A digital asset vulnerability analysis method based on FTA fault tree

Through the analysis method based on the FTA fault tree, the problem of omissions in the security strategy in the digital asset management system is solved, and the vulnerability of digital assets is achieved is achieved, and the security and management efficiency of the industrial control network is improved.

CN114202192BActive Publication Date: 2025-08-22SHANGHAI THREE ZERO GUARD INFORMATION SECURITY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111498674.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-09
Publication Date
2025-08-22
Estimated Expiration
2041-12-09

AI Technical Summary

Technical Problem

The existing digital asset management system cannot effectively supervise the diversity, complexity and different logical relationships between functions and digital assets, resulting in serious omissions in security policies, affecting the safe operation of industrial control networks.

Method used

Using an analysis method based on the FTA fault tree, by drawing the hierarchical relationships of top events, intermediate events, and bottom events, we gradually refine digital assets in a hierarchical manner, associate specific digital assets, and analyze the final functional level affected by their failures through algorithms, and combine the network topology and risk assessment system to evaluate the vulnerability of digital assets.

Benefits of technology

It realizes clear assessment and management of the vulnerability of digital assets, provides a basis for further assessment, and improves the security and management efficiency of industrial control networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114202192B_ABST
    Figure CN114202192B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security of industrial control network systems and discloses a digital asset vulnerability analysis method based on an FTA fault tree, comprising the steps of (1) drawing an FTA fault tree; (2) analyzing the scope of digital assets; (3) associating digital assets with bottom events; (4) analyzing the functional levels affected by a digital asset failure; (5) analyzing multiple digital assets subjected to network attacks and calculating the affected functions and levels respectively; and (6) merging the functions to obtain the highest functional level ultimately affected. The digital asset vulnerability analysis method based on the FTA fault tree of the present invention, by gradually refining the functions, associating specific digital assets, and obtaining the final functional level affected by multiple digital asset failures through an algorithm, provides a basis for further evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security of industrial control network systems, and in particular to a digital asset vulnerability analysis method based on an FTA fault tree. Background Art

[0002] With the rapid development of informatization, networks are becoming increasingly large and widespread, and the types and number of devices connected to them are rapidly increasing. Information security issues in industrial control network systems are becoming increasingly prominent. Since the Stuxnet worm attack on Iran's nuclear facilities in 2010, both domestic and international communities have paid greater attention to the issue of information security in industrial control networks. Information security attacks can affect the availability, integrity, and confidentiality of software and data, adversely impacting the operation of systems, networks, and related equipment, and posing a threat to the security of industrial control networks.

[0003] Fault Tree Analysis is abbreviated as FTA. It is a "top-down" method to identify which part of a system is related to a specific failure. For FTA, this event is usually the loss or degradation of system performance, safety or other important operational attributes. Fault trees are used to identify design problems in complex systems. The end result of fault tree analysis is a diagram that graphically displays the combination of events that may cause system failure under identifiable failure modes. Fault trees are mainly used in engineering design to help identify potential design weaknesses. Fault trees are also of great value in investigating the causes of failures or accidents. FTA is often used for safety analysis of systems, and can also be used for availability and maintainability analysis. At the bottom of the fault tree are "basic faults" and "triggering events", which are generally considered to be the root causes of any failure.

[0004] In actual industrial control production environments, due to the diversity, complexity, and different logical relationships between functions and digital assets, these situations are not recorded in existing digital asset management systems or operation and maintenance systems, and cannot be supervised, resulting in serious omissions in security policies. However, management departments lack effective monitoring and management technical means to discover and manage these violations, seriously affecting the safe operation of internal networks.

[0005] Therefore, to more clearly identify the corresponding relationships between top events, intermediate events, and bottom events, the FTA analysis method was adopted. By gradually refining the functions by level, linking them to specific digital assets, and using an algorithm to determine the final functional level affected by multiple digital asset failures, this method provides a basis for further evaluation. Summary of the Invention

[0006] The purpose of the present invention is to provide a digital asset vulnerability analysis method based on FTA fault tree to solve the problem raised in the above background technology that due to the diversity, complexity and different logical relationships between functions and digital assets, these situations have no records in the existing digital asset management system or operation and maintenance system, and are even more impossible to supervise.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] A digital asset vulnerability analysis method based on an FTA fault tree, the steps of the analysis method are as follows:

[0009] S1: Draw FTA fault tree: Draw the hierarchical relationship of top events, intermediate events, and bottom events through FTA, and judge the logical relationship between events in each layer based on different symbols;

[0010] S2: Analyze the scope of digital assets: According to the FTA fault tree, organize, analyze and identify the scope of digital assets;

[0011] S3: Digital assets associated with bottom events: Based on different bottom events, different digital assets required to implement the bottom events are associated;

[0012] S4: Analyze the functional levels affected by a digital asset failure: Starting from the lowest-level digital asset, the devices connected to the bottom event (leaf function) default to a logical AND relationship, and the digital assets associated with the device default to a logical AND relationship. Based on different logical relationship operations, gradually move upward to the highest-level functions affected by a digital asset failure.

[0013] S5: Based on the network topology of digital assets, the risk assessment system is used to obtain vulnerability information of each digital asset. When multiple digital assets in the network topology are affected by a network attack, the failure or degradation of multiple functions can be obtained.

[0014] S6: By analyzing the impact on several functions, and then performing logical operations to merge several functions, the final affected functions are obtained, which serves as a basis for the next step of evaluation.

[0015] Preferably, the method of dividing the top event, intermediate event and bottom event in S1 is to use the function realized by the entire FTA tree as the top event, and decompose it into different sub-functions according to the principle of top-down. Each sub-function has a hierarchical relationship and a logical relationship. Until the sub-function cannot be further decomposed downward, the bottom-level function is called the bottom event; the function is logically decomposed downward.

[0016] Preferably, the digital assets of S2 are obtained through screening, that is, a combination of manual and scanning.

[0017] Preferably, the manner of associating the device and the digital asset in S4 is based on business correspondence.

[0018] Preferably, the analysis of the functional level affected by a digital asset failure in S4 specifically includes the following steps:

[0019] S5-1. Check whether the digital asset list is running normally. If normal, no action is required. If abnormal, query the connected device list through digital assets.

[0020] S5-2. If the device list is equal to zero in step S5-1, the process ends. If the device list is greater than zero, the digital asset is added to the array and the function list connected by the device is queried.

[0021] S5-3. If the function list is equal to zero in step S5-2, the process ends. If the function list is greater than zero, the device is added to the array, and the function name is queried through the bottom event (leaf function) and set as the top event;

[0022] S5-4, step S5-3: If the top event is confirmed, add the function name and level to the array, jump to processing result 2, that is, the highest level of the affected function, and then continue to judge the logical relationship of the sub-functions under this highest level to calculate whether this highest level will be affected. If the top event is denied, add the function name and level to the array and find the parent function through the sub-function, that is, the top event;

[0023] If the top event is confirmed in step S5-5 and S5-4, the top event information name and logical operation type are obtained, and the process jumps to processing result 1, i.e., the highest level of the affected function. It is then necessary to continue to determine the logical relationship of the sub-functions under this highest level, thereby calculating whether this highest level will be affected. If processing result 1 is confirmed, the process jumps to processing result 2 after adding the function group name and the hierarchical relationship. If processing result 1 is denied, the process jumps directly to processing result 2.

[0024] S5-6. If the top event is denied in step S5-4, the intermediate event name and logical operator are obtained, and the process is jumped to result 1. If the process result 1 is denied, the process is directly jumped to result 2. If the process result 1 is confirmed, the intermediate event name and level are added, and the parent event is found through the intermediate event. If the parent event is the top event, the process is jumped to the intermediate event name and logical operator to repeat the process. If the parent event is the top event, the process is confirmed to obtain the top event name and logical operator, and jump to result 1 in S5-5.

[0025] Preferably, the specific operation of S6 is:

[0026] In processing result 1, the logical operation type of the top event is "and", so the event status is judged to be abnormal and the next step of judgment is entered;

[0027] In processing result 1, the logical operation type of the top event is "not", and the logical operation type of the intermediate time is "or". The sub-events under this intermediate event are obtained. If all the sub-events below are abnormal, the intermediate event will be abnormal; otherwise, the intermediate event will not be abnormal.

[0028] The logical operation type of the intermediate event is 3Vote2, and the number of sub-events under this intermediate event is 3. If two or three of these sub-events are abnormal, the intermediate event status will be abnormal; otherwise, the intermediate event will not be abnormal.

[0029] The logical operation type of the intermediate event is 4Vote2. The number of sub-events under this intermediate event is 4. If two, three, or four of them are abnormal, the intermediate event status will be abnormal. Otherwise, the intermediate event will not be abnormal.

[0030] The logical operation type of the intermediate event is 4Vote3. The number of sub-events under this intermediate event is 4. If 3 or 4 of them are abnormal, the intermediate event status will be abnormal; otherwise, the intermediate event will not be abnormal.

[0031] Compared with the prior art, the present invention has the following beneficial effects:

[0032] The digital asset vulnerability analysis method based on the FTA fault tree described in the present invention gradually refines the functions by level and level, associates them with specific digital assets, and obtains the final functional level affected by multiple digital asset failures through an algorithm, thereby providing a basis for further evaluation. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 This is a logic operation flow chart of S4 analyzing the functional levels affected by a digital asset fault in the digital asset vulnerability analysis method based on the FTA fault tree of the present invention;

[0034] Figure 2 This is a logic operation flow chart of S6 in the digital asset vulnerability analysis method based on FTA fault tree described in the present invention. DETAILED DESCRIPTION

[0035] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0036] The present invention provides the following technical solutions:

[0037] A digital asset vulnerability analysis method based on an FTA fault tree, the steps of the analysis method are as follows:

[0038] S1: Draw FTA fault tree: Draw the hierarchical relationship of top events, intermediate events, and bottom events through FTA, and judge the logical relationship between events in each layer based on different symbols;

[0039] S2: Analyze the scope of digital assets: According to the FTA fault tree, organize, analyze and identify the scope of digital assets;

[0040] S3: Digital assets associated with bottom events: Based on different bottom events, different digital assets required to implement the bottom events are associated;

[0041] S4: Analyze the functional levels affected by a digital asset failure: Starting from the lowest-level digital asset, the devices connected to the bottom event (leaf function) default to a logical AND relationship, and the digital assets associated with the device default to a logical AND relationship. Based on different logical relationship operations, gradually move upward to the highest-level functions affected by a digital asset failure.

[0042] S5: Based on the network topology of digital assets, the risk assessment system is used to obtain vulnerability information of each digital asset. When multiple digital assets in the network topology are affected by a network attack, the failure or degradation of multiple functions can be obtained.

[0043] S6: By analyzing the impact on several functions, and then performing logical operations to merge several functions, the final affected functions are obtained, which serves as a basis for the next step of evaluation.

[0044] Furthermore, the method of dividing the top event, intermediate event, and bottom event in S1 is to use the function realized by the entire FTA tree as the top event, and decompose it into different sub-functions according to the top-down principle. Each sub-function has a hierarchical relationship and a logical relationship. Until the sub-function cannot be further decomposed downward, the bottom-level function is called the bottom event; the function is logically decomposed downward.

[0045] Furthermore, the digital assets of S2 are obtained through screening, that is, a combination of manual and scanning.

[0046] Furthermore, the manner of associating the device and the digital asset in S4 corresponds to the business.

[0047] Furthermore, the analysis of the functional level affected by a digital asset failure in S4 specifically includes the following steps:

[0048] S5-1. Check whether the digital asset list is running normally. If normal, no action is required. If abnormal, query the connected device list through digital assets.

[0049] S5-2. If the device list is equal to zero in step S5-1, the process ends. If the device list is greater than zero, the digital asset is added to the array and the function list connected by the device is queried.

[0050] S5-3. If the function list is equal to zero in step S5-2, the process ends. If the function list is greater than zero, the device is added to the array, and the function name is queried through the bottom event (leaf function) and set as the top event;

[0051] S5-4, step S5-3: If the top event is confirmed, add the function name and level to the array, jump to processing result 2, that is, the highest level of the affected function, and then continue to judge the logical relationship of the sub-functions under this highest level to calculate whether this highest level will be affected. If the top event is denied, add the function name and level to the array and find the parent function through the sub-function, that is, the top event;

[0052] If the top event is confirmed in step S5-5 and S5-4, the top event information name and logical operation type are obtained, and the process jumps to processing result 1, i.e., the highest level of the affected function. It is then necessary to continue to determine the logical relationship of the sub-functions under this highest level, thereby calculating whether this highest level will be affected. If processing result 1 is confirmed, the process jumps to processing result 2 after adding the function group name and the hierarchical relationship. If processing result 1 is denied, the process jumps directly to processing result 2.

[0053] S5-6. If the top event is denied in step S5-4, the intermediate event name and logical operator are obtained, and the process is jumped to result 1. If the process result 1 is denied, the process is directly jumped to result 2. If the process result 1 is confirmed, the intermediate event name and level are added, and the parent event is found through the intermediate event. If the parent event is the top event, the process is jumped to the intermediate event name and logical operator to repeat the process. If the parent event is the top event, the process is confirmed to obtain the top event name and logical operator, and jump to result 1 in S5-5.

[0054] Furthermore, the specific operation of S6 is:

[0055] In processing result 1, the logical operation type of the top event is "and", so the event status is judged to be abnormal and the next step of judgment is entered;

[0056] In processing result 1, the logical operation type of the top event is "not", and the logical operation type of the intermediate time is "or". The sub-events under this intermediate event are obtained. If all the sub-events below are abnormal, the intermediate event will be abnormal; otherwise, the intermediate event will not be abnormal.

[0057] The logical operation type of the intermediate event is 3Vote2, and the number of sub-events under this intermediate event is 3. If two or three of these sub-events are abnormal, the intermediate event status will be abnormal; otherwise, the intermediate event will not be abnormal.

[0058] The logical operation type of the intermediate event is 4Vote2. The number of sub-events under this intermediate event is 4. If two, three, or four of them are abnormal, the intermediate event status will be abnormal. Otherwise, the intermediate event will not be abnormal.

[0059] The logical operation type of the intermediate event is 4Vote3. The number of sub-events under this intermediate event is 4. If 3 or 4 of them are abnormal, the intermediate event status will be abnormal; otherwise, the intermediate event will not be abnormal.

[0060] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A digital asset vulnerability analysis method based on FTA fault tree, characterized by: The steps of the analytical method are as follows: S1: Draw FTA fault tree: Draw the hierarchical relationship of top events, intermediate events, and bottom events through FTA, and judge the logical relationship between events in each layer based on different symbols; S2: Analyze the scope of digital assets: According to the FTA fault tree, organize, analyze and identify the scope of digital assets; S3: Digital assets associated with bottom events: Based on different bottom events, different digital assets required to implement the bottom events are associated; S4: Analyze the functional levels affected by a digital asset failure: Starting from the lowest-level digital asset, the devices connected to the bottom event default to a logical AND relationship, and the digital assets associated with the devices default to a logical AND relationship. Based on different logical relationship operations, gradually move upward to the highest-level functions affected by a digital asset failure. S5: Based on the network topology of digital assets, the risk assessment system is used to obtain vulnerability information of each digital asset. When multiple digital assets in the network topology are affected by a network attack, the failure or degradation of multiple functions can be obtained. S6: By analyzing the impact of several functions, and then performing logical operations on several functions, the final affected functions are obtained, which serves as a basis for the next step of evaluation; The association method between devices and digital assets in S4 is based on business correspondence; Analyzing the functional level affected by a digital asset failure in S4 specifically includes the following steps: S5-1. Check whether the digital asset list is running normally. If normal, no action is required. If abnormal, query the connected device list through digital assets. S5-2. If the device list is equal to zero in step S5-1, the process ends. If the device list is greater than zero, the digital asset is added to the array and the function list connected by the device is queried. S5-3, if the function list is equal to zero in step S5-2, the process ends. If the function list is greater than zero, the device is added to the array, the function name is queried through the bottom event, and set as the top event; S5-4, step S5-3: If the top event is confirmed, add the function name and level to the array, jump to processing result 2, that is, the highest level of the affected function, and then continue to judge the logical relationship of the sub-functions under this highest level to calculate whether this highest level will be affected. If the top event is denied, add the function name and level to the array and find the parent function through the sub-function, that is, the top event; If the top event is confirmed in step S5-5 and S5-4, the top event information name and logical operation type are obtained, and the process jumps to processing result 1, i.e., the highest level of the affected function. It is then necessary to continue to determine the logical relationship of the sub-functions under this highest level, thereby calculating whether this highest level will be affected. If processing result 1 is confirmed, the process jumps to processing result 2 after adding the function group name and the hierarchical relationship. If processing result 1 is denied, the process jumps directly to processing result 2. S5-6. If the top event is denied in step S5-4, the intermediate event name and logical operator are obtained, and the process is jumped to result 1. If the process result 1 is denied, the process is directly jumped to result 2. If the process result 1 is confirmed, the intermediate event name and level are added, and the parent event is found through the intermediate event. If the parent event is the top event, the process is jumped to the intermediate event name and logical operator to repeat the process. If the parent event is the top event, the process is confirmed to obtain the top event name and logical operator, and jump to result 1 in S5-5.

2. The digital asset vulnerability analysis method based on FTA fault tree according to claim 1, characterized in that: The method of dividing the top event, intermediate event, and bottom event in S1 is to use the function realized by the entire FTA tree as the top event, and decompose it into different sub-functions according to the principle of top-down. Each sub-function has a hierarchical relationship and logical relationship. Until the sub-function cannot be further decomposed downward, the bottom-level function is called the bottom event; the function is logically decomposed downward.

3. The digital asset vulnerability analysis method based on FTA fault tree according to claim 1, characterized in that: The digital assets of S2 are obtained through investigation, that is, a combination of manual and scanning.

4. The digital asset vulnerability analysis method based on FTA fault tree according to claim 1, characterized in that: The specific operations of S6 are: In processing result 1, the logical operation type of the top event is "and", so the event status is judged to be abnormal and the next step of judgment is entered; In processing result 1, the logical operation type of the top event is "not", and the logical operation type of the intermediate time is "or". The sub-events under this intermediate event are obtained. If all the sub-events below are abnormal, the intermediate event will be abnormal; otherwise, the intermediate event will not be abnormal. The logical operation type of the intermediate event is 3Vote2, and the number of sub-events under this intermediate event is 3. If two or three of these sub-events are abnormal, the intermediate event status will be abnormal; otherwise, the intermediate event will not be abnormal. The logical operation type of the intermediate event is 4Vote2. The number of sub-events under this intermediate event is 4. If two, three, or four of them are abnormal, the intermediate event status will be abnormal. Otherwise, the intermediate event will not be abnormal. The logical operation type of the intermediate event is 4Vote3. The number of sub-events under this intermediate event is 4. If 3 or 4 of them are abnormal, the intermediate event status will be abnormal; otherwise, the intermediate event will not be abnormal.

Citation Information

Patent Citations

  • Industrial control network security influence analysis method based on function analysis

    CN111585969A