首页|基于通用攻击树的电力工控系统安全研究

基于通用攻击树的电力工控系统安全研究

扫码查看
针对等级保护测评中电力行业工控系统普遍存在的安全风险,提出基于通用攻击树模型的风险量化评估方法.依据CVSSv3.1 系统对通用攻击树模型进行安全分析,对攻击树节点进行风险量化及攻击路径加权运算,提出精准建模、加权攻击能力与攻击路径、攻击发生概率等因素改进通用攻击树.该方法减少工控系统等保测评中的量化的人为主观因素,加权树及安全框架能为企业提供科学有效的风险防范措施.
Security Research of Electric Power Industrial Control System Based on General Attack Tree
Aiming at the common security risks of industrial control system in power industry in grade protec-tion evaluation,a quantitative risk assessment method based on general attack tree model is proposed.According to CVSSv3.1 system,the security analysis of the general attack tree model is carried out,and the risk quantification and attack path weighting are carried out on the nodes of the attack tree,and the factors such as accurate modeling,weighted attack capability and attack path,and attack probability are proposed to improve the general attack tree.The method reduces the quantified subjective factors in the industrial control system and other insurance evaluation.The weighted tree and safety framework can provide scientific and effective risk prevention measures for enterprises.

industrial control systemuniversal attack treegrade protection evaluation 2.0weighted treequantitative risk assessment

张建珍、祁彦军、闫波

展开 >

山西机电职业技术学院,山西 长治 046000

山西因弗美讯科技有限公司,山西 长治 046000

工业控制系统 通用攻击树 等保2.0 加权树 风险量化评估

2024

山西电子技术
山西省电子工业科学研究院 山西省电子学会

山西电子技术

影响因子:0.197
ISSN:1674-4578
年,卷(期):2024.(6)