首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >Continuous Quantitative Risk Management in Smart Grids Using Attack Defense Trees
【2h】

Continuous Quantitative Risk Management in Smart Grids Using Attack Defense Trees

机译:使用攻击防御树在智能电网中连续定量风险管理

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Although the risk assessment discipline has been studied from long ago as a means to support security investment decision-making, no holistic approach exists to continuously and quantitatively analyze cyber risks in scenarios where attacks and defenses may target different parts of Internet of Things (IoT)-based smart grid systems. In this paper, we propose a comprehensive methodology that enables informed decisions on security protection for smart grid systems by the continuous assessment of cyber risks. The solution is based on the use of attack defense trees modelled on the system and computation of the proposed risk attributes that enables an assessment of the system risks by propagating the risk attributes in the tree nodes. The method allows system risk sensitivity analyses to be performed with respect to different attack and defense scenarios, and optimizes security strategies with respect to risk minimization. The methodology proposes the use of standard security and privacy defense taxonomies from internationally recognized security control families, such as the NIST SP 800-53, which facilitates security certifications. Finally, the paper describes the validation of the methodology carried out in a real smart building energy efficiency application that combines multiple components deployed in cloud and IoT resources. The scenario demonstrates the feasibility of the method to not only perform initial quantitative estimations of system risks but also to continuously keep the risk assessment up to date according to the system conditions during operation.
机译:尽管从很久以前就已经研究了风险评估纪律作为支持安全投资决策的手段,但在攻击和防御可能针对事物互联网的不同部分的情况下,不存在整体方法,以便连续和定量地分析网络风险(IOT)基于智能电网系统。在本文中,我们提出了一种全面的方法,可以通过不断评估网络风险的智能电网系统的安全保护决策。该解决方案基于在系统上建模的攻击防御树的使用以及通过在树节点中传播风险属性来实现系统风险的建议风险属性的计算。该方法允许对不同攻击和防御方案进行系统风险敏感性分析,并优化关于风险最小化的安全策略。该方法提出了使用来自国际公认的安全控制家庭的标准安全和隐私辩护分类,例如NIST SP 800-53,这有助于安全认证。最后,本文介绍了在实际智能构建能效应用中执行的方法,该应用程序结合了在云和物联网资源中部署的多个组件。该方案展示了该方法不仅执行对系统风险的初始定量估计的可行性,而且还要根据运行期间的系统条件连续地保持风险评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号