信息网络安全 ›› 2017, Vol. 17 ›› Issue (4): 86-90.doi: 10.3969/j.issn.1671-1122.2017.04.012

• • 上一篇    下一篇

基于电力系统的信息安全风险评估机制研究

梁智强(), 林丹生   

  1. 广东电网有限责任公司电力科学研究院,广东广州 510080
  • 收稿日期:2017-03-11 出版日期:2017-04-20 发布日期:2020-05-12
  • 作者简介:

    作者简介: 梁智强(1983—),男,广东,高级工程师,硕士,主要研究方向为电力信息安全、电力调度自动化技术;林丹生(1986—),男,广东,工程师,硕士,主要研究方向为电力信息安全技术。

Information Security Risk Assessment Mechanism Research Based on Power System

Zhiqiang LIANG(), Dansheng LIN   

  1. Electric Power Research Institute of Guangdong Power Grid Corp Ltd, Guangzhou Guangdong 510080, China
  • Received:2017-03-11 Online:2017-04-20 Published:2020-05-12

摘要:

针对传统电力系统中信息安全风险评估机制精确度较差、完善性欠缺与效率值较低等不足,文章依据电力系统的特定应用情况,将层次分析法(AHP)引入到风险评估机制中,并在风险计算过程中采取模糊数学知识,设计出一种新型的信息安全风险评估模型,即AF-RA模型,并对此模型进行详细阐述与分析。该模型首先构造脆弱性评估层次结构,评估威胁强制利用系统脆弱点的发生概率,并通过专家学者对其评估对象进行赋分;其次通过资产、威胁及脆弱性三类风险计算基本点的安全价值,综合风险参数与计算结果,从而计算得到被评估目标的整体风险;最后通过风险计算对总体数据信息以及核心资产安全风险重要程度排序,依据电力系统的安全应用特征,做出与安全风险级别相对应的安全处理方式,达到减少相关系统脆弱点的目的。

关键词: 风险评估, 电力系统, 层次分析法, 模糊数学, AF-RA

Abstract:

This paper is dedicated to design a brand new information security risk assessment model, aka AF-RA model, based on AHP analysis algorithm utilized in risk assessment system and methods from fussy mathematics under the specific application condition of electricity power system, to address the problems of relatively low accuracy, low efficiency and inadequate optimization of information risk assessment mechanism in classical electricity power system. This model will be explained and analyzed in depth in this paper. In this model, the probability of the system vulnerabilities being exploited is estimated through a hierarchical structure of vulnerabilities assessment subsystem, and then a threatening level mark is given from the expertise. The security value of primal points is calculated according to risk level of the asset, threatening and vulnerability and the overall risk of the subject under assessment can be concluded based on this calculation result and synthesized risk parameters. At the output side of this model, security measures to eliminate the vulnerability of correlated systems can be arranged according to the security risk level concluded and the measures is prioritized by the significance of the total data information and core asset security, in accordance of the specific characteristics of electricity power system security.

Key words: risk assessment, power system, AHP, fuzzy math, AF-RA

中图分类号: