Integrated Risk Assessment Methods and Systems for Industrial Control Systems
By employing an integrated risk assessment method that utilizes Bayesian networks and hidden Markov models to generate indicators, the cost waste caused by separate assessments of industrial control systems is resolved, providing optimal protection strategies and ensuring system security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-15
- Publication Date
- 2026-04-03
AI Technical Summary
In existing technologies, functional safety and information security assessments of industrial control systems are usually conducted separately, resulting in a waste of human and material resources and a lack of integrated assessment tools, making it difficult to effectively integrate risk data.
An integrated risk assessment approach is adopted, which generates information security indicators by determining the objective function, mapping fault trees to Bayesian networks, combining hidden Markov models and Monte Carlo methods, and providing the best protection strategy based on the Pareto optimal solution set.
It enables simultaneous assessment of the functional safety and information security of industrial control systems, saving manpower and material costs, providing optimal protection strategies, and ensuring the safe operation of the system.
Smart Images

Figure CN116880375B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial control technology, and in particular to an integrated risk assessment method and system for industrial control systems. Background Technology
[0002] Industrial Control Systems (ICS) are computer systems and networks used to monitor and control production and industrial processes. ICS are a crucial component of national critical infrastructure, widely applied in energy, transportation, communications, water conservancy, environmental protection, military, and many other fields. They play a vital role in a nation's economy, security, and development, and ensuring the stable operation of ICS is of irreplaceable importance to national development and security.
[0003] Functional safety and information security are both crucial for industrial control systems (ICS), as system failures or attacks can lead to serious consequences such as production interruptions, equipment damage, or workplace accidents. By conducting integrated risk assessments of functional safety and information security, potential security vulnerabilities and risks can be identified, allowing for timely remediation and reinforcement measures. This ensures ICS security, improves ICS robustness and reliability, reduces ICS operating costs, and enhances the company's competitiveness in the market.
[0004] Currently, integrated risk assessment of functional safety and information security in industrial control systems (ICS) faces several challenges: ICS typically consists of multiple components, different network protocols, and varying hardware and software, complicating risk assessment and making it difficult to identify the necessary risk data. Functional safety and information security assessments are usually conducted separately, lacking integrated assessment tools, requiring assessors to perform tedious data integration and comparison work. Furthermore, functional safety and information security assessments for industrial control systems require different tools, often from different vendors and potentially incompatible, necessitating significant time and effort from assessors to integrate and utilize these tools. Summary of the Invention
[0005] The integrated risk assessment method and system for industrial control systems provided by this invention are used to solve the problem that the functional safety and information security of industrial control systems need to be assessed separately in the prior art, resulting in a waste of human and material resources.
[0006] This invention provides an integrated risk assessment method for industrial control systems, comprising:
[0007] The target function is determined based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system.
[0008] Based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function, the constraints of the objective function are determined. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system.
[0009] The optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set of the space curve corresponding to the objective function.
[0010] According to an integrated risk assessment method for industrial control systems provided by the present invention, the method for obtaining the functional safety indicators of the industrial control system includes:
[0011] Based on the logical relationships between the equipment and components in the industrial control system, the industrial control system is decomposed to determine its tree structure.
[0012] Based on the tree structure, the industrial control system, the equipment, and the component failure events, a fault tree for the industrial control system is determined, wherein the structure of the fault tree is the same as the tree structure.
[0013] Determine the failure probability of each node in the fault tree, wherein the nodes in the fault tree include failure events of the industrial control system, the equipment, and the components;
[0014] The fault tree is mapped to a Bayesian network, and the failure probability of the industrial control system is determined based on the Bayesian network.
[0015] The functional safety index is determined based on the failure probability.
[0016] According to an integrated risk assessment method for industrial control systems provided by the present invention, the step of mapping the fault tree to a Bayesian network and determining the failure probability of the industrial control system based on the Bayesian network includes:
[0017] Based on the logical relationships between the nodes in the fault tree, each node in the fault tree is mapped to a node in the Bayesian network.
[0018] The failure probability is determined based on the conditional probability of each node failure in the Bayesian network and the failure probability.
[0019] According to the integrated risk assessment method for industrial control systems provided by the present invention, the method for obtaining information security indicators of the industrial control system includes:
[0020] The probability of selecting an attack technique and the probability of switching to an attack tactic are obtained for the industrial control system, wherein the attack tactic includes one or more of the aforementioned attack techniques.
[0021] The optimal attack sequence is generated based on the Hidden Markov Model (HMM). The observed variable of the HMM is the attack technique, the initial state probability of the HMM is the initial probability of the attack tactic, the transition probability of the HMM is the jump probability of the attack tactic, and the launch probability of the HMM is the selection probability of the attack technique.
[0022] Based on the Monte Carlo method and the optimal attack sequence, a distribution curve of the attacker's success probability over time is generated.
[0023] Based on the distribution curve, the shortest attack success time for the attacker's shortest attack path is determined, and the shortest attack success time is used as the information security indicator.
[0024] According to the integrated risk assessment method for industrial control systems provided by the present invention, the step of generating a distribution curve of the attacker's success probability over time based on the Monte Carlo method and the optimal attack sequence includes:
[0025] Based on the optimal attack sequence, the probability distribution corresponding to the target attack techniques in the optimal attack sequence is obtained from the information security risk database. The information security risk database stores at least the network threat intelligence, vulnerability knowledge base, security control measures and alarm information of the industrial control system.
[0026] Based on the probability distribution, target samples are generated, wherein the samples in the target samples are determined by the shortest attack success time generated according to the probability in the probability distribution;
[0027] Based on the distribution of the target attack techniques along the attack path, obtain the local shortest attack success time and the global shortest attack success time.
[0028] The global shortest attack success time is used as a random variable, and the random distribution of the random variable is obtained;
[0029] Based on the random distribution, a distribution curve of the attacker's success probability over time is generated.
[0030] According to an integrated risk assessment method for industrial control systems provided by the present invention, determining the optimal protection strategy for the industrial control system based on the Pareto optimal solution set of the space curve corresponding to the objective function includes:
[0031] With the goal of minimizing the functional safety risk index function, the optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set. The optimal protection strategy is determined based on the Pareto optimal solution that minimizes the functional safety risk index function.
[0032] The present invention also provides an integrated risk assessment system for industrial control systems, comprising: a first acquisition module, a second acquisition module, and a third acquisition module;
[0033] The first acquisition module is used to determine the target function based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system.
[0034] The second acquisition module is used to determine the constraints of the objective function based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system.
[0035] The third acquisition module is used to determine the optimal protection strategy of the industrial control system based on the Pareto optimal solution set of the space curve corresponding to the objective function.
[0036] The present invention also provides an electronic device, including a processor and a memory storing a computer program, wherein the processor executes the program to implement an integrated risk assessment method for industrial control systems as described above.
[0037] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements an integrated risk assessment method for industrial control systems as described above.
[0038] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements an integrated risk assessment method for industrial control systems as described above.
[0039] The integrated risk assessment method and system for industrial control systems provided by this invention can simultaneously assess the functional safety and information security risks of industrial control systems. Compared with the prior art, which requires separate risk assessments for functional safety and information security of industrial control systems, this method saves manpower and material resources and provides the best protection strategy for industrial control systems, ensuring their safe operation. Attached Figure Description
[0040] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0041] Figure 1 This is one of the flowcharts of the integrated risk assessment method for industrial control systems provided by the present invention;
[0042] Figure 2 This is the second flowchart of the integrated risk assessment method for industrial control systems provided by this invention;
[0043] Figure 3 This is a schematic diagram illustrating the principle of information security risk analysis provided by the present invention;
[0044] Figure 4 This is a schematic diagram of the integrated risk assessment system for industrial control systems provided by the present invention;
[0045] Figure 5 This is an example diagram of the attacker's TTC time distribution provided by the present invention;
[0046] Figure 6 This is a schematic diagram of the integrated risk assessment system for industrial control systems provided by the present invention;
[0047] Figure 7 This is a schematic diagram of the physical structure of the electronic device provided by the present invention. Detailed Implementation
[0048] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0049] To address the shortcomings of existing technologies, this invention provides an integrated risk assessment system and method for industrial control systems. It simultaneously collects basic information about the industrial control system, functional safety risk data, and information security risk data. Based on system topology and Bayesian networks, it generates functional safety risk indicators. Based on Hidden Markov Models (HMMs) and Monte Carlo methods, it simulates and generates information security indicators. Finally, it displays the optimal attack path and asset risk ranking, and automatically provides the best protection strategy based on the Pareto optimal solution set. The specific implementation is as follows:
[0050] Figure 1 This is one of the flowcharts illustrating the integrated risk assessment method for industrial control systems provided by this invention, such as... Figure 1 As shown, the method includes:
[0051] Step 110: Determine the target function based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system.
[0052] Step 120: Determine the constraints of the objective function based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system.
[0053] Step 130: Determine the optimal protection strategy for the industrial control system based on the Pareto optimal solution set of the space curve corresponding to the objective function.
[0054] It should be noted that the above method can be implemented by computer equipment.
[0055] Optionally, the objective function is the objective function of a multi-objective optimization problem for an industrial control system, specifically including the functional safety risk index function f of the industrial control system. pfd (x safety ,x security and information security risk indicator function f ttc (x safety ,x security The functional safety risk index function can be specifically derived from the functional safety indicators of the industrial control system, where the functional safety indicator can be the failure probability. The information security risk index function can be specifically derived from the information security indicators of the industrial control system, where the information security indicator can be the shortest attack success time, x.safety ,x security These represent functional safety protection measures and information security protection measures for industrial control systems, respectively.
[0056] Determine the constraints of the objective function: Traverse the functional safety assurance measures library and information security defense measures library of the industrial control system to determine the solution space X of the objective function. safety X security Based on the functional safety level requirements and information security level requirements of the industrial control system, the functional safety constraint SIL and information security constraint SL of the objective function are determined. The constraints of the objective function are then determined based on the solution space, functional safety constraint SIL, and information security constraint SL.
[0057] Based on the objective function and its constraints, the objective function for the multi-objective optimization problem is as follows:
[0058]
[0059] Generate the spatial curve of the objective function, obtain the Pareto optimal solution set, and based on the solutions included in the Pareto optimal solution set, obtain the optimal functional safety protection measures and the optimal information security protection measures for the industrial control system.
[0060] We will use the best functional safety and information security protection measures for industrial control systems as the best protection strategies and provide defense recommendations for industrial control systems.
[0061] The integrated risk assessment method for industrial control systems provided by this invention can simultaneously assess the functional safety and information security risks of industrial control systems. Compared with the prior art, which requires separate risk assessments for functional safety and information security of industrial control systems, this method saves manpower and material resources and provides the best protection strategy for industrial control systems, ensuring their safe operation.
[0062] Furthermore, in one embodiment, the method for obtaining the functional safety indicators of the industrial control system may specifically include:
[0063] Based on the logical relationships between the equipment and components in the industrial control system, the industrial control system is decomposed to determine its tree structure.
[0064] Based on the tree structure, the industrial control system, the equipment, and the component failure events, a fault tree for the industrial control system is determined, wherein the structure of the fault tree is the same as the tree structure.
[0065] Determine the failure probability of each node in the fault tree, wherein the nodes in the fault tree include failure events of the industrial control system, the equipment, and the components;
[0066] The fault tree is mapped to a Bayesian network, and the failure probability of the industrial control system is determined based on the Bayesian network.
[0067] The functional safety index is determined based on the failure probability.
[0068] Furthermore, in one embodiment, mapping the fault tree to a Bayesian network and determining the failure probability of the industrial control system based on the Bayesian network may specifically include:
[0069] Based on the logical relationships between the nodes in the fault tree, each node in the fault tree is mapped to a node in the Bayesian network.
[0070] The failure probability is determined based on the conditional probability of each node failure in the Bayesian network and the failure probability.
[0071] Optionally, Figure 2 This is the second flowchart of the integrated risk assessment method for industrial control systems provided by this invention, as shown below. Figure 2 As shown, it includes:
[0072] Step 1: Collect, store, and manage basic information about the industrial control system (equipment list, equipment topology, etc.);
[0073] Step 2: Collect, store, and manage functional safety risk data of industrial control systems (e.g., basic failure unit failure probability and mean time between failures (MTBF)).
[0074] Step 3: Collect, store, and manage information security risk data of industrial control systems (e.g., cyber threat intelligence, vulnerability knowledge base, security control measures, and alarm information);
[0075] Step 4: Based on the same system topology and system analysis, for functional safety, the failure probability (PFD) of the industrial control system is calculated by analyzing the fault tree and then mapping the fault tree to a Bayesian network.
[0076] Step 5: For information security, HMM is used to generate the optimal attack sequence, and then the shortest attack success time (TTC) of the attacker is simulated based on the Monte Carlo method.
[0077] Step 6: Traverse the functional safety assurance measures library and information security defense measures library of the industrial control system, generate the spatial curve of the objective function, find the Pareto optimal solution set, and obtain the best protection strategy.
[0078] The specific process of the functional safety analysis in step 4 above is as follows:
[0079] Step 41, Decompose the industrial control system. Based on functional characteristics and the logical relationships between equipment and components in the industrial control system, specifically based on the connection relationships between equipment and components, the industrial control system is decomposed and its system configuration is recorded using a method of first decomposing the equipment and then the components. A tree structure can be used.
[0080] Step 42: Build a fault tree based on the tree structure. Using industrial control system failures as top-level events, equipment or component failures as intermediate events, and root causes as bottom-level events, build a fault tree model. Specifically, use industrial control system failure events as the root node of the fault tree, equipment failure events as child nodes of the root node, and component failure events as child nodes of the child nodes. Construct the fault logic from top to bottom until tracing back to the root cause of the failure event in the industrial control system.
[0081] Step 43, data selection: fill in the failure probability of basic fault units (including equipment and components) based on the data in the functional safety risk library. When data is unavailable, fill in the failure probability given by experts or the failure probability of similar products, and use it as the failure probability of each node in the fault tree.
[0082] Step 44: Based on the logical relationships between the nodes in the fault tree, map the fault tree to a Bayesian network. The mapping method is as follows:
[0083] A) Event Mapping Node: Maps the fault events corresponding to each node in the fault tree to each node in the Bayesian network, ensuring that the physical meaning of each node label in the Bayesian network corresponds one-to-one with the fault events in the fault tree;
[0084] B) Fault logic mapping directed edges automatically connect each node in the Bayesian network based on the logical relationship between fault events established by the fault tree. The starting point of the directed edge is the input event of the logic gate, and the ending point is the output event of the logic gate. That is, the fault event corresponding to the child node in the fault tree is taken as the starting point of the directed edge, and the fault event corresponding to the parent node of the child node in the fault tree is taken as the ending point of the directed edge.
[0085] C) Logic gate mapping conditional probability table (including the conditional probability of each node's failure in the Bayesian network). The conditional probability table of each node in the Bayesian network is obtained based on the logic gate mapping of the fault tree. The mapping logic is shown in the following equation, where... For node X i All parent nodes, X i =fault represents node X iFault.
[0086]
[0087] Step 45: Functional safety index calculation. Based on the prediction, reasoning and diagnosis of Bayesian networks, the conditional probability table and the failure probability of fault events in the fault tree, the functional safety index of the industrial control system, namely the failure probability PFD, is obtained.
[0088] Furthermore, in one embodiment, the method for obtaining the information security indicators of the industrial control system may specifically include:
[0089] The probability of selecting an attack technique and the probability of switching to an attack tactic are obtained for the industrial control system, wherein the attack tactic includes one or more of the aforementioned attack techniques.
[0090] The optimal attack sequence is generated based on the Hidden Markov Model (HMM). The observed variable of the HMM is the attack technique, the initial state probability of the HMM is the initial probability of the attack tactic, the transition probability of the HMM is the jump probability of the attack tactic, and the launch probability of the HMM is the selection probability of the attack technique.
[0091] Based on the Monte Carlo method and the optimal attack sequence, a distribution curve of the attacker's success probability over time is generated.
[0092] Based on the distribution curve, the shortest attack success time for the attacker's shortest attack path is determined, and the shortest attack success time is used as the information security indicator.
[0093] Furthermore, in one embodiment, generating the distribution curve of the attacker's success probability over time based on the Monte Carlo method and the optimal attack sequence may specifically include:
[0094] Based on the optimal attack sequence, the probability distribution corresponding to the target attack techniques in the optimal attack sequence is obtained from the information security risk database. The information security risk database stores at least the network threat intelligence, vulnerability knowledge base, security control measures and alarm information of the industrial control system.
[0095] Based on the probability distribution, target samples are generated, wherein the samples in the target samples are determined by the shortest attack success time generated according to the probability in the probability distribution;
[0096] Based on the distribution of the target attack techniques along the attack path, obtain the local shortest attack success time and the global shortest attack success time.
[0097] The global shortest attack success time is used as a random variable, and the random distribution of the random variable is obtained;
[0098] Based on the random distribution, a distribution curve of the attacker's success probability over time is generated.
[0099] Optionally, the specific process of information security analysis in step 5 above is as follows: Figure 3 As shown, it includes:
[0100] Step 51: Analyze the information security risk data to obtain risk identification results, and store and update the selection probability of attack techniques and the jump probability of attack tactics (including one or more attack techniques) based on the risk identification results.
[0101] Step 52: Generate the optimal attack sequence based on the Hidden Markov Model (HMM). For the HMM, the initial probability of the attack tactic is set as the initial state probability, the observed variable is set as the attack technique, the transition probability is set as the jump probability of the attack tactic, and the launch probability is set as the selection probability of the attack technique, thus generating the optimal attack sequence.
[0102] Step 53: Generate information security indicators, specifically the shortest attack success time (TTC), using the Monte Carlo method. Industrial control system attacks are uncommon and suffer from small sample sizes. The Monte Carlo method, by capturing the geometric quantities and characteristics of motion, uses mathematical methods to simulate these phenomena—essentially conducting a digital simulation experiment. It is based on a probabilistic model, and the results of the simulation, following the process described by this model, serve as an approximate solution to the problem. Specific analysis methods:
[0103] A) Based on the optimal attack sequence generated by HMM, extract the probability distribution corresponding to the attack techniques (i.e. target attack techniques) in the optimal attack sequence from the information security risk database. The information security risk database stores at least network threat intelligence, vulnerability knowledge base, security control measures and alarm information of industrial control systems.
[0104] B) Generate a certain number of samples, i.e., target samples (e.g., 1000), based on a specified probability distribution (e.g., gamma distribution). The value of each sample can be understood as the time of TTC, and different TTCs are generated according to the corresponding probabilities.
[0105] C) Obtain the local TTC / global TTC calculation formula based on the distribution of attack techniques along the attack path: The probability distribution of each attack step can be linked to the time required to execute the attack technique. Taking a three-node (A->C / B->C) path as an example, assuming the attack technique at node C follows a gamma distribution, the local shortest attack success time T... loc The relation for (C) is as follows:
[0106] φ(C)=P(T loc (C)=t)=Gamma(24,0.5);
[0107] Here, t represents the local TTC. By substituting multiple different values of t and averaging them, the probability distribution curve of the TTC is obtained.
[0108] Global shortest attack success time T glob (C) The calculation formula is as follows:
[0109] T glob (C)=min(T glob (A),T glob (B))+T loc (C);
[0110] Among them, T glob (A) and T glob (B) represents the global TCC of nodes A and B respectively.
[0111] Treat the global TTC as a random variable (this random variable is a discrete table), and find the random distribution of this random variable. Specifically, divide the random variable into 105 categories, and accumulate the probability of belonging to each category. For example, if t = 50 days is a category, count the number of values less than 50 in this set of data, and then divide by the sample size of 1000 to get the cumulative probability, that is, the random distribution.
[0112] Step 54: Plot the cumulative probability curve to obtain the distribution curve of the attacker's success probability over time, and obtain the shortest attack success time of the attacker's shortest attack path based on the distribution curve, and use the shortest attack success time of the attacker's shortest attack path as an information security indicator.
[0113] Optionally, after calculating the functional safety and information security indicators of the industrial control system, the attacker's optimal attack path is highlighted, and a ranking of node asset risk values is generated and high-risk assets are marked.
[0114] The integrated risk assessment method for industrial control systems provided by this invention calculates the functional safety and information security indicators of the industrial control system, generates and highlights the optimal attack path for attackers, generates a ranking of node asset risk values and marks high-risk assets, constructs an objective function based on the functional safety indicator (PFD) and information security indicator, traverses the system security strategy library (functional safety assurance measures library and information security defense measures library), generates the spatial curve of the objective function, finds the Pareto optimal solution, and provides optimal security configuration suggestions to ensure the safe operation of the industrial control system.
[0115] Furthermore, in one embodiment, determining the optimal protection strategy for the industrial control system based on the Pareto optimal solution set of the space curve corresponding to the objective function may specifically include:
[0116] With the goal of minimizing the functional safety risk index function, the optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set. The optimal protection strategy is determined based on the Pareto optimal solution that minimizes the functional safety risk index function.
[0117] Optionally, the optimal protection strategy is selected based on the functional safety priority criterion. Specifically, with the goal of minimizing the functional safety risk index function, the Pareto optimal solution that minimizes the functional safety risk index function is found from the Pareto optimal solution set, and the corresponding functional safety protection measures and information security protection measures are taken as the optimal protection strategy, thereby determining the actual safety level of the industrial control system.
[0118] Figure 4 This is a schematic diagram of the integrated risk assessment system for industrial control systems provided by the present invention, as shown below. Figure 4 As shown, this integrated risk assessment system may specifically include:
[0119] The system includes a basic information management module for industrial control systems, an information security risk data analysis module, a functional safety risk data analysis module, an attack graph generation module, a Bayesian analysis module, and an integrated risk assessment module.
[0120] The Industrial Control System Basic Information Management Module can be used to manage basic information of industrial control systems (equipment information, equipment type, firmware version, etc.) and equipment topology information.
[0121] The information security risk data analysis module can be specifically used to maintain the mapping relationship between NIST SP800-53 security controls and ATT&CK (Adversarial Tactics, Technologies, and Common Knowledge); regularly acquire network threat intelligence (Common Weaknesses (CWE), Common Attack Type Classification Datasets (CAPEC), and Common Vulnerability Disclosures (CVE)); update the mapping relationship between CWE, CAPEC, and CVE and ATT&CK; and parse alarm information in real time and update the mapping relationship between alarm information and ATT&CK.
[0122] Functional safety risk data analysis module: It can be used to construct JSON files to store basic fault units and failure probabilities, allowing users to customize and modify them according to system operation; it can also maintain industry accident databases, general reliability databases, human error databases, and historical operation accident databases.
[0123] Attack graph generation module: Specifically, it can be used to generate optimal attack sequences between devices based on device topology and information security risk data, and then complete the global attack graph generation based on system topology reachability. Finally, it uses the Monte Carlo method to simulate and generate the shortest attack path TTC for the attacker.
[0124] Bayesian Analysis Module: Specifically, it can be used to build a fault tree with industrial control system failure as the top-level event, equipment or component failure as the intermediate event, and the root cause of the failure as the bottom event. According to the transformation algorithm, the fault tree is converted into a Bayesian network, and the failure probability (PFD) of the industrial control system is calculated through Bayesian analysis.
[0125] The integrated risk assessment module can be used to calculate the functional safety and information security indicators of industrial control systems in real time, generate and highlight the optimal attack path for attackers, generate a ranking of node asset risk values and mark high-risk assets; construct an objective function based on the functional safety indicator (PFD) and information security indicator, traverse the system security strategy library (functional safety assurance measures library and information security defense measures library), generate the spatial curve of the objective function, find the Pareto optimal solution, and provide optimal security configuration recommendations based on this.
[0126] (1) The input files for the basic information management module of the industrial control system are asset and equipment list, asset topology list, safety standard questionnaire, active scan report, administrator correction, etc. It realizes the management and maintenance of basic information of industrial control system.
[0127] First, import the asset and equipment list from the industrial control system as a JSON file. The JSON fields include equipment name, equipment ID, equipment type, MAC address, IP address, manufacturer, usage protocol, firmware version, and hardware failure probability. Next, import the asset topology list from the industrial control system as a JSON file. The JSON fields include source device ID, destination device ID, and protocol number.
[0128] Secondly, a security standard questionnaire matrix is stored in a MySQL database, and a survey questionnaire interface is generated on the front end using JavaScript for users to use, thereby collecting security standard implementation data.
[0129] Next, import the proactive scan report. Taking Nessus as an example, after the system completes the scan, it generates scan results in XML format. After parsing the XML file, it automatically stores the vulnerability information, configuration information, and host information corresponding to the device ID into the database.
[0130] Finally, the system provides administrator modification functionality, allowing administrators to directly modify basic information of the industrial control system through the user interface in cases of JSON file errors, inaccurate active scanning, or changes in system devices.
[0131] (2) The inputs to the information security risk data analysis module include network threat intelligence, asset information, and security standard implementation data. It enables the collection, quantification, and mapping of information security risk data for industrial control systems.
[0132] First, obtain online network threat intelligence information by requesting different sites (NIST, mitre, etc.) through network APIs: ATT&CK, CWE, Capec, and CVE.
[0133] By comprehensively analyzing the correlations between data from different sources, a mapping relationship of CVE->CWE->Capec->ATT&CK is generated through an inference engine to extract the attack techniques corresponding to the devices within the system.
[0134] Secondly, historical APT attack data is extracted from online ATT&CK data, and the attack tactics used by different organizations / malware and their interdependencies are analyzed to update the jump probability of attack tactics.
[0135] Next, import the security standard execution data and compare it with the NIST security control measures -> ATT&CK mapping relationship in the database to extract the attack techniques corresponding to the industrial control system.
[0136] Finally, the system provides administrators with the ability to modify the mapping relationships of security control measures and to customize mapping relationships based on expert experience.
[0137] (3) The inputs to the functional safety risk data analysis module include system topology, asset information, and functional safety failure data. This enables the collection, quantification, and management of information security risk data for industrial control systems.
[0138] Establish a general reliability database, maintaining the hardware failure probability for different equipment types based on typical and representative equipment in the industry. Establish an industry-specific accident database, maintaining the historical accident probability for different industrial control systems. Establish a human error database, maintaining the human-caused failure probability for different industrial control systems. Establish a historical operational accident database, importing and maintaining operation, maintenance, fault, and accident data for industrial control systems. Based on the asset and equipment list and the above databases, maintain the failure probability of assets within the system.
[0139] (4) The attack graph generation module takes information security risk data and asset topology list as input, generates the optimal attack sequence between devices based on the HMM model, generates the system global attack graph based on the asset topology list, and finally generates information security indicators based on Monte Carlo simulation.
[0140] First, the initial probability P of the ATT&CK attack tactic is generated using the ATT&CK mapping relationship output by the information security risk data analysis module.a The jump probability P of the ATT&CK attack tactic v The probability P of choosing the ATT&CK attack technique b And store it in the database.
[0141] Secondly, the optimal attack sequence is generated based on the Hidden Markov Model (HMM). An HMM is a statistical model used to describe a Markov process with hidden unknown parameters. The integrated risk system uses this model to generate the optimal attack sequence. The core of an HMM is a quintuple HMM{S, K, Π, A, B}, where the state set (i.e., the observed variables) S = {s1, ..., s2}. N The corresponding ATT&CK attack tactics in the system database have an initial state probability П={π i}, i∈S corresponds to the initial probability P of the ATT&CK attack tactic in the system database. a The state transition probability (i.e., the transition probability) A = {a ij}, i, j∈S correspond to the jump probability P of the ATT&CK attack tactic in the system database. v The symbol emission probability (i.e., emission probability) B = {b} ijk}, i,j∈S,k∈M correspond to the selection probability P of the ATT&CK attack technique in the system database. b The output set K = {k1,...,k} m} corresponds to the final generated optimal attack sequence.
[0142] Finally, based on the optimal attack sequence, the distribution curve of the attacker's success probability over time was obtained through Monte Carlo simulation. An example of the attacker's TTC probability distribution is shown below. Figure 5 As shown.
[0143] (5) The Bayesian analysis module takes functional safety risk data and basic information of industrial control system as input. It uses the fault tree analysis method to easily model the fault tree of industrial control system to Bayesian network. Then, it uses the advantages of Bayesian network to express and analyze uncertain and probabilistic events to obtain the functional safety index of industrial control system.
[0144] First, based on functional safety risk data and the system's own situation, analysts manually drag and drop process boxes to build a fault tree.
[0145] Secondly, the module matches fault tree node keywords with functional safety risk data keywords and automatically populates fault tree nodes. For insufficient data, the module automatically recommends similar product data and reliability database data (such as OREDA), which is then ultimately selected by the analyst.
[0146] Finally, the fault tree is mapped to the corresponding Bayesian network according to the mapping method, and the functional safety index (PFD) of the industrial control system is calculated using Bayes' theorem.
[0147] (6) The integrated risk assessment module serves as the output module of the system, providing risk assessment results for the industrial control system, including: a visual front-end display of the attacker's optimal attack path, a risk ranking of high-risk assets, and suggestions for the system's optimal security protection measures, and outputting a risk assessment report in PDF format.
[0148] First, attack graph data and optimal attack path (TTC attack path) data in JSON format are obtained from the attack graph generation module, and then the optimal attack path is rendered and highlighted on the front end.
[0149] Secondly, based on the TTC ranking and equipment reliability ranking among nodes, information on high-risk assets and their corresponding ATT&CK attack tactics and equipment failure probabilities are displayed from high to low.
[0150] Furthermore, when the system security risk indicator function changes—that is, when the attack graph generation module / Bayesian analysis module updates the information security indicators / functional safety indicators in real time, or when the functional safety assurance measures library and information security defense measures library are updated—the spatial curve of the multi-objective function is regenerated to obtain the Pareto optimal solution set. Finally, optimal protection strategy recommendations are generated based on the functional safety priority criterion.
[0151] Finally, output a risk assessment report in PDF format.
[0152] The integrated risk assessment method for industrial control systems provided by this invention selects the best protection strategy based on the functional safety priority principle, provides defense suggestions for industrial control systems, and reduces the probability of them being attacked.
[0153] The integrated risk assessment system for industrial control systems provided by this invention will be described below. The integrated risk assessment system for industrial control systems described below can be referred to in correspondence with the integrated risk assessment method for industrial control systems described above.
[0154] Figure 6 This is a schematic diagram of the integrated risk assessment system for industrial control systems provided by the present invention, as shown below. Figure 6 As shown, it includes:
[0155] The first acquisition module 610, the second acquisition module 611, and the third acquisition module 612;
[0156] The first acquisition module 610 is used to determine the target function based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system.
[0157] The second acquisition module 611 is used to determine the constraints of the objective function based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system.
[0158] The third acquisition module 612 is used to determine the optimal protection strategy of the industrial control system based on the Pareto optimal solution set of the space curve corresponding to the objective function.
[0159] The integrated risk assessment system for industrial control systems provided by this invention can simultaneously assess the functional safety and information security risks of industrial control systems. Compared with the prior art, which requires separate risk assessments for functional safety and information security of industrial control systems, this system saves manpower and material resources and provides the best protection strategy for industrial control systems, ensuring their safe operation.
[0160] Figure 7 This is a schematic diagram of the physical structure of an electronic device provided by the present invention, such as... Figure 7 As shown, the electronic device may include a processor 710, a communication interface 711, a memory 712, and a bus 713. The processor 710, communication interface 711, and memory 712 communicate with each other via the bus 713. The processor 710 can call logical instructions from the memory 712 to execute the following methods:
[0161] The target function is determined based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system.
[0162] Based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function, the constraints of the objective function are determined. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system.
[0163] The optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set of the space curve corresponding to the objective function.
[0164] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and sold or used as independent products, and can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer power supply (which may be a personal computer, server, or network power supply, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0165] Furthermore, this invention discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when these instructions are executed by a computer, the computer can execute the integrated risk assessment method for industrial control systems provided in the above-described method embodiments, for example including:
[0166] The target function is determined based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system.
[0167] Based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function, the constraints of the objective function are determined. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system.
[0168] The optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set of the space curve corresponding to the objective function.
[0169] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the integrated risk assessment method for industrial control systems provided in the above embodiments, including, for example:
[0170] The target function is determined based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system.
[0171] Based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function, the constraints of the objective function are determined. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system.
[0172] The optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set of the space curve corresponding to the objective function.
[0173] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0174] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer power supply (which may be a personal computer, server, or network power supply, etc.) to execute the methods described in various embodiments or some parts of the embodiments.
[0175] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An integrated risk assessment method for industrial control systems, characterized in that, include: The target function is determined based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system. Based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function, the constraints of the objective function are determined. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system. The optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set of the space curve corresponding to the objective function. The methods for obtaining the functional safety indicators of the industrial control system include: Based on the logical relationships between the equipment and components in the industrial control system, the industrial control system is decomposed to determine its tree structure. Based on the tree structure, the industrial control system, the equipment, and the component failure events, a fault tree for the industrial control system is determined, wherein the structure of the fault tree is the same as the tree structure. Determine the failure probability of each node in the fault tree, wherein the nodes in the fault tree include failure events of the industrial control system, the equipment, and the components; The fault tree is mapped to a Bayesian network, and the failure probability of the industrial control system is determined based on the Bayesian network. The functional safety index is determined based on the failure probability. The step of mapping the fault tree to a Bayesian network and determining the failure probability of the industrial control system based on the Bayesian network includes: Based on the logical relationships between the nodes in the fault tree, each node in the fault tree is mapped to a node in the Bayesian network. The failure probability is determined based on the conditional probability of failure of each node in the Bayesian network and the failure probability. The methods for obtaining the information security indicators of the industrial control system include: The probability of selecting an attack technique and the probability of switching to an attack tactic are obtained for the industrial control system, wherein the attack tactic includes one or more of the aforementioned attack techniques. The optimal attack sequence is generated based on the Hidden Markov Model (HMM). The observed variable of the HMM is the attack technique, the initial state probability of the HMM is the initial probability of the attack tactic, the transition probability of the HMM is the jump probability of the attack tactic, and the launch probability of the HMM is the selection probability of the attack technique. Based on the Monte Carlo method and the optimal attack sequence, a distribution curve of the attacker's success probability over time is generated. Based on the distribution curve, the shortest attack success time of the attacker's shortest attack path is determined, and the shortest attack success time is used as the information security indicator. The generation of the attacker's success probability distribution curve over time based on the Monte Carlo method and the optimal attack sequence includes: Based on the optimal attack sequence, the probability distribution corresponding to the target attack techniques in the optimal attack sequence is obtained from the information security risk database. The information security risk database stores at least the network threat intelligence, vulnerability knowledge base, security control measures and alarm information of the industrial control system. Based on the probability distribution, target samples are generated, wherein the samples in the target samples are determined by the shortest attack success time generated according to the probability in the probability distribution; Based on the distribution of the target attack techniques along the attack path, obtain the local shortest attack success time and the global shortest attack success time. The global shortest attack success time is used as a random variable, and the random distribution of the random variable is obtained; Based on the random distribution, a distribution curve of the attacker's success probability over time is generated.
2. The integrated risk assessment method for industrial control systems according to claim 1, characterized in that, The step of determining the optimal protection strategy for the industrial control system based on the Pareto optimal solution set of the space curve corresponding to the objective function includes: With the goal of minimizing the functional safety risk index function, the optimal protection strategy for the industrial control system is determined based on the Pareto optimal solution set. The optimal protection strategy is determined based on the Pareto optimal solution that minimizes the functional safety risk index function.
3. An integrated risk assessment system for industrial control systems, characterized in that, include: The first acquisition module, the second acquisition module, and the third acquisition module; The first acquisition module is used to determine the target function based on the functional safety risk index function and the information security risk index function of the industrial control system. The functional safety risk index function is determined based on the functional safety index of the industrial control system, and the information security risk index function is determined based on the information security index of the industrial control system. The second acquisition module is used to determine the constraints of the objective function based on the solution space of the objective function, the functional safety level requirements of the industrial control system, the information security level requirements of the industrial control system, and the objective function. The solution space is obtained by traversing the functional safety protection measures in the functional safety assurance measures library and the information security protection measures in the information security defense measures library of the industrial control system. The third acquisition module is used to determine the optimal protection strategy of the industrial control system based on the Pareto optimal solution set of the space curve corresponding to the objective function. The methods for obtaining the functional safety indicators of the industrial control system include: Based on the logical relationships between the equipment and components in the industrial control system, the industrial control system is decomposed to determine its tree structure. Based on the tree structure, the industrial control system, the equipment, and the component failure events, a fault tree for the industrial control system is determined, wherein the structure of the fault tree is the same as the tree structure. Determine the failure probability of each node in the fault tree, wherein the nodes in the fault tree include failure events of the industrial control system, the equipment, and the components; The fault tree is mapped to a Bayesian network, and the failure probability of the industrial control system is determined based on the Bayesian network. The functional safety index is determined based on the failure probability. The step of mapping the fault tree to a Bayesian network and determining the failure probability of the industrial control system based on the Bayesian network includes: Based on the logical relationships between the nodes in the fault tree, each node in the fault tree is mapped to a node in the Bayesian network. The failure probability is determined based on the conditional probability of failure of each node in the Bayesian network and the failure probability. The methods for obtaining the information security indicators of the industrial control system include: The probability of selecting an attack technique and the probability of switching to an attack tactic are obtained for the industrial control system, wherein the attack tactic includes one or more of the aforementioned attack techniques. The optimal attack sequence is generated based on the Hidden Markov Model (HMM). The observed variable of the HMM is the attack technique, the initial state probability of the HMM is the initial probability of the attack tactic, the transition probability of the HMM is the jump probability of the attack tactic, and the launch probability of the HMM is the selection probability of the attack technique. Based on the Monte Carlo method and the optimal attack sequence, a distribution curve of the attacker's success probability over time is generated. Based on the distribution curve, the shortest attack success time of the attacker's shortest attack path is determined, and the shortest attack success time is used as the information security indicator. The generation of the attacker's success probability distribution curve over time based on the Monte Carlo method and the optimal attack sequence includes: Based on the optimal attack sequence, the probability distribution corresponding to the target attack techniques in the optimal attack sequence is obtained from the information security risk database. The information security risk database stores at least the network threat intelligence, vulnerability knowledge base, security control measures and alarm information of the industrial control system. Based on the probability distribution, target samples are generated, wherein the samples in the target samples are determined by the shortest attack success time generated according to the probability in the probability distribution; Based on the distribution of the target attack techniques along the attack path, obtain the local shortest attack success time and the global shortest attack success time. The global shortest attack success time is used as a random variable, and the random distribution of the random variable is obtained; Based on the random distribution, a distribution curve of the attacker's success probability over time is generated.
4. An electronic device comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the integrated risk assessment method for industrial control systems as described in any one of claims 1 to 2.
5. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the integrated risk assessment method for industrial control systems as described in any one of claims 1 to 2.
6. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the integrated risk assessment method for industrial control systems as described in any one of claims 1 to 2.
Citation Information
Patent Citations
Risk analyzing method based on Monte-Carlo simulation solution dynamic fault tree model
CN104778370A
Demand analysis and integration method for function safety and information safety of industrial control system
CN105045251A