Multimodel-Based Incident Prediction and Risk Assessment in Dynamic Cybersecurity Protection for Industrial Control Systems

Multimodel-Based Incident Prediction and Risk Assessment in Dynamic Cybersecurity Protection for Industrial Control Systems
复制标题

工业控制系统动态网络安全保护中基于多模型的事件预测和风险评估

DOI:
10.1109/tsmc.2015.2503399
复制
发表时间:
2016-10-01
影响因子:
8.7
通讯作者:
Huang, Shuang
Huang, Shuang
中科院分区:
计算机科学1区
文献类型:
--
作者:
Zhang, Qi;Zhou, Chunjie;Huang, Shuang

文献摘要

被引文献

相似文献

目前,越来越多的信息/通信技术被采用到工业控制系统(ICS)中。虽然这些IT技术提供了高度的灵活性,互操作性和方便的ICS管理,但它们也带来了网络安全风险。动态网络安全风险评估是安全保护的关键基础组成部分。然而,由于信息通信系统的特点,信息技术系统的风险评估并不完全适用于信息通信系统。本文通过对入侵检测系统特点的分析,提出了一种包含攻击模型、功能模型和事件模型的有针对性的多级贝叶斯网络。根据这一建议,一个新的基于多模型的危险事件预测方法的设计。在此基础上,设计了一种动态的网络安全风险评估方法,能够对未知攻击造成的风险进行评估。此外,为了提高风险评估的准确性,这可能会减少不同的后果之间的重叠的冗余积累,一个统一的后果量化方法。最后,为了验证所提出的方法的有效性,一个简化的化学反应器控制系统在MATLAB中进行了仿真。仿真结果表明,该方法能够及时动态计算智能通信系统的网络安全风险。此外,不同的比较模拟的结果表明,我们的方法有能力评估未知的攻击所造成的风险。
Currently, an increasing number of information/communication technologies are adopted into the industrial control systems (ICSs). While these IT technologies offer high flexibility, interoperability, and convenient administration of ICSs, they also introduce cybersecurity risks. Dynamic cybersecurity risk assessment is a key foundational component of security protection. However, due to the characteristics of ICSs, the risk assessment for IT systems is not completely applicable for ICSs. In this paper, through the consideration of the characteristics of ICSs, a targeted multilevel Bayesian network containing attack, function, and incident models is proposed. Following this proposal, a novel multimodel-based hazardous incident prediction approach is designed. On this basis, a dynamic cybersecurity risk assessment approach, which has the ability to assess the risk caused by unknown attacks, is also devised. Furthermore, to improve the accuracy of the risk assessment, which may be reduced by the redundant accumulation of overlaps amongst different consequences, a unified consequence quantification method is presented. Finally, to verify the effectiveness of the proposed approach, a simulation of a simplified chemical reactor control system is conducted in MATLAB. The simulation results can clearly demonstrate that the proposed approach has the ability to dynamically calculate the cybersecurity risk of ICSs in a timely manner. Additionally, the result of a different comparative simulation shows that our approach has the ability to assess the risk caused by unknown attacks.