信息网络安全 ›› 2023, Vol. 23 ›› Issue (9): 85-94.doi: 10.3969/j.issn.1671-1122.2023.09.008

• 技术研究 • 上一篇    下一篇

基于概率攻击图的工控系统跨域动态安全风险分析方法

浦珺妍, 李亚辉, 周纯杰()   

  1. 华中科技大学人工智能与自动化学院,武汉 430074
  • 收稿日期:2023-06-25 出版日期:2023-09-10 发布日期:2023-09-18
  • 通讯作者: 周纯杰 E-mail:cjiezhou@hust.edu.cn
  • 作者简介:浦珺妍(1999—),女,江苏,硕士研究生,主要研究方向为工控系统安全|李亚辉(1992—),男,河南,博士研究生,CCF会员,主要研究方向为工控系统安全、知识图谱|周纯杰(1965—),男,湖北,教授,博士,主要研究方向为网络化控制系统、工控系统安全
  • 基金资助:
    国家自然科学基金(62127808)

Cross-Domain Dynamic Security Risk Analysis Method of Industrial Control System Based on Probabilistic Attack Graph

PU Junyan, LI Yahui, ZHOU Chunjie()   

  1. School of Artificial Intelligence and Automation, Huazhong University of Science and Technology, Wuhan 430074, China
  • Received:2023-06-25 Online:2023-09-10 Published:2023-09-18
  • Contact: ZHOU Chunjie E-mail:cjiezhou@hust.edu.cn

摘要:

安全风险分析是保障工控系统长周期安全稳定运行的基础,信息物理紧耦合的特点增加了工控系统安全风险的复杂性。针对大规模复杂异构工控系统潜在安全风险精准跨域动态分析评估问题,文章提出一种基于概率攻击图的工控系统跨域动态安全风险分析方法。首先基于知识图谱技术将设备、漏洞和拓扑结构等安全元数据进行语义关联,并通过跨域攻击图生成算法完成跨域攻击图的自动生成;然后基于跨域攻击图将漏洞基本属性和威胁时变特点纳入风险传播概率计算,实现对工控系统跨域动态安全风险的定量分析。实验结果表明,该方法实现了对工控系统的自动化跨域动态安全风险分析,且双层攻击图的表现形式有效提升了安全分析人员对复杂系统分析的便捷性。

关键词: 工控系统, 概率攻击图, 知识图谱, 动态安全风险分析

Abstract:

Security risk analysis is the foundation for ensuring the long-term safe and stable operation of industrial control systems. The characteristics of cyber-physical coupling make the system security risk increase sharply. In order to realize accurate security situation awareness of large-scale industrial control systems, a cross-domain dynamic security risk analysis framework based on probabilistic attack graph was proposed. Firstly, the cross-domain attack graph was automatically generated by cross-domain attack graph generation algorithm based on system security metadata, system topology and association constraints between preconditions and postconditions of vulnerabilities in security knowledge graph. Then, based on the cross-domain attack graph, the basic attributes of vulnerabilities and the time-varying characteristics of threats were incorporated into the risk propagation probability calculation to realize the cross-domain dynamic security risk analysis of industrial control system. The experimental results show that the method realizing the automatic cross-domain dynamic security risk analysis of industrial control systems, and the representation of the two-layer attack graph effectively improves the convenience of security analysts in analyzing complex systems.

Key words: industrial control system, probabilistic attack graph, knowledge graph, dynamic security risk analysis

中图分类号: