Risk Identification Method and System for STAMP-Based Industrial Control Systems

By generating a hazard scenario tree to display the risk identification results of industrial control systems, the problem that the STPA method cannot be displayed intuitively is solved. This enables in-depth risk identification and safety analysis of industrial control systems. Combined with functional safety and information security constraints, it improves the visualization and operability of risk identification.

CN116880374BActive Publication Date: 2026-01-30INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310712000.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-15
Publication Date
2026-01-30
Estimated Expiration
2043-06-15

AI Technical Summary

Technical Problem

Existing STPA methods based on STAMP cannot intuitively display the risk identification results of industrial control systems, and fail to effectively identify the interaction between information security risks and functional safety risks.

Method used

The STAMP-based risk identification method for industrial control systems generates a hazard scenario tree, which includes the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping results from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. This method intuitively displays the risk identification results and combines functional safety and information security constraints.

Benefits of technology

It enables an intuitive display of risk identification results for industrial control systems, allowing for more effective in-depth safety analysis of key components and the development of safety mitigation strategies. It overcomes the abstract limitations and reliance on expert experience of the STPA method, improving the visualization and operability of risk identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116880374B_ABST
    Figure CN116880374B_ABST
Patent Text Reader

Abstract

This invention provides a risk identification method and system for industrial control systems based on STAMP. The method includes: generating a hazard scenario tree for the industrial control system based on target parameters required for generating such a tree. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined based on the topology and control structure of the industrial control system. Based on the hazard scenario tree, the risks existing in the industrial control system are identified. The system executes the method. This invention, based on the finally generated hazard scenario tree, more intuitively displays the risk identification results of the industrial control system, enabling more effective in-depth safety analysis of equipment within the industrial control system and the formulation of safety mitigation strategies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control technology, and in particular to a risk identification method and system for an industrial control system based on STAMP. Background Technology

[0002] Industrial control systems are the nerve center of a nation's critical infrastructure, widely used in sectors vital to the national economy and people's livelihoods, such as water conservancy, transportation, power, and pipeline transport. In the past, industrial control systems largely relied on physically closed networks and proprietary component protocols, facing risks primarily from within the system itself, namely functional safety risks such as equipment failure and human error. With the increasing informatization of industrial control systems, the information security risks they face are also growing. Industrial control systems are highly vulnerable to cyber-physical attacks, necessitating methods for identifying these convergent risks.

[0003] Industrial control systems differ from traditional software systems. Attackers can exploit the compliance functions provided by industrial control systems to cause production interruptions or even physical domain damage simply by modifying business logic. Traditional information security risk identification methods, based on the identification of assets, threats, and vulnerabilities, cannot be easily reused in the industrial control field. Traditional functional safety risk identification methods, such as Failure Mode and Effect Analysis (FMEA) and Hazard and Operability Study (HAZOP), cannot identify information security risks. While academia has made some improvements to these methods, proposing integrated risk identification methods such as Failure Mode, Vulnerabilities and Effects (FMEAV) and Security-Hazard and Operability Study (HAZOPs), these methods still fail to address the interaction between information security and functional safety risks.

[0004] System-Theoretic Accident Model and Processes (STAMP) is a novel accident causal model based on systems theory. Compared to the Swiss cheese model, a traditional risk identification technique, STAMP treats safety as a dynamic control problem rather than a fault prevention problem. Existing STAMP-based analysis methods are primarily System-Thertic Process Analysis (STPA) methods, which cannot intuitively demonstrate the risk identification results of industrial control systems. Summary of the Invention

[0005] The present invention provides a risk identification method and system for industrial control systems based on STAP, which is used to solve the problem that the existing STAP-based methods cannot intuitively display the risk identification results of industrial control systems.

[0006] This invention provides a risk identification method for an industrial control system based on STAMP, comprising:

[0007] The hazard scenario tree is generated based on the target parameters required to generate the hazard scenario tree of the industrial control system. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined based on the topology and control structure of the industrial control system.

[0008] Based on the aforementioned hazard scenario tree, the risks existing in the industrial control system are identified.

[0009] The present invention also provides a risk identification system for an industrial control system based on STAMP, comprising: a generation module and an identification module;

[0010] The generation module is used to generate the hazard scenario tree according to the target parameters required to generate the hazard scenario tree of the industrial control system. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined based on the topology and control structure of the industrial control system.

[0011] The identification module is used to identify the risks existing in the industrial control system based on the hazard scenario tree.

[0012] The present invention also provides an electronic device, including a processor and a memory storing a computer program, wherein the processor executes the program to implement the risk identification method of the STAMP-based industrial control system as described above.

[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the risk identification method for an industrial control system based on STAMP as described above.

[0014] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the risk identification method for an industrial control system based on STAMP as described above.

[0015] The present invention provides a risk identification method and system for industrial control systems based on STAMP. The hazard scenario tree generated based on the target parameters of the industrial control system includes the mapping relationship between hazardous control behaviors and hazards, the mapping results from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. This enables the generated hazard scenario tree to more intuitively display the risk identification results of the industrial control system, and can more effectively conduct in-depth safety analysis of the equipment in the industrial control system and formulate safety mitigation strategies. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0017] Figure 1 This is one of the flowcharts illustrating the risk identification method for an industrial control system based on STAMP provided by the present invention;

[0018] Figure 2 This is the second flowchart illustrating the risk identification method for an industrial control system based on STAMP provided by the present invention.

[0019] Figure 3 This is a control structure diagram for introducing system defects provided by the present invention;

[0020] Figure 4 This is a topology diagram of the gas pipeline network testing system provided by the present invention;

[0021] Figure 5 This is a control structure diagram of the gas pipeline network testing system provided by the present invention;

[0022] Figure 6 This is a schematic diagram of the mapping result from the control layer to the component layer of the gas pipeline network testing system provided by the present invention;

[0023] Figure 7 This is an example diagram of the hazard scenario tree of the gas pipeline network testing system provided by the present invention;

[0024] Figure 8 This is a schematic diagram of the risk identification system for an industrial control system based on STAMP provided by the present invention;

[0025] Figure 9 This is a schematic diagram of the physical structure of the electronic device provided by the present invention. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0027] To address the shortcomings and deficiencies of the current STPA method, this invention proposes a risk identification method for industrial control systems based on STPA.

[0028] The STPA method is a control-level abstraction analysis approach. This invention maps the control layer of an industrial control system to the component layer, overcoming the limitations of STPA's overly abstract nature. Since STPA does not consider the possibility of network attacks, this invention introduces component-level information security constraints on top of component-level functional safety constraints, simultaneously considering both functional safety and information security risk factors. The risk identification results of STPA are not intuitive enough; therefore, this invention ultimately presents the risk identification results based on a hazard scenario tree, enabling more effective in-depth security analysis of equipment corresponding to critical components and the development of security mitigation strategies based on the industrial control system. Furthermore, this invention simplifies the analysis process for analysts and provides a STPA-based risk identification tool for industrial control systems, addressing the STPA method's reliance on long-term work by expert teams. The specific implementation is as follows:

[0029] Figure 1 This is one of the flowcharts illustrating the risk identification method for an industrial control system based on STAMP provided by this invention, such as... Figure 1 As shown, the method includes:

[0030] Step 110: Generate the hazard scenario tree according to the target parameters required to generate the hazard scenario tree of the industrial control system. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined based on the topology and control structure of the industrial control system.

[0031] Step 120: Based on the hazardous scenario tree, identify the risks existing in the industrial control system.

[0032] It should be noted that the subject executing the above method can be a computer device or the risk identification tool (hereinafter referred to as the tool) of the STAMP-based industrial control system provided by this invention.

[0033] Optionally, the industrial control system may specifically include process control systems, discrete control systems, power systems, nuclear industry systems, etc.

[0034] The target parameters can specifically include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping relationship between losses and hazards, the mapping results from the control layer to the component layer, and the safety constraint data (including functional safety constraints and information security constraints) corresponding to hazardous control behaviors. The mapping results from the control layer to the component layer can be obtained specifically based on the topology and control structure of the industrial control system.

[0035] Figure 2 This is the second flowchart illustrating the risk identification method for an industrial control system based on STAMP provided by this invention. Figure 2 As shown, the process of obtaining the target parameter can specifically include: system model input, system hazard identification, hazard control behavior identification, control layer to component layer mapping, and integrated safety constraints, specifically:

[0036] The system model input includes the following steps: (1) importing asset data of the industrial control system; (2) drawing the topology of the industrial control system; (3) drawing the control logic structure of the industrial control system.

[0037] System hazard identification includes the following steps: (1) identifying the losses of the industrial control system; (2) identifying the hazards of the industrial control system; and (3) establishing a mapping relationship between the losses and hazards of the industrial control system.

[0038] Hazard control behavior identification includes the following steps: (1) identifying variables of the industrial control system; (2) identifying hazard control behaviors based on the variables of the industrial control system; and (3) establishing a mapping relationship between hazard control behaviors and hazards.

[0039] The mapping from the control layer to the component layer includes the following steps: (1) Automated mapping of the control structure of the industrial control system to the topology of the component layer to obtain the mapping structure from the control layer to the component layer;

[0040] Integrated security constraints include the following steps: (1) functional safety constraint labeling; (2) information security constraint labeling.

[0041] The system model input step primarily utilizes automatic and semi-automatic methods to ensure accurate input of the industrial control system model. Furthermore, in actual industrial control environments, the internal equipment and connections of the industrial control system frequently change, requiring the system model to be adjusted accordingly.

[0042] The specific process is as follows: Import the industrial control system assets via a JSON file. Analysts select the industry category of the industrial control system (process control system, discrete control system, power system, nuclear industry, etc.), and the tool provides the corresponding default topology and control structure template. Analysts then adjust the connection lines between the topologies according to the actual situation of the industrial control system being analyzed, generating the actual topology and control structure of the industrial control system.

[0043] (2) System hazard identification steps: Traditional risk identification methods are mostly bottom-up methods, focusing on how to better protect industrial control systems from information security threats / functional safety failures. However, the STAMP-based risk identification method for industrial control systems provided in this invention is a combined qualitative risk identification method, which is a top-down approach. It needs to clarify which basic functions and services of the industrial control system are not affected by interference and which losses are unacceptable.

[0044] Specific Process: Based on the selected industry for the industrial control system, the tool provides a corresponding loss template (used to record the mapping relationship between losses and hazards of the industrial control system). Analysts adjust this loss template according to the actual situation of the industrial control system to form a definition of the losses. Example of a loss for an industrial control system: personal injury or death. Subsequently, analysts need to input the hazards of the industrial control system based on the losses. This hazard refers to a state or condition at the industrial control system level that will lead to loss in the event of damage. The hazard must also describe the situation that needs to be prevented. <Hazard> = <System> & <Unsafe Condition> & <Caused Loss>. Example of a hazard: <Gas Pipeline System> & <Leakage and Explosion> & <Personal Injury, Equipment Damage, Gas Supply Interruption>. Then, based on the losses and hazards of the industrial control system, the tool automatically generates a mapping relationship between losses and hazards.

[0045] (3) Hazardous control behavior identification steps: This invention is based on the STAMP theory, and its core lies in identifying hazardous control behaviors in industrial control systems. Traditional risk identification techniques are based on the Swiss Cheese model, which identifies risks by recognizing all faults and threats present in the system. The Swiss Cheese model focuses too much on individual components of the industrial control system and cannot effectively identify new risks introduced by the interaction between functional safety and information security.

[0046] Specific process: Based on the controlled process and sensor identification in the control structure of the industrial control system, the variables of the industrial control system are formed, resulting in the variable V of the industrial control system. After determining the system variable V, the variable is introduced into the control structure diagram of the industrial control system, according to... Figure 3 The hazardous control behaviors shown are identified into five main categories (actuator failure to perform control, controller issuing incorrect control commands, timing / prompt errors in discrete control behaviors, duration of continuous control behaviors not meeting requirements, and external disturbances) to determine the hazardous control behaviors in industrial control systems. After identifying the hazardous control behaviors, a mapping is performed between the hazardous control behaviors and hazards to obtain the mapping results between the hazardous control behaviors and hazards.

[0047] (4) Mapping from the control layer to the component layer: For different industrial control systems, the topology of the component layer may vary greatly, while the basic negative feedback control logic of the control layer will not differ significantly. The control layer focuses more on functional interaction, control implementation, and algorithms; the component layer is based on the visualization of system implementation components, including control algorithms, sensor nodes, network nodes, physical network connections, and application layer protocols. By mapping the control structure diagram of the control layer to the component layer, the mapping result from the control layer to the component layer is obtained. This allows for the mapping of generalized hazardous control behaviors to specific individual devices, enabling component-level risk identification and facilitating subsequent functional safety and information security constraint mapping.

[0048] (5) Integrated safety constraint mapping steps: For the same hazardous control behavior at the component level, industrial control systems simultaneously have functional safety constraints and information security constraints. The traditional STPA method includes functional safety reliability constraints, but does not consider malicious active attack behavior. Therefore, this invention adds information security constraints based on the three elements of information security. For industrial control systems, information security constraints include: availability constraints and integrity constraints.

[0049] Integrity constraints (control loops): CS-I-1: Control injection; CS-I-2: Control deletion; CS-I-3: Control modification; CS-I-4: Control delay; CS-I-5: Measurement injection; CS-I-6: Measurement deletion; CS-I-7: Measurement modification; CS-I-8: Measurement delay;

[0050] Availability constraints (communication): CS-A-1: Communication delay; CS-A-2: Communication deletion; CS-A-3: Communication modification;

[0051] Specific process: Based on the mapping results from the control layer to the component layer of the industrial control system, for the device nodes (nodes representing devices) and communication nodes (nodes representing communication protocols) in the component layer nodes, mark the possible dangerous control behaviors. For device nodes, mark functional safety constraints based on STAMP, and mark integrity constraints / availability constraints; for communication nodes, mark availability constraints.

[0052] (6) Hazardous Scenario Tree Generation Step: This step uses the target parameters collected in the previous five steps to derive the hazardous scenarios faced by the industrial control system. Since there is a parent-child dependency relationship between hazardous scenarios and safety constraints, a tree structure is used to represent the hazards faced by the industrial control system and their corresponding safety constraints to avoid conflicts in safety constraints within sub-scenarios. A hazardous scenario is a textual representation of a specific situation during the operation of the industrial control system. In this case, defects in the industrial control system may lead to hazardous control behaviors, subsequently triggering the hazardous scenario and potentially ultimately resulting in the loss of the industrial control system. Each hazardous scenario is associated with a set of violated safety constraints that trigger defects in the industrial control system and cause it to take hazardous control behaviors.

[0053] This hazard scenario tree can be used to provide a basis for specifying safety mitigation measures for industrial control systems. For example, component-level safety constraints determine which components should undergo in-depth equipment safety analysis, and detected vulnerabilities can be considered violations of these constraints. If a set of safety mitigation measures can achieve hazard mitigation from the leaf node to the root node, it is considered an effective set of safety mitigation measures. Simultaneously, the hazard scenario tree can also provide integrated analysis and mitigation for functional safety and information security. For instance, if information security constraints cannot be met (e.g., equipment cannot be replaced), possible safety mitigation measures can be set based on functional safety constraints (e.g., enabling Safety Instrumented Systems (SIS) and setting the permissible operating range of parameters).

[0054] The specific process is as follows: The industrial control system takes the output of the first five steps as input data, which includes: the mapping relationship between dangerous control behaviors and hazards, the mapping results from the control layer to the component layer, and the safety constraint data corresponding to dangerous control behaviors. It generates a hazard scenario tree and automatically fills in the descriptive information (such as text information) based on the node information. Then, the analysts adjust the structure of the hazard scenario tree and modify the descriptive information according to the actual situation of the industrial control system.

[0055] Based on this hazard scenario tree, the risk identification results of the industrial control system are displayed intuitively.

[0056] The present invention provides a risk identification method for industrial control systems based on STAMP. The method generates a hazard scenario tree based on the target parameters of the industrial control system. The tree includes the mapping relationship between hazardous control behaviors and hazards, the mapping results from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. This allows the generated hazard scenario tree to more intuitively display the risk identification results of the industrial control system, and enables more effective in-depth safety analysis of the equipment in the industrial control system and the formulation of safety mitigation strategies.

[0057] Furthermore, in one embodiment, generating the hazard scenario tree based on the target parameters required for generating the hazard scenario tree of the industrial control system may specifically include:

[0058] The hazardous scenarios of the industrial control system are used as the root node of the hazardous scenario tree, and the hazardous scenarios are determined based on the hazardous control behaviors.

[0059] Based on the dangerous scenario corresponding to the root node, the dangerous control behavior corresponding to the dangerous scenario is taken as the first child node of the root node, and the description information of the first child node is determined.

[0060] If there is a sub-hazard control behavior corresponding to the first sub-node, the sub-hazard control behavior is taken as the second sub-node of the first sub-node, and the description information of the second sub-node is determined.

[0061] If the sub-hazard control behavior corresponding to the first sub-node does not exist, the component layer node that is extracted and associated with the first sub-node and meets the first preset condition will be used as the third sub-node of the first sub-node.

[0062] If the number of component layer nodes associated with the third child node is less than or equal to a preset value, determine the description information of the third child node;

[0063] If the number of component layer nodes associated with the third child node is greater than the preset value, the extracted component layer nodes associated with the third child node and satisfying the second preset condition are taken as the fourth child node of the third child node, and the description information of the fourth child node is determined.

[0064] The description information of the first child node includes hazards, hazard control behaviors, control layer nodes and component layer nodes associated with the first child node;

[0065] The description information of the second child node includes the hazards, hazard control behaviors, control layer nodes, and component layer nodes associated with the second child node;

[0066] The description information of the third child node includes the control layer node, component layer node, functional safety constraints, and information security constraints associated with the third child node;

[0067] The description information of the fourth child node includes the control layer node, component layer node, functional safety constraints, and information security constraints associated with the fourth child node;

[0068] The hazards associated with the first child node, the second child node, the third child node, and the fourth child node are all determined based on the mapping relationship between the hazard control behavior and the hazard. The hazard control behavior associated with the first child node, the second child node, the third child node, and the fourth child node is determined based on the hazard scenario. The control layer node and the component layer node associated with the first child node, the second child node, the third child node, and the fourth child node are determined based on the mapping result from the control layer to the component layer. The information security constraints associated with the third child node and the fourth child node are determined based on the security constraint data corresponding to the hazard control behavior.

[0069] The first preset condition includes a timing error in the application of variables or control algorithms contained in the component layer nodes associated with the first child node to the industrial control system, and the variable or control algorithm not being applied in a given state of the industrial control system.

[0070] The second preset condition includes that the communication protocol attributes contained in the component layer node associated with the third child node are tampering, deletion, and delay;

[0071] The security constraint data includes information security constraints and functional safety constraints.

[0072] Optionally, the hazardous scenario of the industrial control system is used as the root node of the hazardous scenario tree. This hazardous scenario can be specifically determined based on the hazardous control behavior, and the hazardous scenario tree is generated based on the following process:

[0073] 1. If the current node is the root node, iterate through the hazardous control behaviors of the industrial control system, generate the child nodes of the root node (that is, take each hazardous control behavior corresponding to the hazardous scenario as a child node, i.e., the first child node) and fill in its corresponding descriptive information such as text information. The text information of the first child node can specifically include the hazard, hazardous control behavior, control layer node and component layer node associated with it.

[0074] 2. If the current node is the first child node, and the hazard control behavior corresponding to the first child node has a sub-hazard control behavior, then iterate through the sub-hazard control behaviors, generate the child node of the current node (i.e. the second child node), and fill in its corresponding descriptive information such as text information. The text information of the second child node can specifically include the hazard, hazard control behavior, control layer node and component layer node associated with it.

[0075] 3. If the current node is the first child node, and the hazard control behavior corresponding to the first child node has no sub-hazard control behavior, then extract the component layer node associated with the current node that meets the first preset condition as the child node of the current node (i.e., the third child node or safety constraint child node), and determine the description information of the third child node, such as text information. The text information of the safety constraint child node may specifically include the control layer node and component layer node associated with it. The first preset condition may specifically include the timing error of the application of variables or control algorithms contained in the component layer node associated with the first child node to the industrial control system (e.g., applied too early or applied too late), and the failure to apply variables or control algorithms in a given state of the industrial control system.

[0076] 4. If the current node is a safety constraint child node (i.e., the third child node), and the number of nodes in the component layer nodes associated with the current node is less than or equal to the first preset value (e.g., 5), then fill in the description information corresponding to the current node, such as safety constraint text information (including functional safety constraints and information security constraints).

[0077] 5. If the current node is a security constraint child node (i.e., the third child node), and the number of nodes in the component layer nodes associated with the current node is greater than the first preset value (e.g., 5), then the extracted component layer nodes associated with the current node that satisfy the second preset condition are taken as child nodes of the current node (i.e., the fourth child node), and the description information of the fourth child node, such as text information, is determined. The text information of the fourth child node may specifically include the control layer node, component layer node, functional safety constraint, and information security constraint associated with it. The second preset condition may specifically include the attributes of the communication protocols (including physical network connections and application layer protocols) contained in the component layer nodes associated with the third child node being tampered with, deleted, and delayed. Extract the component layer nodes associated with the current node. For the physical network connections and application layer protocols contained therein, generate corresponding child nodes (i.e., the fourth child node, also called security constraint child nodes) based on their attributes of tampering, deletion, and delay.

[0078] Optionally, the hazards associated with the first, second, third, and fourth child nodes can be obtained specifically based on the mapping relationship between hazard control behaviors and hazards; the hazard control behaviors associated with the first, second, third, and fourth child nodes can be obtained specifically based on hazard scenarios; the control layer nodes and component layer nodes associated with the first, second, third, and fourth child nodes can be obtained specifically based on the mapping results from the control layer to the component layer; and the information security constraints associated with the third and fourth child nodes can be obtained specifically based on the security constraint data corresponding to the hazard control behaviors.

[0079] The STAMP-based risk identification method for industrial control systems provided by this invention overcomes the limitations of the overly abstract STPA method by mapping the control layer of the industrial control system to the component layer. It addresses the problems of STPA's heavy reliance on expert experience, requiring analysts (for large industrial control systems, STPA risk assessment relies on a team of experts) to have in-depth understanding of the functional safety and information security of the industrial control system or undergo systematic learning and training before it can be used. This also results in a complex assessment process, taking weeks to complete manually, and poor scalability. Furthermore, since the STPA method does not consider the possibility of cyberattacks on the industrial control system, this invention introduces component-level information security constraints on top of the component-level functional safety constraints of the industrial control system by adding functional safety and information security constraints to the generated hazard scenario tree. By considering both functional safety and information security risk factors, it can more effectively protect the system's vulnerabilities.

[0080] Furthermore, in one embodiment, the method for obtaining the mapping relationship between the hazardous control behavior and the hazard of the industrial control system may specifically include:

[0081] Based on the sensor type of the industrial control system, identify the variables of the controlled process in the control structure of the industrial control system, including temperature, pressure, and flow rate;

[0082] Introduce the variable into the control structure;

[0083] Determine the control algorithm of the industrial control system and the dangerous control behaviors and hazards corresponding to the disturbances of the variables;

[0084] By mapping the aforementioned hazard control behaviors to the hazards, a mapping relationship between the hazard control behaviors and the hazards can be obtained.

[0085] Optionally, based on the sensor type of the industrial control system, the key physical parameters of the controlled process in the control structure of the industrial control system are identified: temperature T, pressure P, and flow rate F, to obtain the key parameter sequence V = {T, P, F}, and these parameters are introduced into the control structure as variables.

[0086] Based on the control algorithm and the disturbance of variables, dangerous control behaviors of industrial control systems are identified in five categories, and mapped to the hazards of industrial control systems corresponding to the disturbances of control algorithms and variables, thus obtaining the mapping relationship between dangerous control behaviors and hazards.

[0087] Furthermore, in one embodiment, the method for obtaining the mapping result from the control layer to the component layer includes:

[0088] Based on the topology of the industrial control system, determine the topology of the component layer in the industrial control system;

[0089] Based on the topology of the component layer, a first set of the industrial control system is determined. The first set includes a first subset consisting of all assets in the component layer and a second subset of the connection relationships between the assets. The assets include at least the device types and communication protocols of the devices in the topology of the component layer.

[0090] Based on the control structure of the industrial control system, a second set of the industrial control system is determined. The second set includes a third subset and a fourth subset. The third subset is determined based on all elements in the control structure, and the elements include at least the device types in the control structure. The fourth subset is a set of directed edges between elements.

[0091] Based on the first set, logical mapping is performed on the host computer type devices in the control structure to obtain the first mapping result;

[0092] Based on the second set, the parameters of the control loop in the control structure are mapped to obtain a second mapping result;

[0093] Based on the first mapping result and the second mapping result, the mapping result from the control layer to the component layer is obtained.

[0094] Optionally, in the system model input stage, the analyst has already implemented the input of the industrial control system assets, the drawing of the industrial control system topology, and the drawing of the industrial control system control structure, and has achieved data persistence.

[0095] Based on the topology of the industrial control system, the topology of the component layer in the industrial control system is obtained, and based on the topology of the component layer, the first set G of the industrial control system is obtained. cpt The first set Gcpt Specifically, it can include the first subset C consisting of all assets in the component layer. A The second subset E of the connection relationships between the asset A and the component layer topology includes the device type, device name, device MAC address, device IP address, device ID, and device communication protocol.

[0096] Wherein, asset A = {id, ip, mac, name, type, protocol}, and the device types in the component layer can specifically include: information security protection devices, enterprise information layer devices, field device layer devices, control layer devices, and physical layer devices.

[0097] Among them, G cpt ={C A ,E}, where C A E represents the first subset consisting of all assets in the component layer, and E represents the set of undirected edges connecting the assets, i.e., the second subset.

[0098] Based on the control structure of this industrial control system, the second set G of the industrial control system is obtained. ctrl The second set may specifically include the third subset C. ctrl and the fourth subset E ctrl .

[0099] Among them, G ctrl ={C ctrl E ctrl}, where C ctrl ={id,type} represents all elements (i.e., devices) in the control structure, specifically including the device type and device ID. The device type in the control structure can specifically include: controller, actuator (e.g., valve), sensor, host computer, control algorithm, and variables (setpoint, measured value, actual value). ctrl A set of directed edges that connect elements.

[0100] According to the first set G cpt ={C A ,E}, perform logical mapping on the host computer type devices in the control structure to obtain the logical mapping result of the host computer type devices, i.e. the first mapping result.

[0101] According to the second set G ctrl ={C ctrl E ctrl The parameters of the control loop in the control structure are mapped to obtain the parameter mapping result of the control loop, i.e., the second mapping result;

[0102] Based on the first and second mapping results, the mapping result from the control layer to the component layer is obtained.

[0103] Furthermore, in one embodiment, the step of logically mapping the host computer type devices in the control structure according to the first set to obtain a first mapping result may specifically include:

[0104] Iterate through the first subset of the first set;

[0105] If the first subset is determined to be a non-empty set, then based on the device type in the first subset, obtain all enterprise information layer devices and field device layer devices in the first subset;

[0106] Based on all the enterprise information layer devices and field device layer devices, a third set is determined;

[0107] Traverse the third set, and if the target element in the third set is the enterprise information layer device, perform a depth-first search on the third set;

[0108] If the next first device connected to the enterprise information layer device corresponding to the target element is a non-information security protection device, then a target control algorithm is inserted between the enterprise information layer device corresponding to the target element and the first device; otherwise, a first communication protocol is inserted between the enterprise information layer device corresponding to the target element and the next device to obtain a first sub-mapping result. The target control algorithm is determined according to the second set, and the first communication protocol is determined according to the first set.

[0109] If the target element in the set is the field device layer device, a depth-first search is performed on the third set;

[0110] If the next second device connected to the field device layer device corresponding to the target element is a non-information security protection device, then a variable setting value is inserted between the field device layer device corresponding to the target element and the second device; otherwise, a second communication protocol is inserted between the field device layer device corresponding to the target element and the second device to obtain a second sub-mapping result. The variable setting value is determined according to the second set, and the second communication protocol is determined according to the first set.

[0111] The first mapping result is determined based on the first sub-mapping result and the second sub-mapping result.

[0112] Optionally, traverse the first set G. cpt The first subset C in A If the first subset C is determined AIf the set is empty, then the logical mapping of the host computer type device ends. If the first subset C is determined... A If the set is non-empty, then traverse the first subset C. A Elements with a mid-vertex degree of 1 form a third set C. Initial The element with a vertex degree of 1 corresponds to all enterprise information layer devices and field device layer devices in the first subset.

[0113] Traversing the third set C Initial For C Initial If the device type corresponding to the target element is an enterprise information layer device, a depth-first search is performed on the target element. If the next-hop device (i.e., the next first device) connected to the enterprise information layer device corresponding to the target element is a non-information security protection device, then a target control algorithm is inserted between the enterprise information layer device and the next first device. This target control algorithm can be specifically based on the second set C. ctrl Get; otherwise, insert communication protocol C between the enterprise information layer device and the next first device based on the asset's protocol attribute. protocol Depth-first search ends with the control layer device as the device type.

[0114] For C Initial If the target element corresponds to a field device layer device, a depth-first search is performed on the target element. If the next-hop device (i.e., the next second device) connected to the field device layer device corresponding to the target element is a non-information security protection device, then a variable setting value is inserted between the enterprise information layer device and the next second device. The setting value of this variable can be specifically based on the second set C. ctrl Get; otherwise, insert a communication protocol C between the field device layer device and the next second device based on the asset's protocol attribute. protocol Depth-first search ends with the control layer device as the device type.

[0115] After completing the third set C Initial After searching for all elements, the logical mapping of the host computer type device ends, and the logical influence of the host computer type device is obtained, which is the first mapping result.

[0116] Furthermore, in one embodiment, mapping the parameters of the control loop in the control structure according to the second set to obtain a second mapping result may specifically include:

[0117] If the fourth subset is a non-empty set, traverse the fourth subset in the second set;

[0118] For the first directed edge in all directed edges of the fourth subset, whose starting point is the controller and whose ending point is the actuator, insert the set value of the variable between the starting point and the ending point of the first directed edge.

[0119] For the second directed edge in all directed edges of the fourth subset, whose starting point is the actuator and whose ending point is the sensor, insert the true value of the variable between the starting point and the ending point of the second directed edge.

[0120] For the third directed edge in all directed edges of the fourth subset, whose starting point is the sensor and whose ending point is the controller, the measured value of the variable is inserted between the starting point and the ending point of the third directed edge.

[0121] The set value, the actual value, and the measured value of the variable are all determined based on the second set.

[0122] Optionally, traverse the second set G. ctrl The fourth subset E in ctrl If the fourth subset E is determined ctrl If the set is empty, then the control loop parameter mapping ends. If the fourth subset E is determined... ctrl If the set is non-empty, then traverse the fourth subset E. ctrl For the fourth subset E ctrl The first directed edge (i.e., the first directed edge) is where the starting point is the controller and the ending point is the actuator. The setpoints of the industrial control system's variables are inserted at the starting and ending points of this first directed edge. For the fourth subset E... ctrl For all directed edges, the starting point is the actuator and the ending point is the sensor (i.e., the second directed edge). The true values ​​of the corresponding variables are inserted between the starting and ending points of this second directed edge. For the fourth subset E... ctrl All directed edges have a starting point at the sensor and an ending point at the controller (i.e., the third directed edge). The measured values ​​of the corresponding variables are inserted between the starting point and the ending point of the third directed edge. The set value, the actual value, and the measured value of the variables can all be obtained from the second set.

[0123] For example, the risk identification method for industrial control systems based on STAMP provided by this invention can be used to identify risks in gas pipeline testing systems.

[0124] Specifically, the system model input steps involve importing the assets of the gas pipeline network testing system via a JSON file. Based on the asset list and corresponding equipment types, the topology and control structure drawing interfaces for the gas pipeline network testing system are generated. The gas pipeline network testing system provides default network topology templates corresponding to basic industries. Analysts can drag and adjust the asset connection methods of the gas pipeline network testing system according to the actual industrial control system production environment to draw the topology structure of the gas pipeline network testing system, such as... Figure 4 As shown; based on the actual logic control loop and referring to the template provided by the tool, connect and draw the control structure of the gas pipeline network test system, as follows. Figure 5 As shown.

[0125] The system hazard identification process begins by selecting the corresponding system loss template based on the industry classification of industrial control systems (process control systems, discrete control systems, power systems, nuclear industry, etc.), and then modifying it according to the actual system conditions. The gas pipeline network testing system is a process control industry system, and the corresponding modified system losses are: (L-1) personnel injury, (L-2) equipment damage, (L-3) environmental pollution, (L-4) gas supply interruption, and (L-5) information leakage. Subsequently, based on the system losses, the following system hazards are input: (H-1) system gas leak, (H-2) system fire, (H-2.1) jet fire, (H-2.2) fireball, (H-3) system vapor cloud explosion, (H-4) system false alarm, and (H-5) system unauthorized access. The mapping relationship between losses and hazards is automatically generated as shown in Table 1.

[0126] Table 1

[0127] L1 L2 L3 L4 L5 H1 √ √ H2.1 √ √ √ H2.2 √ √ √ H3 √ √ √ H4 √ H5 √

[0128] The hazardous control behavior identification process begins by identifying the key physical parameters of the controlled process based on the system's sensor types: temperature (T), pressure (P), and flow rate (F), obtaining the key parameter sequence V = {T, P, F}. This sequence is then used as a variable and introduced into the control structure. Next, based on the control algorithm and variable disturbances, hazardous control behaviors are identified into four categories and mapped to hazards. The mapping relationship between hazardous control behaviors and hazards is shown in Table 2, where HC-1 represents the actuator not performing control, HC-2 represents the controller issuing incorrect control commands, HC-3 represents timing errors in discrete control behavior, and HC-4 represents disturbances.

[0129] Table 2

[0130]

[0131]

[0132] The control layer to component layer mapping step involves inputting the assets and topology of the gas pipeline network testing system, and then using an automated mapping algorithm to perform the mapping from the control layer to the component layer. The mapping result is as follows: Figure 6 As shown.

[0133] The integrated safety constraint labeling process is based on the mapping results from the control layer to the component layer of the gas pipeline network testing system. Some labeling results are shown in Table 3, where CS-I and CS-A are information security constraints, CR is a functional safety constraint (reliability), and CC is a functional safety constraint (control constraint).

[0134] Table 3

[0135]

[0136] The hazard scenario tree generation process involves combining data obtained from previous steps to generate a hazard scenario tree. A partial hazard scenario tree for a gas pipeline network testing system is shown below. Figure 7 As shown.

[0137] The text information for each node in the hazardous scenario tree is as follows:

[0138] S-1: The actuator is not performing control;

[0139] Hazards: H1, H2.1, H2.2, H3;

[0140] Hazard control behavior: HC-1;

[0141] Control layer nodes: PLC1, PLC2, actuators;

[0142] Component layer nodes: PLC1, PLC2, valve, C-9, C-10;

[0143] S-1-1: The control commands received by the valve have been altered, delayed, or deleted;

[0144] Control layer nodes: PLC1, actuator;

[0145] Component layer nodes: PLC1, valve, C-9;

[0146] Functional safety constraints: CR (C-9, PLC1), CC-1 (valve should take action), CC-2 (valve should take action);

[0147] Information security constraints: CS-A-1, CS-A-2, CS-A-3;

[0148] S-1-2: The valve received the correct control command but did not operate;

[0149] Control layer node: host computer;

[0150] Component layer node: Server;

[0151] Functional safety constraints: CR (valve), CC-1 (valve should take action), CC-2 (valve should take action);

[0152] Information security constraint: none;

[0153] S-2: The controller issued an incorrect control command;

[0154] Hazards: H1, H2.1, H2.2, H3, H5;

[0155] Hazard control behavior: HC-2;

[0156] Control layer nodes: PLC1, PLC2, host computer, sensors;

[0157] Component layer nodes: PLC1, PLC2, Sensors, C-11, C-9, C-8, C-7, C-6, C-5, C-4, C-3, C-2, C-1, Gateway, Switch, HMI, Server, IDS, Firewall, Operator Station, Engineer Station;

[0158] S-2-1: Error control algorithm caused by the host computer;

[0159] Hazards: H1, H2.1, H2.2, H3, H5;

[0160] Hazard control behavior: HC-2.1;

[0161] Control layer nodes: PLC1, PLC2, host computer, sensors;

[0162] Component layer nodes: PLC1, PLC2, Sensors, C-11, C-9, C-8, C-7, C-6, C-5, C-4, C-3, C-2, C-1, Gateway, Switch, HMI, Server, IDS, Firewall, Operator Station, Engineer Station;

[0163] S-2-1-1; PLC1 received the error V setting value from HMI;

[0164] Control layer nodes: host computer, PLC1;

[0165] Component layer nodes: PLC1, Gateway, Switch, HMI, C-4, C-6, C-7

[0166] S-2-1-1-1; The HMI sent an incorrect V setting value;

[0167] Control layer node: host computer;

[0168] Component layer node: HMI;

[0169] Functional safety constraints: CR (HMI), CC-7 (HMI settings);

[0170] Information security constraints: CS-I-1, CS-I-2, CS-I-3;

[0171] S-2-1-1-2; The HMI sent the correct V setting value, but it was tampered with, deleted, or delayed during transmission;

[0172] Control layer node: host computer;

[0173] Component layer nodes: Gateway, Switch, C-4, C-6, C-7;

[0174] Functional safety constraints: CR (gateway, switch);

[0175] Information security constraints: CS-A-1, CS-A-2, CS-A-3;

[0176] S-2-1-1-3; The HMI sent the correct V setting value, but the PLC tampered with it after receiving it.

[0177] Control layer node: PLC1;

[0178] Component layer node: PLC1;

[0179] Functional safety constraint: CR(PLC1);

[0180] Information security constraints: CS-I-1, CS-I-2, CS-I-3, CS-I-4.

[0181] The risk identification method for industrial control systems based on STAMP provided by this invention realizes the automated mapping process from the control layer to the component layer of the industrial control system according to the automated mapping algorithm. It overcomes the limitation of the ATPA method being too abstract and can effectively conduct in-depth security analysis of the industrial control system from the component layer, which facilitates the formulation of security mitigation strategies.

[0182] The risk identification system for an industrial control system based on STAMP provided by this invention will be described below. The risk identification system for an industrial control system based on STAMP described below can be referred to in correspondence with the risk identification method for an industrial control system based on STAMP described above.

[0183] Figure 8 This is a schematic diagram of the risk identification system for an industrial control system based on STAMP provided by the present invention, as shown below. Figure 8 As shown, it includes:

[0184] Generation module 810 and recognition module 811;

[0185] The generation module 810 is used to generate the hazard scenario tree according to the target parameters required to generate the hazard scenario tree of the industrial control system. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined according to the topology and control structure of the industrial control system.

[0186] The identification module 811 is used to identify the risks existing in the industrial control system based on the hazard scenario tree.

[0187] The present invention provides a risk identification system for industrial control systems based on STAMP. The system generates a hazard scenario tree based on the target parameters of the industrial control system. This tree includes the mapping relationship between hazardous control behaviors and hazards, the mapping results from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. This allows the generated hazard scenario tree to more intuitively display the risk identification results of the industrial control system, and enables more effective in-depth safety analysis of the equipment in the industrial control system and the formulation of safety mitigation strategies.

[0188] Figure 9 This is a schematic diagram of the physical structure of an electronic device provided by the present invention, such as... Figure 9 As shown, the electronic device may include a processor 910, a communication interface 911, a memory 912, and a bus 913. The processor 910, communication interface 911, and memory 912 communicate with each other via the bus 913. The processor 910 can call logical instructions from the memory 912 to execute the following methods:

[0189] The hazard scenario tree is generated based on the target parameters required to generate the hazard scenario tree of the industrial control system. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined based on the topology and control structure of the industrial control system.

[0190] Based on the aforementioned hazard scenario tree, the risks existing in the industrial control system are identified.

[0191] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and sold or used as independent products, and can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer power supply (which may be a personal computer, server, or network power supply, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0192] Furthermore, this invention discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when these instructions are executed by a computer, the computer can execute the risk identification method for an industrial control system based on STAMP provided in the above-described method embodiments, for example including:

[0193] The hazard scenario tree is generated based on the target parameters required to generate the hazard scenario tree of the industrial control system. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined based on the topology and control structure of the industrial control system.

[0194] Based on the aforementioned hazard scenario tree, the risks existing in the industrial control system are identified.

[0195] On the other hand, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the risk identification method for the STAMP-based industrial control system provided in the above embodiments, including, for example:

[0196] The hazard scenario tree is generated based on the target parameters required to generate the hazard scenario tree of the industrial control system. The target parameters include the topology and control structure of the industrial control system, the mapping relationship between hazardous control behaviors and hazards, the mapping result from the control layer to the component layer, and the safety constraint data corresponding to the hazardous control behaviors. The mapping result from the control layer to the component layer is determined based on the topology and control structure of the industrial control system.

[0197] Based on the aforementioned hazard scenario tree, the risks existing in the industrial control system are identified.

[0198] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0199] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer power supply (which may be a personal computer, server, or network power supply, etc.) to execute the methods described in various embodiments or some parts of the embodiments.

[0200] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for risk identification of an STAMP-based industrial control system, characterized in that, The method comprises the following steps: generating a dangerous scenario tree of an industrial control system according to target parameters required for generating the dangerous scenario tree, the target parameters comprising a topology structure, a control structure, a mapping relationship between dangerous control behaviors and hazards, a mapping result of a control layer to a component layer, and safety constraint data corresponding to the dangerous control behaviors of the industrial control system, the mapping result of the control layer to the component layer being determined according to the topology structure and the control structure of the industrial control system; identifying risks existing in the industrial control system based on the dangerous scenario tree; the method of generating the dangerous scenario tree of the industrial control system according to the target parameters required for generating the dangerous scenario tree comprises the following steps: taking a dangerous scenario of the industrial control system as a root node of the dangerous scenario tree, the dangerous scenario being determined according to the dangerous control behaviors; taking the dangerous control behaviors corresponding to the dangerous scenario of the root node as first child nodes of the root node, and determining description information of the first child nodes according to the dangerous scenario corresponding to the root node; in a case where the dangerous control behaviors corresponding to the first child nodes have sub-dangerous control behaviors, taking the sub-dangerous control behaviors as second child nodes of the first child nodes, and determining description information of the second child nodes; in a case where the dangerous control behaviors corresponding to the first child nodes do not have the sub-dangerous control behaviors, taking component layer nodes associated with the first child nodes and satisfying a first preset condition as third child nodes of the first child nodes; in a case where a number of the component layer nodes associated with the third child nodes is less than or equal to a preset value, determining description information of the third child nodes; in a case where the number of the component layer nodes associated with the third child nodes is greater than the preset value, taking component layer nodes associated with the third child nodes and satisfying a second preset condition as fourth child nodes of the third child nodes, and determining description information of the fourth child nodes; wherein the description information of the first child nodes comprises hazards, dangerous control behaviors, control layer nodes, and component layer nodes associated with the first child nodes; the description information of the second child nodes comprises hazards, dangerous control behaviors, control layer nodes, and component layer nodes associated with the second child nodes; the description information of the third child nodes comprises control layer nodes, component layer nodes, functional safety constraints, and information safety constraints associated with the third child nodes; the description information of the fourth child nodes comprises control layer nodes, component layer nodes, functional safety constraints, and information safety constraints associated with the fourth child nodes. The hazards associated with the first sub-node, the second sub-node, the third sub-node and the fourth sub-node are determined according to the mapping relationship between the dangerous control behaviors and the hazards, the dangerous control behaviors associated with the first sub-node, the second sub-node, the third sub-node and the fourth sub-node are determined according to the dangerous scene, the control layer nodes and the component layer nodes associated with the first sub-node, the second sub-node, the third sub-node and the fourth sub-node are determined according to the mapping result of the control layer to the component layer, and the information security constraints associated with the third sub-node and the fourth sub-node are determined according to the security constraint data corresponding to the dangerous control behaviors; The first preset condition includes a time error of a variable or a control algorithm contained in a component layer node associated with the first sub-node applied to the industrial control system, and the variable or the control algorithm is not applied in a given state of the industrial control system; The second preset condition includes that an attribute of a communication protocol contained in a component layer node associated with the third sub-node is tampering, deletion and delay; The security constraint data includes information security constraints and functional safety constraints.

2. The method of claim 1, wherein the STAMP-based industrial control system risk identification method is characterized by, The acquisition method of the mapping relationship between the dangerous control behaviors and the hazards of the industrial control system includes: According to the sensor type device of the industrial control system, a variable of a controlled process in the control structure of the industrial control system is identified, and the variable includes temperature, pressure and flow; The variable is introduced into the control structure; The dangerous control behaviors and hazards corresponding to the control algorithm of the industrial control system and the disturbance of the variable are determined; The dangerous control behaviors and hazards are corresponded to obtain the mapping relationship between the dangerous control behaviors and the hazards.

3. The method of claim 1, wherein the STAMP-based industrial control system risk identification method is characterized by, The acquisition method of the mapping result of the control layer to the component layer includes: According to the topology structure of the industrial control system, the topology structure of the component layer in the industrial control system is determined; According to the topology structure of the component layer, a first set of the industrial control system is determined, the first set includes a first sub-set composed of all assets in the component layer and a second sub-set of connection relationships between assets, and the assets at least include a device type in the topology structure of the component layer and a communication protocol of the device; According to the control structure of the industrial control system, a second set of the industrial control system is determined, the second set includes a third sub-set and a fourth sub-set, the third sub-set is determined according to all elements in the control structure, and the elements at least include a device type in the control structure, and the fourth sub-set is a directed edge set between elements; According to the first set, a host computer type device in the control structure is logically mapped to obtain a first mapping result; According to the second set, parameters of a control loop in the control structure are mapped to obtain a second mapping result; According to the first mapping result and the second mapping result, the mapping result of the control layer to the component layer is obtained.

4. The method of claim 3, wherein the STAMP-based industrial control system risk identification method is characterized by, The logical mapping of the host computer type device in the control structure according to the first set obtains a first mapping result, comprising: Traverse the first subset in the first set; In the case of determining that the first subset is a non-empty set, according to the device type in the first subset, all enterprise information layer devices and field device layer devices in the first subset are obtained; According to the all enterprise information layer devices and field device layer devices, a third set is determined; Traverse the third set, and in the case that the target element in the third set is the enterprise information layer device, perform a depth-first search on the third set; If the next first device connected to the enterprise information layer device corresponding to the target element is a non-information security protection device, a target control algorithm is inserted between the enterprise information layer device corresponding to the target element and the next first device, otherwise a first communication protocol is inserted between the enterprise information layer device corresponding to the target element and the next first device, to obtain a first sub-mapping result, the target control algorithm is determined according to the second set, and the first communication protocol is determined according to the first set; In the case that the target element in the set is the field device layer device, perform a depth-first search on the third set; If the next second device connected to the field device layer device corresponding to the target element is a non-information security protection device, a set value of a variable is inserted between the field device layer device corresponding to the target element and the next second device, otherwise, a second communication protocol is inserted between the field device layer device corresponding to the target element and the next second device, to obtain a second sub-mapping result, the set value of the variable is determined according to the second set, and the second communication protocol is determined according to the first set; According to the first sub-mapping result and the second sub-mapping result, the first mapping result is determined.

5. The method of claim 3, wherein the STAMP-based industrial control system risk identification method is characterized by, The mapping of the parameters of the control loop in the control structure according to the second set obtains a second mapping result, comprising: In the case that the fourth subset is a non-empty set, traverse the fourth subset in the second set; For all first directed edges in the fourth subset, the starting point of which is a controller and the ending point of which is an actuator, a set value of a variable is inserted between the starting point and the ending point of the first directed edge; For all second directed edges in the fourth subset, the starting point of which is an actuator and the ending point of which is a sensor, a real value of a variable is inserted between the starting point and the ending point of the second directed edge; For all third directed edges in the fourth subset, the starting point of which is a sensor and the ending point of which is a controller, a measured value of a variable is inserted between the starting point and the ending point of the third directed edge; Wherein, the set value of the variable, the real value of the variable and the measured value of the variable are all determined according to the second set.

6. A risk identification system for STAMP-based industrial control systems, characterized in that, Comprising: A generation module and an identification module; The generation module is configured to generate the dangerous scenario tree according to target parameters required for generating the dangerous scenario tree of the industrial control system, the target parameters including a topology structure, a control structure, a mapping relationship between dangerous control behaviors and hazards, a mapping result of a control layer to a component layer, and safety constraint data corresponding to the dangerous control behaviors of the industrial control system, and the mapping result of the control layer to the component layer being determined according to the topology structure and the control structure of the industrial control system; The identification module is configured to identify risks existing in the industrial control system based on the dangerous scenario tree; The generation of the dangerous scenario tree according to the target parameters required for generating the dangerous scenario tree of the industrial control system includes: taking a dangerous scenario of the industrial control system as a root node of the dangerous scenario tree, the dangerous scenario being determined according to the dangerous control behaviors; taking the dangerous control behaviors corresponding to the dangerous scenario of the root node as first child nodes of the root node and determining description information of the first child nodes according to the dangerous scenario corresponding to the root node; in a case where the dangerous control behaviors corresponding to the first child nodes have sub-dangerous control behaviors, taking the sub-dangerous control behaviors as second child nodes of the first child nodes and determining description information of the second child nodes; in a case where the dangerous control behaviors corresponding to the first child nodes do not have the sub-dangerous control behaviors, taking component layer nodes associated with the first child nodes and satisfying a first preset condition as third child nodes of the first child nodes; in a case where a number of the component layer nodes associated with the third child nodes is less than or equal to a preset value, determining description information of the third child nodes; in a case where the number of the component layer nodes associated with the third child nodes is greater than the preset value, taking component layer nodes associated with the third child nodes and satisfying a second preset condition as fourth child nodes of the third child nodes and determining description information of the fourth child nodes; wherein the description information of the first child nodes includes hazards, dangerous control behaviors, control layer nodes, and component layer nodes associated with the first child nodes; the description information of the second child nodes includes hazards, dangerous control behaviors, control layer nodes, and component layer nodes associated with the second child nodes; the description information of the third child nodes includes control layer nodes, component layer nodes, functional safety constraints, and information safety constraints associated with the third child nodes; the description information of the fourth child nodes includes control layer nodes, component layer nodes, functional safety constraints, and information safety constraints associated with the fourth child nodes; The hazards associated with the first sub-node, the second sub-node, the third sub-node and the fourth sub-node are determined according to the mapping relationship between the hazard control behavior and the hazard, the hazard control behaviors associated with the first sub-node, the second sub-node, the third sub-node and the fourth sub-node are determined according to the dangerous scene, the control layer nodes and the component layer nodes associated with the first sub-node, the second sub-node, the third sub-node and the fourth sub-node are determined according to the mapping result from the control layer to the component layer, and the information security constraints associated with the third sub-node and the fourth sub-node are determined according to the security constraint data corresponding to the hazard control behavior; The first preset condition includes a time error of a variable or a control algorithm contained in a component layer node associated with the first sub-node applied to the industrial control system, and the variable or the control algorithm is not applied in a given state of the industrial control system; The second preset condition includes that an attribute of a communication protocol contained in a component layer node associated with the third sub-node is tampering, deletion and delay; The security constraint data includes information security constraints and functional safety constraints.

7. An electronic device comprising a processor and a memory having a computer program stored therein, characterized in that The processor executes the computer program to implement the risk identification method of the STAMP-based industrial control system according to any one of claims 1 to 5.

8. A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the risk identification method of the STAMP-based industrial control system according to any one of claims 1 to 5.

9. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the risk identification method of the STAMP-based industrial control system according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method and system for carrying out safety analysis on reclaimed water reuse system

    CN112987631A

  • Rail transit train control system danger analysis method and equipment based on communication

    CN115729210A