首页|面向流程工业系统的关键攻击步骤识别

面向流程工业系统的关键攻击步骤识别

扫码查看
流程工业系统面临愈来愈多的威胁,基于攻击图的关键攻击步骤识别方法能够主动识别系统威胁,提高系统安全性。然而现有方法未考虑流程工业系统层次结构、工艺执行、事故危害等特征,无法全面准确衡量系统安全情况。为此,提出一种基于混合攻击图的关键攻击步骤识别方法,通过对攻击步骤重要性程度进行排序,实现面向流程工业系统的关键攻击步骤识别。首先,构建混合攻击图识别攻击者可能采取的攻击步骤,克服传统攻击图构建方法对网络可达性的依赖。其次,综合流程工业系统特征量化攻击期望,改进接近和介数中心性指标,以捕捉混合攻击图中的攻击路径信息,同时提出边期望中心性实现节点连接边的重要性度量。最后,改进多属性决策方法实现关键攻击步骤识别。实验分析表明,所提方法能够较全面地识别系统潜在威胁,合理衡量攻击步骤节点及连接边的重要性,有效识别流程工业系统场景中的关键攻击步骤。
Identification of Critical Attack Step for Process Industrial Systems
Security threats in process industrial systems have become increasingly prominent.The identification of critical attack step based on attack graph can identify system threats and improve the security.However,the current identification methods are unable to measure the security of process industrial systems comprehensively and accurately,because system characteristics,such as hierarchical structure,process execution,and accident hazards,have not been taken account in these methods.We propose an identification method of critical attack step based on hybrid attack graph.The method achieves the identification of critical attack step in process industrial systems by ranking the importance of attack steps in the hybrid attack graph.Firstly,a hybrid attack graph is built to identify all possible attack steps,which has a reduction of high dependence on network reachability in traditional attack graph building methods.Then attack expectant is computed according to system characteristics.Closeness and betweenness centralities are improved to capture attack path in-formation,and the edge expectant centrality is put forward to measure edge importance.Finally,a multi-attribute decision-making method is modified to achieve the evaluation of attack step importance and the identification of critical step.Experimental results show that the proposed method can completely identify all potential threats in process industrial systems,reasonably measure attack step importance,and effectively identify critical attack step.

process industry systemattack graphattack pathcentrality metricscritical attack step

陈翊璐、王子博、张耀方、梁超、刘红日、王佰玲

展开 >

哈尔滨工业大学(威海) 计算机科学与技术学院,山东 威海 264200

威海天之卫网络空间安全科技有限公司,山东 威海 264200

流程工业系统 攻击图 攻击路径 中心性指标 关键攻击步骤

国家重点研发计划

2021YFB2012400

2024

计算机技术与发展
陕西省计算机学会

计算机技术与发展

CSTPCD
影响因子:0.621
ISSN:1673-629X
年,卷(期):2024.34(2)
  • 20