计算机与现代化 ›› 2020, Vol. 0 ›› Issue (07): 32-37.doi: 10.3969/j.issn.1006-2475.2020.07.007

• 信息安全 • 上一篇    下一篇

攻击图与HMM工业控制网络安全风险评估

  

  1. (1.中国石油大学(华东)海洋与空间信息学院,山东青岛266580;
    2.中国石油大学(华东)计算机科学与技术学院,山东青岛266580)

  • 出版日期:2020-07-06 发布日期:2020-07-15
  • 作者简介:崔雯迪(1995-),女,山东淄博人,硕士研究生,研究方向:网络安全,电子通信,E-mail: 1752078453@qq.com; 段鹏飞(1996-),男,硕士研究生,研究方向:网络安全; 朱红强(1993-),男,硕士研究生,研究方向:网络安全,人工智能; 刘娜(1993-),女,硕士研究生,研究方向:网络安全。
  • 基金资助:
    国家自然科学基金资助项目(61772551); 山东省自然科学基金资助项目(ZR2019MF034)

Security Risk Assessmenton of Attack Graph and HMM Industrial Control Network

  1. (1. College of Oceanography and Space Informatics, China University of Petroleum, Qingdao 266580, China;
    2. College of Computer Science and Technology, China University of Petroleum, Qingdao 266580, China)
  • Online:2020-07-06 Published:2020-07-15

摘要: 为了准确评估工业控制系统的网络安全风险,实现工业控制系统的有效防御,提出攻击图与HMM的工业控制系统风险评估方法,根据攻击行为的变化描述网络安全状态。首先建立工业控制网络攻击图模型,将网络攻击转化为网络状态转换问题,引入网络节点关联性(NNC),对工业控制网络节点关联性进行研究,进一步分析网络的安全风险。然后HMM建立网络观测与攻击状态之间的关系,引入CVSS评价系统对工业控制系统的安全状态进行评价。最后,以火电厂集中控制系统为实验背景,进行案例分析。分析结果表明,该方法能够较全面分析工业控制系统的安全隐患,为安全管理人员采取有效的防范措施提供依据。

关键词: 工业控制网络, 网络安全, 风险评估, 攻击图, 隐马尔科夫模型

Abstract: In order to evaluate the network security risk of industrial control system and realize the effective defense of industrial control system, a risk assessment method based on attack graph and HMM is proposed to describe the network security status according to the change of attack behavior. Firstly, the industrial control network attack graph model is established, and the network attack is transformed into the network state migration problem. The network node association (NNC) is introduced to study the association of the industrial control network nodes, and further analyze the network security risks. Then the HMM establishes the relationship between network observation and attack state, and introduces the CVSS evaluation system to evaluate the security status of the industrial control system. Finally, a case study is carried out with the centralized control system of thermal power plant as the experimental background. The analysis results show that the method can comprehensively analyze the safety hazards of industrial control systems and provide a basis for safety management personnel to take effective preventive measures.

Key words: industrial control network, network security, risk assessment, attack map, hidden Markov models

中图分类号: