信息网络安全 ›› 2023, Vol. 23 ›› Issue (2): 26-34.doi: 10.3969/j.issn.1671-1122.2023.02.004

• 技术研究 • 上一篇    下一篇

一种基于ATT&CK的新型电力系统APT攻击建模

李元诚(), 罗昊, 王庆乐, 李建彬   

  1. 华北电力大学控制与计算机工程学院,北京 102206
  • 收稿日期:2022-10-09 出版日期:2023-02-10 发布日期:2023-02-28
  • 通讯作者: 李元诚 E-mail:ycli@ncepu.edu.cn
  • 作者简介:李元诚(1970—),男,山东,教授,博士,主要研究方向为网络信息安全|罗昊(1998—),男,湖北,硕士研究生,主要研究方向为网络信息安全|王庆乐(1987—),女,山东,副教授,博士,主要研究方向为量子密码|李建彬(1968—),男,山东,教授,博士,主要研究方向为网络空间安全

An Advanced Persistent Threat Model of New Power System Based on ATT&CK

LI Yuancheng(), LUO Hao, WANG Qingle, LI Jianbin   

  1. School of Control and Computer Engineering, North China Electric Power University, Beijing 102206, China
  • Received:2022-10-09 Online:2023-02-10 Published:2023-02-28
  • Contact: LI Yuancheng E-mail:ycli@ncepu.edu.cn

摘要:

以新能源为主体的新型电力系统,新能源与多元负荷形态比例大幅提升。高比例的可再生新能源与电力电子设备的接入以及供给侧和需求侧的随机性,导致电网遭受的攻击面增大,攻击者利用隐蔽和复杂的手段针对新型电力系统发动高级可持续威胁攻击,严重影响电网调度与能源消纳。文章基于ATT&CK知识库建立了面向新型电力系统APT攻击的杀伤链模型,针对传统方法难以将 APT 攻击技术划分到杀伤链攻击阶段,从而导致安全员无法迅速做出防御决策的情况,提出了一种基于杀伤链模型的APT攻击技术阶段划分方法,并采用Bert模型对技术文本进行语义分析,自动将攻击技术划分到所属阶段。实验结果表明,文章所提方法比现有模型具有更好的效果。

关键词: 新型电力系统, APT攻击, ATT&CK, 攻击建模, Bert模型

Abstract:

The establishment of a new power system with new energy as the main body has greatly increased the proportion of new energy and multiple load forms. The high proportion of renewable energy and power electronic equipment access, as well as the randomness of the supply side and the demand side, lead to an increase in the attack surface of the power grid. Advanced persistent threat (APT), which tamper or block data, seriously affect grid scheduling and energy consumption. Based on the ATT&CK knowledge base, a kill chain model for APT attacks on new power systems was established. It is difficult to divide the APT attack technology into the kill chain attack stage, resulting in the inability of security personnel to make defense decision-making quickly, a method of dividing APT attack technology stages based on the kill chain model was proposed. The Bert model was used to perform semantic analysis on technical texts, and the attack technologies were automatically divided into their respective stages by training the model. Experimental results show that this method achieves better results than existing models.

Key words: new power system, advanced persistent threat, ATT&CK, attack modeling, Bert model

中图分类号: