首页> 外文期刊>IEEE Transactions on Systems, Man, and Cybernetics >Multimodel-Based Incident Prediction and Risk Assessment in Dynamic Cybersecurity Protection for Industrial Control Systems
【24h】

Multimodel-Based Incident Prediction and Risk Assessment in Dynamic Cybersecurity Protection for Industrial Control Systems

机译:工业控制系统动态网络安全保护中基于多模型的事件预测和风险评估

获取原文
获取原文并翻译 | 示例
       

摘要

Currently, an increasing number of information/communication technologies are adopted into the industrial control systems (ICSs). While these IT technologies offer high flexibility, interoperability, and convenient administration of ICSs, they also introduce cybersecurity risks. Dynamic cybersecurity risk assessment is a key foundational component of security protection. However, due to the characteristics of ICSs, the risk assessment for IT systems is not completely applicable for ICSs. In this paper, through the consideration of the characteristics of ICSs, a targeted multilevel Bayesian network containing attack, function, and incident models is proposed. Following this proposal, a novel multimodel-based hazardous incident prediction approach is designed. On this basis, a dynamic cybersecurity risk assessment approach, which has the ability to assess the risk caused by unknown attacks, is also devised. Furthermore, to improve the accuracy of the risk assessment, which may be reduced by the redundant accumulation of overlaps amongst different consequences, a unified consequence quantification method is presented. Finally, to verify the effectiveness of the proposed approach, a simulation of a simplified chemical reactor control system is conducted in MATLAB. The simulation results can clearly demonstrate that the proposed approach has the ability to dynamically calculate the cybersecurity risk of ICSs in a timely manner. Additionally, the result of a different comparative simulation shows that our approach has the ability to assess the risk caused by unknown attacks.
机译:当前,工业控制系统(ICS)中采用了越来越多的信息/通信技术。这些IT技术提供了ICS的高度灵活性,互操作性和便捷管理功能,但同时也带来了网络安全风险。动态网络安全风险评估是安全保护的重要基础部分。但是,由于ICS的特性,IT系统的风险评估并不完全适用于ICS。本文通过考虑ICS的特性,提出了一种包含攻击,功能和事件模型的目标多级贝叶斯网络。根据该建议,设计了一种新颖的基于多模型的危险事件预测方法。在此基础上,还设计了一种动态的网络安全风险评估方法,该方法可以评估未知攻击造成的风险。此外,为了提高风险评估的准确性(可能由于不同后果之间重叠的冗余积累而降低),提出了一种统一的后果量化方法。最后,为验证所提方法的有效性,在MATLAB中对简化的化学反应堆控制系统进行了仿真。仿真结果可以清楚地表明,该方法具有及时动态计算ICS的网络安全风险的能力。此外,不同比较模拟的结果表明,我们的方法能够评估未知攻击造成的风险。

著录项

  • 来源
    《IEEE Transactions on Systems, Man, and Cybernetics》 |2016年第10期|1429-1444|共16页
  • 作者单位

    Key Laboratory of Ministry of Education for Image Processing and Intelligent Control, School of Automation, Huazhong University of Science and Technology, Wuhan, China;

    Key Laboratory of Ministry of Education for Image Processing and Intelligent Control, School of Automation, Huazhong University of Science and Technology, Wuhan, China;

    Department of Business and Computer Science, Southwestern Oklahoma State University, Weatherford, OK, USA;

    Key Laboratory of Ministry of Education for Image Processing and Intelligent Control, School of Automation, Huazhong University of Science and Technology, Wuhan, China;

    Key Laboratory of Ministry of Education for Image Processing and Intelligent Control, School of Automation, Huazhong University of Science and Technology, Wuhan, China;

    Key Laboratory of Ministry of Education for Image Processing and Intelligent Control, School of Automation, Huazhong University of Science and Technology, Wuhan, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Risk management; Bayes methods; Industrial control; Control systems; Computer crime;

    机译:风险管理;贝叶斯方法;工业控制;控制系统;计算机犯罪;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号