CVSS Based Attack Analysis Using a Graphical Security Model: Review and Smart Grid Case Study

CVSS Based Attack Analysis Using a Graphical Security Model: Review and Smart Grid Case Study
复制标题

使用图形安全模型进行基于 CVSS 的攻击分析:回顾和智能电网案例研究

DOI:
--
复制
发表时间:
2020
期刊:
SGIoT
影响因子:
--
通讯作者:
Yasuo Tan
Yasuo Tan
中科院分区:
--
文献类型:
--
作者:
T. Le;Mengmeng Ge;Phan The Duy;Hien Do Hoang;A. Anwar;S. Loke;R. Beuran;Yasuo Tan

文献摘要

被引文献

相似文献

智能电网是为社会和经济发展提供基本服务的关键技术之一。近年来,智能电网系统受到了各种网络攻击,造成了各种负面影响。因此,了解智能电网系统的特点和评估攻击的后果是至关重要的。图形安全模型(GrSM)包括攻击树(AT)和攻击图(AG),与通用漏洞评分系统(CVSS)相结合是分析智能电网系统攻击的潜在技术。然而,目前利用GrSM和CVSS进行智能电网攻击分析的研究工作还很少。在本研究中,我们首先对使用GrSM和CVSS进行攻击分析的现有研究进行全面研究,范围包括(1)传统网络、(2)新兴技术和(3)智能电网。我们指出,物联网的自动化安全分析框架是一个很有前途的方向,智能电网攻击分析使用GrSM和CVSS。该框架已被应用于评估智能电网系统的安全性。一个案例研究使用PNNL分类馈线R4-12.47-2和智能电网网络模型与网关进行验证所使用的框架。通过捕获所有潜在的攻击路径并在漏洞分析过程中计算选定的安全度量值,丰富了我们的研究。此外,AG可以自动生成。该研究可用于智能电网网络安全培训。
Smart Grid is one of the critical technologies that provide essential services to sustain social and economic developments. There are various cyber attacks on the Smart Grid system in recent years, which resulted in various negative repercussions. Therefore, understanding the characteristics and evaluating the consequences of an attack on the Smart Grid system is essential. The combination of Graphical Security Model (GrSM), including Attack Tree (AT) and Attack Graph (AG), and the Common Vulnerability Score System (CVSS) is a potential technology to analyze attack on Smart Grid system. However, there are a few research works about Smart Grid attack analysis using GrSM and CVSS. In this research, we first conduct a comprehensive study of the existing research on attack analysis using GrSM and CVSS, ranging from (1) Traditional Networks, (2) Emerging Technologies, to (3) Smart Grid. We indicate that the framework for automating security analysis of the Internet of Things is a promising direction for Smart Grid attack analysis using GrSM and CVSS. The framework has been applied to assess security of the Smart Grid system. A case study using the PNNL Taxonomy Feeders R4-12.47-2 and Smart Grid network model with gateways was conducted to validate the utilized framework. Our research is enriched by capturing all potential attack paths and calculating values of selected security metrics during the vulnerability analysis process. Furthermore, AG can be generated automatically. The research can potentially be utilized in Smart Grid cybersecurity training.