首页|基于贝叶斯攻击图的油气生产物联网系统风险评估

基于贝叶斯攻击图的油气生产物联网系统风险评估

扫码查看
针对油气生产物联网系统动态风险评估问题,提出一种基于贝叶斯攻击图的油气生产物联网系统风险评估模型.首先通过对系统进行风险分析,得到入侵证据及系统漏洞,结合入侵证据和漏洞利用成功概率,采用EM算法对训练数据进行数据补全并动态更新贝叶斯攻击图的条件概率参数表,通过条件概率表可计算得出先验概率,结合入侵证据计算得到节点的后验概率,进而得到系统的风险值,考虑资源利用的相关性对风险值进行最终修正.仿真结果分析证明了该模型的有效性和准确性.
Risk assessment of oil and gas production IoT system based on Bayesian attack graph
Aiming at the dynamic risk assessment of oil and gas production IoT system,a risk assessment model of oil and gas production IoT system based on Bayesian attack graph was proposed.Firstly,through the risk analysis of the system,the intrusion evidence and system vulnerabilities are obtained,combined with the intrusion evidence and the success probability of vulnerability exploitation,the EM algorithm is used to complete the data of the training data and dynamically update the conditional probability parameter table of the Bayesian attack graph,the prior probability can be calculated through the conditional probability table,and the posterior probability of the node is calculated by combining the intrusion evidence,then the risk value of the system is ob-tained,and the risk value is finally corrected considering the correlation of resource utilization.The simulation results have proved the effectiveness and accuracy of the model.

Bayesian attack diagramBayesian parameter learningvalue-at-risk calculationrisk value correction

刘子龙、周纯杰、胡晓娅、曹德舜、李娜

展开 >

华中科技大学 人工智能与自动化学院,湖北 武汉 470074

深圳华中科技大学研究院,广东 深圳 518057

中石化安全工程研究院有限公司,山东 青岛 266000

贝叶斯攻击图 贝叶斯参数学习 风险值计算 风险值修正

深圳市科技计划

JCYJ20230807143613028

2024

网络安全与数据治理
华北计算机系统工程研究所(中国电子信息产业集团有限公司第六研究所)

网络安全与数据治理

影响因子:0.348
ISSN:2097-1788
年,卷(期):2024.43(4)
  • 14