-Sec yönteminin deniz kritik altyapılarının çok bileşenli yapısını anlamada ve öngörülmesi güç siber-fiziksel risk senaryolarını proaktif biçimde değerlendirmede güçlü ve uygulanabilir bir araç olduğunu göstermekte; denizcilik alanında siber güvenliğin yalnızca bir bilgi güvenliği meselesi değil, doğrudan bir emniyet meselesi olarak ele alınması gerektiğini vurgulamaktadır.
Özet (Çeviri)
The maritime transportation industry serves as the backbone of the global economy, carrying a large share of world trade by volume. In recent years, accelerating digitalization and automation have turned ships and ports into interconnected and increasingly complex cyber-physical systems. Through this transformation, information technology and operational technology layers have become deeply intertwined, and navigation, machinery control and communication systems that were once physically isolated are now exposed to external networks. The maritime environment carries distinctive weaknesses in the face of these threats. Vessels remain in service for decades and often rely on operational technology that was installed years earlier and is difficult to update. The spread of satellite connectivity has removed the isolation that once protected shipboard systems, and the portable devices that crew members use for daily operations have become a common route of infection. While this integration improves operational efficiency, it also gives rise to serious security vulnerabilities against cyber-attacks. Events such as the 2017 NotPetya attack have shown that cyber threats are not confined to data or financial losses; they can cause major disruptions across the global supply chain and result in physical damage. In parallel with this reality, international maritime regulations have begun to treat cyber risk management as an integral part of ship safety management systems, turning it from an optional precaution into an obligation. Traditional risk analysis methods tend to focus on the failure of individual components and evaluate the security of system elements in isolation. In cyber-physical systems, however, the most severe hazards may emerge from the interactions between components and from flaws in their control relationships, even when each component functions correctly on its own. This thesis examines the cyber-physical security risks of maritime critical infrastructures using the STPA-Sec (System Theoretic Process Analysis for Security) methodology, which treats security as a control problem grounded in systems theory. The underlying idea of the method is that an accident or a security breach usually stems not from a single broken part but from a deficiency in the control structure of the system. For this reason, the method addresses unsafe control actions at the system level and the causal scenarios that lead to them, rather than component failure. This orientation makes it possible to reveal interaction-based vulnerabilities that conventional approaches often overlook, particularly those that arise not from a broken part but from the way parts influence one another. The central aim of the study is to demonstrate the applicability of STPA-Sec to maritime critical infrastructures and to combine its qualitative output with a quantitative risk assessment, thereby providing decision-makers with an applicable framework. The analysis was carried out in four stages. In the first stage, the unacceptable losses that the system must prevent and the hazardous states that could lead to them were defined. In the second stage, the control structure of the system was modelled, identifying the controllers, actuators, sensors and the command and feedback paths through which information flows. In the third stage, unsafe control actions were derived by considering the principal ways in which a control action can become hazardous: when a required command is not provided, when a hazardous command is provided, when a command is given at the wrong time or in the wrong order, and when it is applied for an incorrect duration. In the final stage, the root causes of these unsafe control actions and the corresponding cyber-attack scenarios were established, with particular attention to how an adversary could manipulate the control loop rather than simply disable a component. A recurring concern in this stage was the integrity of the information reaching the controller, since a controller that acts on corrupted feedback may issue a technically correct command that nonetheless produces a hazardous outcome. The qualitative findings were transferred to a risk matrix built upon the ISO 31000 risk management standard and the NIST cybersecurity framework. For each scenario, a risk score was computed as the product of its likelihood and its impact, allowing the scenarios to be prioritized on a common scale. The analysis was applied to three case studies. The first is a cargo ship equipped with navigation, machinery control and electronic chart systems. The second is a port automation system that carries out automated loading and unloading together with the management of yard traffic. The third is an autonomous vessel that conducts its navigation and decision-making without human intervention. The cargo ship was treated as the in-depth representative case and processed through every step of the method, whereas the port automation system and the autonomous vessel were examined comparatively in order to demonstrate the generalizability of the approach to different types of infrastructure. To study the physical consequences of the attacks, a simplified mathematical model representing the surge and yaw behaviour of the vessel was constructed. This model was not intended to reproduce the full hydrodynamic behaviour of a ship, but to capture the dimensions relevant to the analysed threats. For instance, in a GPS spoofing scenario, the injection of a false yet plausible position gradually and silently diverts the vessel from its intended route without triggering immediate detection, so that a small continuous error accumulates into a significant deviation over time. In addition, STPA-Sec was evaluated in comparison with the STRIDE, CORAS and Attack Trees methods, and a cost-benefit analysis was carried out for the most prominent security measures. For the cargo ship, nine cyber-attack scenarios were identified and classified according to their risk levels, of which three were assessed as critical, three as high, one as medium and two as low. The scenarios fall into several groups: attempts to spoof position and chart information on navigation systems, manipulation of commands to the machinery and steering, denial-of-service attacks against the operational technology network, and unauthorized access that violates the confidentiality of cargo and crew data. The highest-risk scenarios target the systems that directly govern the physical motion of the vessel, in particular the electronic chart display, the autopilot and the machinery control units. The results indicate that the most critical vulnerabilities are concentrated at the points where data received from external systems are used within control loops without adequate validation. This common root cause reflects the unverified trust that the system places in its incoming data flow rather than a weakness in any single component. The comparative evaluation of the methods further showed that component-oriented and threat-oriented approaches can structurally miss such interaction-based, system-level vulnerabilities, whereas STPA-Sec brings them, and their physical consequences, to the surface. To mitigate the identified vulnerabilities, specific security requirements were derived at the technical, operational and regulatory levels. The technical requirements address the protection of data integrity through encryption, the segmentation of the network into critical zones, the verification of software integrity, and the cross-checking of data from multiple sensors so that a single manipulated source can be detected. The operational requirements concern the improvement of the crew's cybersecurity awareness and the establishment of procedures for reporting incidents. The regulatory requirements emphasize compliance with international rules and the oversight mechanisms of classification societies. In prioritizing these requirements, the risk level of the scenario to which each requirement is linked was the decisive factor. The economic dimension of the proposed measures was also assessed. The investment was found to have a short payback period and a positive net present value, and was therefore judged to be economically justifiable. A sensitivity assessment, carried out against the uncertainty in the input values, showed that the resulting prioritization remained largely stable despite this uncertainty, which suggests that the ordering of the measures does not depend on the precise value of any single assumption. Considered as a whole, the original contribution of this study is an integrated framework that combines qualitative STPA-Sec analysis with quantitative risk assessment in the context of maritime cyber-physical systems, providing decision-makers with both a prioritization and a financial indicator. The results should be interpreted within the limitations of the study. The likelihood and impact values rely largely on informed estimates, because sector-specific data are scarce as a consequence of confidentiality and the limited reporting of incidents, and the analysis was conducted on representative models rather than on real field data. Future work may strengthen these estimates through validation with operational data and through probabilistic techniques such as Bayesian networks, and it may extend the detailed analysis carried out for the cargo ship to the port and autonomous vessel cases. Despite these limitations, the study demonstrates that the STPA-Sec methodology is a powerful and applicable tool for understanding the multi-component nature of maritime critical infrastructures and for proactively assessing cyber-physical risk scenarios that are difficult to foresee. More broadly, it underlines that cybersecurity in the maritime domain should be regarded not merely as a matter of information security but as a matter of physical safety.
Benzer Tezler
- Siber fiziksel sistemler üzerinde bütünleşik siber güvenlik risk değerlendirmesi: Bir konteyner limanı uygulaması
Integrated cyber security risk assesment on cyber pyhsical systems: A case study on a container port
BÜNYAMİN GÜNEŞ
Yüksek Lisans
Türkçe
2019
Denizcilikİstanbul Teknik ÜniversitesiDeniz Ulaştırma İşletme Mühendisliği Ana Bilim Dalı
DR. ÖĞR. ÜYESİ PELİN BOLAT
- Digital twin-enabled intelligent attack detection mechanisms for autonomous networks
Otonom ağlar için dijital ikiz destekli akıllı saldırı tespit mekanizmaları
YAĞMUR YİĞİT
Yüksek Lisans
İngilizce
2023
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrolİstanbul Teknik ÜniversitesiBilgisayar Mühendisliği Ana Bilim Dalı
PROF. DR. BERK CANBERK
- Ulusal ve uluslararası güvenlik politikaları temelinde dijitalleşme ve siber güvenlik: Hukuksal ve yönetsel bir değerlendirme
Digitalization and cybersecurity based on national and international security policies: A legal and administrative assessment
MEHMET ONUR ÖZER
Doktora
Türkçe
2023
Kamu YönetimiHatay Mustafa Kemal ÜniversitesiSiyaset Bilimi ve Kamu Yönetimi Ana Bilim Dalı
PROF. DR. MEHMET KAHRAMAN
- Advancing maritime security with uncrewed marine systems
İnsansız deniz sistemleri ile deniz güvenliğinin geliştirilmesi
DENİZ ÇİÇEK
Yüksek Lisans
İngilizce
2025
Savunma ve Savunma Teknolojileriİstanbul Teknik ÜniversitesiGeomatik Mühendisliği Ana Bilim Dalı
PROF. DR. BİHTER EROL
- IEC 61850 tabanlı akıllı şebekelerde zaman kısıtlı nondeterministik sonlu otomata (TC-NFA) ile anomali tespiti
Anomaly detection in IEC 61850-based smart grids using time-constrained nondeterministic finite automata (TC-NFA)
DENİZ BERFİN TAŞTAN
Yüksek Lisans
Türkçe
2026
EnerjiSakarya ÜniversitesiBilgisayar Mühendisliği Ana Bilim Dalı
DR. ÖĞR. ÜYESİ MUSA BALTA