首页|基于不完全信息静态博弈的工控系统风险评估方法

基于不完全信息静态博弈的工控系统风险评估方法

扫码查看
针对目前大多数工业控制系统风险评估方法未思考防御者策略以及攻防两者之间的对抗问题,提出一种基于博弈模型的风险评估方法.通过攻击防御图模型,计算攻击收益和防御收益;建立静态贝叶斯攻防博弈模型,计算混合策略贝叶斯纳什均衡,获得攻防两者最优策略概率分布.根据信息安全风险评估的计算方法,以防御者收益和攻击者最优策略选择概率分布为基础进行风险评估计算.通过一个实例证明了该方法的可行性和有用性.
RISK ASSESSMENT METHOD OF INDUSTRIAL CONTROL SYSTEM BASED ON INCOMPLETE INFORMATION STATIC GAME
At present,most industrial control system risk assessment methods do not consider the defender strategy and the confrontation between attack and defense.Therefore,this paper proposes a risk assessment method based on game model.The attack defense graph was used to calculate attack gain and defense gain.The static Bayesian attack and defense game model was established to calculate the mixed strategy Bayesian Nash equilibrium,and the optimal probability distribution of attack and defense strategies was obtained.According to the calculation method of information security risk assessment,the risk assessment analysis method was calculated based on the probability distribution of the defender's benefit and the attacker's optimal strategy selection.An example was used to illustrate the feasibility and usefulness of the proposed method.

Industrial control systemRisk assessmentStatic Bayesian gameBayesian game equilibrium

宋宇、张春杰、程超

展开 >

长春工业大学计算机科学与工程学院 吉林长春 130000

工业控制系统 风险评估 静态贝叶斯博弈 贝叶斯博弈均衡

国家自然科学基金项目吉林省发展改革委项目吉林省科技厅项目

619030472019C040-320200401127GX

2024

计算机应用与软件
上海市计算技术研究所 上海计算机软件技术开发中心

计算机应用与软件

CSTPCD北大核心
影响因子:0.615
ISSN:1000-386X
年,卷(期):2024.41(6)