计算机与现代化 ›› 2023, Vol. 0 ›› Issue (09): 105-114.doi: 10.3969/j.issn.1006-2475.2023.09.017

• 信息安全 • 上一篇    下一篇

基于随机Petri网的RFID系统安全性分析模型

  

  1. (1.南京邮电大学计算机学院,江苏 南京 210023; 2. 南京邮电大学网络安全和可信计算研究所,江苏 南京 210023)
  • 出版日期:2023-09-28 发布日期:2023-10-10
  • 作者简介:肖航(1998—),男,安徽广德人,硕士研究生,研究方向:物联网安全,E-mail: 1020041127@njput.edu.con; 通信作者:李鹏(1979—),男,福建长汀人,教授,博士生导师,研究方向:网络安全,云计算技术,E-mail: lipeng@njupt.edu.cn; 马荟平(1998—),男,甘肃白银人,硕士研究生,研究方向:物联网安全,E-mail: 1020041117@njput.edu.con; 朱枫(1986—),男,安徽合肥人,讲师,博士,研究方向:系统安全,E-mail: zhufeng@njupt.edu.cn。
  • 基金资助:
    国家自然科学基金资助项目(61872196, 61872194, 61902196, 62102194, 62102196); 江苏省六大人才高峰高层次人才项目(RJFW-111)

RFID System Security Analysis Model Based on Stochastic Petri Net

  1. (1. School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China; 2. Institute of Network Security and Trusted Computing of Nanjing University of Posts and Telecommunications, Nanjing 210023, China)
  • Online:2023-09-28 Published:2023-10-10

摘要: 针对日益频发的RFID系统攻击给RFID系统带来瘫痪风险问题,提出一种采用基于层次广义随机Petri网的RFID系统安全性分析模型。该模型利用已有的知识储备模拟真实的RFID虚拟环境,对攻击RFID系统过程进行准确有效的实验推演,并量化分析RFID系统风险。首先,利用攻击层次、攻击权限和基于权限的攻击等信息构建RFID攻击者模型;其次,对攻击者的行为进行建模描述,刻画其对RFID系统状态的影响;最后,基于所构建的模型对目标RFID系统的攻击概率、脆弱节点等方面进行风险评估。实验结果表明,本文提出模型可有效地对RFID系统进行风险评估,并且大大降低了评估时间和复杂度。

关键词: 随机Petri网, 安全评估, 时间复杂度, 组合攻击

Abstract: To solve the problem of RFID system breakdown risk caused by frequent RFID system attacks, this paper proposes a RFID system security analysis model based on hierarchical generalized stochastic Petri net. The model uses the existing knowledge reserve to simulate the real RFID virtual environment, accurately and effectively deduces the attack process in the RFID system, and quantifies the risk of the RFID system. Firstly, the RFID attacker model is constructed using the information of attack hierarchy,attack authority and permission-based attacks. Secondly, the description of the attacker's behavior is modeled  and described its impact on the RFID system state. Finally, based on the constructed model, the attack probability, weak nodes and other aspects of the RFID system are assessed. The experimental results show that the proposed model can effectively evaluate the risk of RFID system, and greatly reduce the complexity of evaluation time.

Key words: stochastic Petri net, safety assessment, time complexity, combination of attack

中图分类号: