A dynamic security assessment method and device for an underwater system, a medium and a product
By employing a dynamic assessment mechanism that refines risk assessment through multi-level triggering and adjusts information entropy weights, the accuracy and stability issues of dynamic safety assessment in underwater systems are resolved, enabling detailed assessment of underwater systems and effective response to sudden risks.
Patent Information
- Application Number
- CN202410622565.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-20
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2044-05-20
AI Technical Summary
Existing technologies are insufficient for effective dynamic safety assessments of underwater systems. They lack reasonable quantitative standards, are subjective and inaccurate, and cannot adapt to the specific circumstances of underwater systems.
A multi-level triggering and refined risk assessment mechanism is adopted, which combines quantitative and qualitative indicators, uses information entropy to adjust weights and time windows, and designs abnormal indicators to couple potential risks, so as to achieve dynamic assessment.
It improves the accuracy and stability of underwater system safety assessments, reduces reliance on historical data, enhances the ability to respond to sudden risks, and makes the assessments more objective and reasonable.
Smart Images

Figure CN118573420B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of underwater system dynamic assessment technology, and in particular to a dynamic safety assessment method, device, medium and product for underwater systems. Background Technology
[0002] Security assessment is a systematic approach used to evaluate the security of a specific system or organization. It involves identifying, assessing, and managing the potential risks of possible security threats and vulnerabilities. Current research on security assessment methods focuses on two main areas: qualitative static assessment and quantitative dynamic assessment.
[0003] Dynamic security assessment is a quantitative security assessment method used to evaluate the security risks and threats faced by a specific system or organization in actual operation. Compared to static assessment, dynamic security assessment can more effectively assess and manage unexpected risks encountered by a system during actual operation.
[0004] Existing technology 1: Z. Huang et al., "Safety Assessment of Emergency Training for Industrial Accident Scenarios Based on Analytic Hierarchy Process and Gray-Fuzzy Comprehensive Assessment," in IEEE Access, vol. 8, pp. 144767-144777, 2020, proposed a qualitative static assessment method based on the Analytic Hierarchy Process (AHP) in a practical industrial scenario. It mainly uses the AHP to classify and grade risks in this scenario and assigns weights to risk indicators based on the AHP, thereby completing the risk assessment. However, the safety assessment method it employs is a qualitative static assessment, which still lacks reasonable quantitative standards in the assessment process and cannot eliminate subjective human judgment. Furthermore, there is a strong subjectivity in the weight assignment process, and the safety assessment method only has one assessment standard, failing to refine the assessment according to the specific circumstances of the underwater system. Therefore, this method is difficult to directly apply to underwater systems.
[0005] Existing technology 2: T. Liu et al., "A Bayesian Learning Based Scheme for Online Dynamic Security Assessment and Preventive Control," in IEEE Transactions on Power Systems, vol.35, no.5, pp.4088-4099, Sept.2020, doi:10.1109 / TPWRS.2020.2983477, proposes a dynamic risk assessment method based on dynamic Bayesian networks. First, a dynamic Bayesian network model based on the risk assessment process is established. Second, based on Bayesian theory and inference procedures, an information system is analyzed, and the probability of risk is calculated. However, the modeling process of dynamic Bayesian networks relies on a large amount of data and subjective domain knowledge. In practical underwater systems, obtaining complete, accurate, and real-time data may be difficult, and the modeling of this network has a strong subjective element. Furthermore, parameter estimation of the dynamic Bayesian network model needs to consider the probability distribution relationships between multiple variables, which involves complex mathematical calculations and model adjustments in practical underwater systems, potentially leading to model inaccuracies and instabilities.
[0006] Existing technology 3: J. Jiang, X. Zhu, G. Han, M. Guizani and L. Shu, "A Dynamic Trust Evaluation and Update Mechanism Based on C4.5 Decision Tree in Underwater Wireless Sensor Networks," in IEEE Transactions on Vehicular Technology, vol. 69, no. 8, pp. 9031-9040, Aug. 2020, proposes a trust evaluation and update mechanism for underwater wireless sensor networks based on the C4.5 decision tree algorithm (TEUC). In TEUC, security evaluation is triggered based on time and security events, and then the C4.5 decision tree needs to be trained using a large amount of collected trust evidence. However, event-triggered trust updates and time-triggered trust updates cannot fully fit the specific situation of underwater systems, and they do not adequately consider sudden risks, leading to inaccurate risk trigger judgments for underwater systems. Furthermore, the data collection in this scenario is based on underwater sensors, but in underwater systems, the data is operational data, and the data collection type and source are not well matched. Furthermore, decision tree training requires a large amount of data, which is difficult to obtain in actual underwater systems.
[0007] Therefore, this invention provides a dynamic safety assessment method, apparatus, medium, and product for underwater systems, addressing the current shortcomings and incompleteness of the safety assessment index system for underwater systems. It establishes a comprehensive safety assessment index system for underwater systems and improves the detailed assessment triggering of safety risks at different levels. Employing a multi-condition, progressively refined granularity principle, it designs multi-level triggering for detailed risk judgment, ensuring accurate assessment of different levels of safety risks. It designs anomaly indicator coupling to select potential risks for prediction and, based on dynamic risk assessment, processes them from both weight and time dimensions, thereby improving the sensitivity and real-time performance of the safety assessment. Summary of the Invention
[0008] The purpose of this invention is to provide a dynamic safety assessment method, device, medium, and product for underwater systems, which solves the problem of missing and incomplete safety assessment index system for underwater systems, establishes a safety assessment index system for underwater systems, and improves the detailed assessment and triggering of safety risks at different levels of underwater systems.
[0009] To achieve the above objectives, the present invention provides the following solution:
[0010] In a first aspect, the present invention provides a dynamic safety assessment method for underwater systems, comprising:
[0011] Step 1: Determine the ship's status; the ship's status includes: a sealed state and an unsealed state.
[0012] Step 2: If the ship is in a non-sealed state, proceed to step 5;
[0013] Step 3: When the ship is in a closed state, calculate the preliminary risk value of the system;
[0014] Step 4: Determine the event status based on the preliminary risk value; the event status includes: critical event, critical event, and safety event;
[0015] Step 5: When the event status is a safety event, determine the abnormality of the risk value of each indicator and obtain the judgment result; the indicators include: quantitative indicators and qualitative indicators;
[0016] Step 6: If the judgment result is abnormal, then proceed to step 13;
[0017] Step 7: If the judgment result is normal, output the risk value of each indicator;
[0018] Step 8: If the event status is a critical event or a critical event, then proceed to step 13;
[0019] Step 9: Determine the abnormal risk threshold based on the risk value of each indicator;
[0020] Step 10: When the risk level of an indicator is greater than the abnormal risk level threshold, it is determined to be an abnormal indicator, and the process proceeds to step 13.
[0021] Step 11: Determine the potential risk indicator class of the abnormal indicator based on the aforementioned risk level anomaly threshold;
[0022] Step 12: Adjust the risk level of indicators in the same indicator class based on the potential risk indicator class to obtain the updated risk level of the indicators;
[0023] Step 13: Calculate the weights of quantitative indicators using information entropy;
[0024] Step 14: Calculate the weights of qualitative indicators using information entropy;
[0025] Step 15: Calculate the initial weights of the quantitative indicators using the weights of information entropy based on the quantitative indicators;
[0026] Step 16: Calculate the initial weights of the qualitative indicators based on the information entropy weights;
[0027] Step 17: Calculate the risk level at the current time n based on the initial weights of the quantitative indicators and the initial weights of the qualitative indicators;
[0028] Step 18: Dynamically adjust the number of time windows;
[0029] Step 19: Calculate the final risk level based on the adjusted number of time windows and the risk level at the current time n.
[0030] Optionally, in step 3, the preliminary risk value of the system is calculated using the following formula:
[0031]
[0032] in, Indicates time window t n The level of risk at any moment Indicates the weight of quantitative indicators. This represents the risk value of a quantitative indicator. Indicates the weight of qualitative indicators. This represents the risk value of a qualitative indicator, and N represents the N moments in the time window.
[0033] Optionally, the event status is determined based on the preliminary risk value using the following formula:
[0034]
[0035] Where ε represents the threshold for security events, Vpre This indicates the preliminary risk value.
[0036] Optionally, in step 5, the abnormality of the risk value of each indicator is judged to obtain the judgment result, specifically using the following formula:
[0037]
[0038] in, Let the historical risk level of index i at time m be denoted as i = 1, 2, ..., 8; m = 1, 2, ..., M. This represents the average risk value over M historical moments. This represents the risk value of indicator i at the current time n.
[0039] Optionally, the expression for the risk level of the updated indicator in step 12 is as follows:
[0040]
[0041] in, Indicators The correlation coefficient for index j is α∈{0.6,0.8,1}. This represents the risk value of indicator i at the current time n.
[0042] Optionally, the expression for the risk level at the current time n in step 17 is as follows:
[0043]
[0044] in, This represents the initial weight of quantitative index i. This represents the initial weight of qualitative index j. This represents the risk value of quantitative indicator i at the current time n. This represents the risk value of the qualitative indicator j at the current time n.
[0045] Optionally, the final risk level in step 19 is expressed as follows:
[0046]
[0047] Where N' = N + ΔN, N is the number of sub-time windows of the current time window, ΔN is the number of time windows that need to be dynamically increased or decreased after calculation, k is the control factor, and e is a constant.
[0048] In a second aspect, the present invention provides a computer device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the computer program to implement the steps of the method described in the first aspect.
[0049] Thirdly, the present invention provides a computer-readable storage medium having a computer program stored thereon, characterized in that the computer program, when executed by a processor, implements the steps of the method described in the first aspect.
[0050] Fourthly, the present invention provides a computer program product, including a computer program, characterized in that, when the computer program / instructions are executed by a processor, they implement the steps of the method described in the first aspect.
[0051] According to specific embodiments provided by the present invention, the present invention discloses the following technical effects:
[0052] This invention employs a dynamic evaluation mechanism, which refines trigger judgments in a tiered manner based on the specific conditions of the underwater system. It utilizes dynamic processing of risk levels, such as anomaly indicators coupled with potential risks, reducing subjectivity and making the evaluation more objective and reasonable. Dynamic evaluation based on risk level information reduces reliance on historical data and subjective judgment, and eliminates the need to consider the probability distribution relationships of multiple variables, increasing the accuracy and stability of the evaluation mechanism. The designed three-level triggering system considers the specific characteristics of the underwater system and is more suitable for its environment. The designed triggering mechanism and the coupling of potential risks with anomaly indicators demonstrate strong capabilities in responding to sudden risks, and are more objective and reasonable as they do not rely on historical data. Attached Figure Description
[0053] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0054] Figure 1 A schematic diagram of the dynamic evaluation mechanism provided by this invention;
[0055] Figure 2 A multi-level triggering perception flowchart for the dynamic safety assessment method for underwater systems provided by this invention;
[0056] Figure 3 This is a comparison chart of the evaluation of static weights and dynamic weights provided by the present invention;
[0057] Figure 4 This is a comparative diagram illustrating the assessment under continuous risk provided by the present invention;
[0058] Figure 5 This is a comparative diagram illustrating the assessment of mutation risk provided by the present invention;
[0059] Figure 6This is a comparison diagram between the dynamic mechanism provided by this invention and classic static techniques. Detailed Implementation
[0060] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0061] The purpose of this invention is to provide a dynamic safety assessment method, device, medium, and product for underwater systems, which solves the problem of missing and incomplete safety assessment index system for underwater systems, establishes a safety assessment index system for underwater systems, and improves the detailed assessment and triggering of safety risks at different levels of underwater systems.
[0062] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0063] Referring to GB / T 20984-2022 "Information Security Technology - Information Security Risk Assessment Method", and combining actual risk assessment project experience with the above-mentioned underwater system attack scenarios, commonly used necessary influencing factors are selected as assessment indicators, and a comprehensive risk assessment indicator system is constructed as shown in the table below.
[0064] Table 1 Risk Assessment Index System for Underwater Systems
[0065]
[0066] The table above presents a risk assessment index system for underwater systems, constructed based on attack scenarios. These attack scenarios primarily include three typical types of attacks: DoS attacks, latency attacks, and injection attacks. These attacks mainly exploit three attack points within the underwater system: the network data layer, the control layer, and the fiber optic ring network. DoS attacks can exploit the communication network portion of the network data layer, consuming network resources and preventing the system from responding to legitimate user requests. Attacks can also target the control layer, particularly the access communication portions of the underlying actuators and sensors, using latency attacks to delay the transmission of control commands and affect system response speed. Finally, attacks may target the fiber optic ring network using injection attacks to disrupt the underwater system's network structure and infrastructure, compromising data transmission integrity.
[0067] To address the aforementioned typical attacks and enhance the risk prediction and response capabilities of the designed dynamic assessment mechanism, indicators closely related to typical attacks were selected from the indicator system in Table 1 to establish a potential risk indicator class for typical attacks. DoS attacks, leveraging large-scale traffic, distributed attacks, and deception, can quickly and easily render the target underwater system unavailable, making them the most common and effective attack method. This potential risk indicator class selects indicators such as throughput, network traffic, and the number of request-response packets. Latency attacks primarily attack the system by increasing latency and affecting the system's packet transmission and reception, causing communication disruptions, data transmission delays, resource waste, and service unavailability. This potential risk indicator class mainly selects indicators such as latency attacks, latency, and network packet loss rate. Injection attacks primarily accomplish their purpose by disrupting the network structure and infrastructure of the underwater system. While equipment and facilities on submarines are isolated and protected, all systems on a submarine are computer-controlled automated systems. Therefore, one of the most effective means of attacking submarines is to use malware for injection attacks. Thus, this potential risk indicator mainly selects indicators such as DDS-QoS configuration, network structure, and traffic interleaving. Therefore, the indicator categories for the three types of potential risks established based on the indicator system are shown in the table below:
[0068] Table 2 Indicator Categories of Potential Risks
[0069] Potential risks Relevant indicators DOS attack Throughput, network traffic, number of request and response packets Delay attack Latency and network packet loss rate Injection attack DDS-QoS configuration, network structure, and interleaved service traffic
[0070] The indicator data in Table 2 were mainly obtained through business data collection and are closely related to typical attacks; therefore, they are quantitative indicators, which can be represented by W. The risk 1-DoS attack-related indicators, including throughput, request / response packet count, and network traffic, are now defined as W. 1 The risk of network packet loss rate and latency is defined as W - latency attack related indicators. 2 The risk of DDS-QoS configuration, network structure, and interleaved service traffic is defined as W. 3 Based on the specific operations of the underwater system, the initial time window number N is set, meaning that one time window contains N sub-windows of time. Let the current time be within the time window t. n If n∈{1,2,…,N}, then at the current time n, W 1 The set of sub-indicator risk levels is named These represent throughput, the number of request / response packets, and the risk level of network traffic at the current time n, respectively. At the current time n, W 2 The set of sub-indicator risk levels is named These represent the network packet loss rate and latency risk at the current time n, respectively. At the current time n, W 3 The risk set is named These represent the risk levels of DDS-QoS configuration, network structure, and traffic interleaving at the current time n, respectively. The quantitative indicators are within the time window t. n The weights are represented as i = 1, 2, ..., 8.
[0071] In Table 1, the risk assessment indicator system for underwater systems, apart from the indicators mentioned above, mainly consists of qualitative indicators. These indicators generally cannot be quantified through specific data and are usually derived from observation and judgment. These qualitative indicators are defined as U. As shown in Table 1, there are 14 qualitative indicators in total. The risk level of each qualitative indicator at the current time n is defined as... j = 1, 2, ..., 14. The qualitative indicators are within the time window t. n The weights are represented as j = 1, 2, ..., 14.
[0072] in, and The value range is {0.1, 0.3, 0.5, 0.7, 0.9}, which represent the risk value of this indicator under the conditions of a safe state, a low-intensity attack, a high-intensity attack, a very high-intensity attack, and an extremely high-intensity attack, respectively.
[0073] The attack intensity and type are determined using indicators closely related to the attack, as shown in Table 3. The attack type and intensity are initially assessed based on the indicator data. For different attacks of varying intensities, the risk level of indicators with collectable data is obtained by comparing it with the security situation in actual business operations. The risk level of indicators without collectable data is primarily assigned based on the different attack types and intensities listed in Table 3. The following table shows the risk level assignments for indicators under different attack intensities:
[0074] Table 3
[0075]
[0076]
[0077]
[0078]
[0079]
[0080]
[0081]
[0082]
[0083] The overall process of the designed dynamic evaluation mechanism is as follows, mainly divided into two parts: multi-level perception triggering and dynamic adjustment. For example... Figure 1 As shown, a multi-condition, progressively refined granularity approach is adopted, designing a multi-level perception trigger. The first-level trigger determines the trigger based on the underwater system status. The second-level trigger has two layers of judgment: first, a safety event judgment is used to initially perceive safety risks; based on this initial perception, it determines whether to proceed to the second-level judgment. The second-level judgment uses anomaly indicator monitoring to further refine the perception of safety risks. After the second-level trigger, the dynamic adjustment of anomaly indicators couples with potential risks, enabling the mechanism to cope with potential risks. After the above judgment and risk coupling, the designed algorithm dynamically adjusts the indicator weights and time windows based on risk level information to achieve dynamic reassessment. After completing the dynamic reassessment, the third-level trigger is initiated to determine potential risks and output them to the defense system. After the defense system completes its defense, it conducts another assessment to verify the accuracy of the dynamic assessment. The following flowchart describes the entire implementation process of the invention.
[0084] Figure 1 This diagram illustrates the entire mechanism, which mainly includes multi-level perception triggering and dynamic adjustment. Multi-level perception triggering comprises two parts: a three-level triggering system primarily based on the first two levels, and a reassessment triggering based on defensive measures against potential risks. Dynamic adjustment mainly includes two parts: coupling potential risks with abnormal indicators and dynamic reassessment based on risk level information. The specific workflow and its principles will be described below.
[0085] Example 1
[0086] See Figure 2 , Figure 2 The multi-level triggering perception flowchart of the dynamic safety assessment method for underwater systems provided by this invention specifically includes:
[0087] Level 1 trigger:
[0088] Step 1: Determine the ship's status; the ship's status includes: a sealed state and an unsealed state.
[0089] Step 2: If the ship is in a non-sealed state, proceed to step 5.
[0090] The first level of triggering, for underwater systems, involves two main states on the ship: enclosed and non-enclosed. In enclosed states such as navigation, the system directly enters the first level of the second-level trigger for safety event assessment. In non-enclosed states such as entering port or taking refuge, the ship has more contact with the outside world due to maintenance and repair, thus the risk is higher than in other stages. Therefore, it directly triggers the second level of the second-level trigger for more detailed assessment, monitoring and evaluating abnormal conditions of indicators.
[0091] Second-level trigger:
[0092] The second-level trigger involves two layers of judgment. First, an initial risk value V needs to be obtained through preliminary assessment. pre The initial assessment of the security incident's status will guide the selection of the next steps.
[0093] Step 3: When the ship is in a closed state, calculate the preliminary risk value of the system.
[0094] The initial assessment uses Analytic Hierarchy Process (AHP) to assign indicator weights. Since the feedback frequency of each indicator data in the underwater system differs, data is output to the assessment system at different times. The assessment system converts the data into the risk level of each sub-indicator through the design of certain quantitative rules. Therefore, based on the quantitative indicator weights... Risk value of quantitative indicators Qualitative indicator weights Risk value of qualitative indicators And obtain the time window t n Risk level at any moment This allows us to obtain the risks of N sub-windows within a given time window, synthesize them, update them by sliding the window, and finally output the initial assessment result of system security.
[0095] Step 4: Determine the event status based on the preliminary risk value; the event status includes: critical event, critical event, and safety event.
[0096] Based on the preliminary risk value V pre Then, a second-level trigger determination is performed. In the first-level determination of this trigger, let the security event be T, and let the threshold of the security event be ε, according to V pre The security incident is then determined as follows:
[0097]
[0098] Step 5: When the event status is a safety event, determine the abnormality of the risk value of each indicator and obtain the judgment result; the indicators include: quantitative indicators and qualitative indicators.
[0099] Step 6: If the judgment result is abnormal, then proceed to step 13.
[0100] Step 7: If the judgment result is normal, output the risk value of each indicator.
[0101] Whether a security event should be dynamically and refined for assessment requires a second layer of refinement. This second layer of refinement is triggered by situations identified as security events in the first layer. If an underwater system experiences a small-scale attack or an attack in its initial stage, before significant risks are apparent, and most indicators across different dimensions show normal risk levels with only a few exhibiting abnormalities, the initial risk assessment may indicate a security event. Therefore, to ensure predictability and sensitivity in the assessment, and to anticipate potential risks, the second layer of refinement introduces the rate of change of risk levels to trigger the security assessment. This involves monitoring for anomalies in the risk levels of each indicator; if any indicator shows a significant anomaly, a dynamic assessment coupled with potential risks is immediately initiated, refining the monitoring and evaluation of system security. In determining anomalies in risk levels during security events, the concept of standard deviation is introduced to quantify changes in risk levels. Mathematically, standard deviation is a statistic that measures the dispersion of data; it reflects the deviation between data values and the mean, and is the square root of the variance. In this step, we need to measure whether the current risk value is abnormal relative to the normal risk value. Therefore, we can use the standard deviation to quantify the dispersion of the risk value of the indicator. For each indicator, we collect historical data of the underwater system under safe conditions and quantify it using the quantification rules mentioned earlier. This will allow us to obtain the stable dispersion of the risk value of each indicator under safe conditions.
[0102] For quantitative indicators, a series of M historical risk data points are collected under safe conditions. The historical risk level of indicator i at the m-th time point is: If i = 1, 2, ..., 8; m = 1, 2, ..., M, then the average risk value over these M historical moments is... Calculate the standard deviation of risk values under safe conditions. Given that the risk value of index i at time n is... The anomaly detection formula is:
[0103]
[0104] That is, when the ratio is greater than 2, the risk value of the indicator at the current moment can be considered abnormal compared to the safe state; when the ratio is less than 2, the risk value at the current moment is considered normal. If the risk value of any indicator is abnormal, an abnormal indicator is selected and coupled with potential risks, and then a dynamic assessment based on risk information is triggered. If normal, the initial risk assessment V is directly output. pre The qualitative indicators are handled in the same way as above in the second level of detailed judgment in this section.
[0105] Step 8: When the event status is a critical event or a critical event, proceed to step 13.
[0106] The abnormal indicators selected in the dynamic adjustment of identified serious and critical events are coupled with potential risks, and then dynamic assessments are carried out based on risk information.
[0107] Level 3 trigger:
[0108] Compared to the triggers in the first two levels of dynamic assessment, the third level trigger is a reassessment trigger following the dynamic assessment. First, it determines whether a potential risk exists based on anomaly indicators coupled with information about potential risks. If no risk exists, a risk value is directly output. If a risk exists, targeted defensive measures are implemented based on the potential risk. For DoS attacks, measures such as traffic filtering, load balancing, and limiting the number of connections can be used. For latency attacks, measures such as limiting timeout periods and setting up redundant backup transmission links can be used. For injection attacks, measures such as data filtering and authentication can be used. Then, the second level trigger begins a re-triggering process to verify the accuracy of the assessment.
[0109] Potential risks of abnormal indicator coupling
[0110] The section on coupling potential risks with abnormal indicators aims to predict potential risks through some abnormal indicators, thereby improving the sensitivity and real-time nature of security assessments. As shown in Table 2, the indicator categories for potential risks have been defined. The technology in this section mainly includes three steps: determining the abnormal threshold of the indicator, confirming the potential risk indicator category to which the abnormal indicator belongs, and adjusting the risk level of indicators in the same indicator category. See steps 9-12 for details.
[0111] Step 9: Determine the risk level abnormality threshold based on the risk value of each indicator.
[0112] The first step is to determine the risk level anomaly threshold for each sub-indicator within each risk indicator category to identify potential risks. For each quantitative indicator, risk level data over a historical period is collected, and its average risk level v is calculated. i,avg and the standard deviation of risk v i,std Furthermore, the average risk level and the standard deviation of risk level are used to set the risk anomaly threshold ε for the quantitative indicator i. i =v i,avg +βv i,std β is a user-defined multiplier used to adjust the sensitivity of the anomaly threshold. It represents the risk level of indicator i at the current time. Greater than the threshold ε i If the indicator is not found, it is considered an abnormal indicator.
[0113] Step 10: When the risk level of an indicator is greater than the abnormal risk level threshold, it is determined to be an abnormal indicator, and the process proceeds to step 13.
[0114] Step 11: Determine the potential risk indicator class of the abnormal indicator based on the abnormal risk threshold.
[0115] The second step is to identify the category of potential risk indicators to which the abnormal indicators belong, and then match the abnormal indicator i with W. 1 W 2 W 3 The three potential risk indicator categories are used to determine the category to which the abnormal indicator belongs.
[0116] Step 12: Adjust the risk level of indicators in the same indicator class based on the potential risk indicator class to obtain the updated risk level of the indicators.
[0117] The third step is to adjust the risk level of indicators within the same indicator category. After confirming the potential risk indicator category to which the abnormal indicator belongs, the risk level of indicators within the same indicator category is adjusted. In this step, the risk level of abnormal indicator i must first be checked. Is it the maximum value in the indicator class? If it is not the maximum value, then adjust other indicators according to the indicator with the maximum value. If it is the maximum value, then continue to adjust other indicators according to indicator i.
[0118] Setting Indicators This represents an indicator of the same class as indicator i, and the indicator is set based on the concept of linear interpolation. The correlation coefficient with respect to index j is α∈{0.6,0.8,1}. Here, α values of 0.6, 0.8, and 1 represent relatively strong correlation, strong correlation, and very strong correlation, respectively. Furthermore, the indicators... The risk level is set as follows:
[0119]
[0120] After this step, the risk information of the indicator at the current time n has a certain ability to predict risk. The adjusted indicator risk information is output to the dynamic reassessment based on the risk information, and the accurate risk value is obtained through dynamic assessment.
[0121] Dynamic reassessment based on risk information
[0122] The dynamic nature of the reassessment is addressed primarily through two dimensions: weighting and time. In terms of weighting, the risk level is quantified using the concept of information entropy, and the weights of the indicators are dynamically adjusted to achieve dynamic weighting. In terms of time, a sliding window mechanism-based dynamic assessment is implemented by dynamically adjusting the number of time windows.
[0123] In underwater systems, the network environment is complex and ever-changing, and the risk levels of sub-indicators across different dimensions of the system also change at different times. Therefore, to achieve dynamic adjustment of weights, we consider introducing the risk level information entropy of the indicators into the weighted indicators.
[0124] Common methods for calculating weights using information entropy rely on subjective judgment. This involves classifying each indicator based on subjective experience, calculating the information entropy of those probabilities, and then assigning weights by comparing the magnitudes of the information entropy between indicators. This method, however, does not rely on subjective judgment and aims to improve upon this entropy-weighting approach. The risk assessment indicator system for underwater systems comprises 22 indicators: 8 quantitative and 14 qualitative. For this indicator system, a sub-indicator with a high risk level is considered to have a large amount of information and requires priority assessment at the current time; therefore, its weight should be higher than its initial weight.
[0125] Therefore, after uniformly quantifying the risk level of all indicators in the indicator system, a constant is added to the information entropy formula. This makes the indicators with higher risk levels more important, and thus...
[0126]
[0127] Step 13: Calculate the weights of quantitative indicators using information entropy.
[0128] The quantitative indicator i at the current time is adjusted using the weight of information entropy.
[0129] Step 14: Calculate the qualitative indicators using the weights of information entropy.
[0130] Qualitative index j is adjusted using the weight of information entropy.
[0131] Step 15: Calculate the initial weights of the quantitative indicators using the weights of information entropy based on the quantitative indicators.
[0132] Let γ represent the importance of the initial weights, γ∈[0,1], then the initial weights of quantitative index i are... The adjustments are as follows:
[0133] Step 16: Calculate the initial weights of the qualitative indicators using the weights of information entropy based on the qualitative indicators.
[0134] Qualitative index j initial weight The adjustments are as follows:
[0135] Step 17: Calculate the risk level at the current time n based on the initial weights of the quantitative indicators and the initial weights of the qualitative indicators.
[0136] The risk level of n at the current time is adjusted to
[0137] Step 18: Dynamically adjust the number of time windows.
[0138] For time window mechanisms, conventional time windows are fixed, but fixed time windows make it difficult to capture network risk posture and achieve more accurate assessments. This mechanism aims to dynamically change the number of sub-time windows within a sliding time window based on changes in network posture, achieving a second dimension of dynamic assessment, enabling network security assessment values to capture network risk posture. The dynamic adjustment here is based on an initial number of sub-time windows N. For each time window, the comprehensive risk value of the sub-time windows within that time window is calculated using the method described above. The comprehensive risk value of the previous time window is compared with that of the current time window. If the comprehensive risk value of the current time window is larger, it indicates a high level of recent network risk, so the number of sub-time windows is reduced, making assessments more frequent and focused on current risk values. If the comprehensive risk value of the current time window is smaller, it indicates a relatively safe network posture in the short term, so the number of sub-time windows is increased to consider risk values over a longer period. If the comprehensive risk value of the previous time window is similar to that of the current time window, the number of sub-time windows remains unchanged.
[0139] Based on this dynamic thinking, a suitable dynamic function is selected for quantization. Since the sigmoid function's characteristics align with this dynamic thinking, mapping the input to the range [0,1], and by transforming changes in risk into a factor between 0 and 1, the number of sub-time windows can be smoothly adjusted within the time window. Therefore, we consider constructing a dynamic function based on the sigmoid function to add or reduce sub-time windows, i.e.:
[0140]
[0141] ΔN represents the number of sub-time windows that need to be dynamically increased or decreased after calculation, rounded down. N is the number of sub-time windows in the current time window, ΔV is the difference between the risk value of the previous time window and the risk value of the current time window, and k is the control factor. When ΔV is large, the function output is closer to 0.5N, which represents the maximum increase in the number of sub-time windows. If ΔV is small, the function output is closer to -0.5N, which represents the maximum decrease in the number of sub-time windows. If ΔV is close to 0, the function output is close to 0, which keeps the number of sub-time windows essentially unchanged. The new time window is then N′=N+ΔN.
[0142] Step 19: Calculate the final risk level based on the adjusted number of time windows and the risk level at the current time n.
[0143] Therefore, the risk level calculated by the dynamic evaluation algorithm is:
[0144] In summary, this invention proposes a dynamic safety assessment mechanism for underwater systems. By designing a dynamic assessment mechanism that fits the underwater system, a comprehensive assessment of the underwater system can be achieved. Furthermore, by coupling potential risks with abnormal indicators, the assessment mechanism has a certain ability to cope with risks, and dynamic assessment is achieved in both time and weight dimensions.
[0145] In the established simulated underwater system, quantitative indicator information is collected and calculated using tools such as timestamps and Wireshark, while qualitative indicator information is obtained through observation and judgment. This invention verifies the proposed dynamic re-evaluation method by setting up a static evaluation scheme for comparison, and ultimately validates the proposed dynamic evaluation mechanism. In the static evaluation scheme, the analytic hierarchy process (AHP) is used to calculate the indicator weights, and the evaluation time window is fixed at 6. The performance simulation comparison graph is shown below. Figures 3-6 As shown:
[0146] Figure 3 To experimentally verify the effectiveness of the designed dynamic weight adjustment, four different intensities of DoS attacks were sent to the underwater system, resulting in four sets of indicator risk data under the DoS attacks. The dynamic weights were calculated using the dynamic weight adjustment algorithm designed in this invention, and the risk results calculated under static and dynamic weights were compared. Similarly, the risk results under delay attacks and injection attacks were calculated and compared under static and dynamic weights. The attack intensity was set to the highest in Experiment 1, very high in Experiment 2, relatively high in Experiment 3, and low in Experiment 4. The results are as follows: Figure 3 As shown, the risk assessment results of dynamic weights under each type of attack are higher than those of static weights, thus verifying the sensitivity and effectiveness of the weight adjustment algorithm.
[0147] Figure 4 and Figure 5 To experimentally validate the designed sliding time window mechanism, we verified it from two perspectives: rationality and effectiveness. Specifically, we tested whether the sliding time window mechanism is consistent with the fixed time window mechanism under continuous risk conditions, and whether it is more sensitive and effective than the fixed time window mechanism under mutation risk conditions.
[0148] Figure 4To verify the rationality of the experimental verification mechanism, two environments were set up: a continuously high-risk network environment and a continuously low-risk environment. The continuously high-risk network environment attacked all domains of the system through DoS attacks, latency attacks, and injection attacks. After determining the weights of the indicators using AHP, indicator data for 72 time sub-nodes were collected, with an interval of 5 seconds between the time sub-nodes. The initial time window was set to N=6. The two environments were evaluated using a fixed time window mechanism and a sliding time window mechanism, respectively. Figure 4 It can be seen that the evaluation effects of the two mechanisms are basically the same in both sustained high-risk and sustained low-risk environments. This verifies that the dynamic time window mechanism is reasonable in sustained risk environments.
[0149] Figure 5 The experiment verifies the effectiveness of the mechanism, specifically whether it can achieve timely assessment by adjusting the time window when facing sudden risks. Six sub-experiments were set up. After determining the weights using AHP (Adaptive Hierarchy Process), metric data for 12 time sub-nodes were collected in each sub-experiment. The interval between time sub-nodes was 5 seconds, and the initial time window N=6 was set. DoS attack, latency attack, and injection attack were sequentially applied to a portion of the time sub-nodes in two sub-experiments. Two mechanisms were used to evaluate each sub-experiment. Each node in the figure below represents the evaluation effect of the time window containing the attacked node in each sub-experiment. Figure 5 It is evident that the sliding time window mechanism has a significant advantage in detecting sudden risks. While a fixed time window mechanism may not be able to detect and determine danger immediately, the sliding time window mechanism can detect risks by adjusting the time window in a timely manner.
[0150] Figure 6 This study aims to comprehensively verify the dynamic mechanism. The experiment involved setting up 14 attacks—DoS, latency, and injection—on an underwater system and implementing corresponding defensive measures to simulate the dynamic and ever-changing network situation. The dynamic technology was used to evaluate the underwater system in both secure and insecure states during this phase. The results were compared with the classic static evaluation technique (the initial evaluation method presented in this paper) to preliminarily verify the rationality and effectiveness of the dynamic mechanism. The experimental results show that in the insecure state, the dynamic mechanism is more effective and sensitive in risk detection than the static evaluation technique. In the secure state, the evaluation results of the dynamic and static evaluation techniques are similar and largely consistent, indicating that the dynamic evaluation mechanism is more sensitive and effective in assessing dynamic and ever-changing network situations.
[0151] In summary, this invention designs a dynamic assessment mechanism for underwater systems, employing a three-level assessment triggering mechanism to progressively refine the accuracy of safety risk perception. It also proposes a method for dynamically adjusting real-time indicator weights and assessment time windows throughout the entire safety risk perception process. Furthermore, if the assessment results do not converge, a closed-loop feedback mechanism based on post-assessment is designed to reassess the risk management results, ensuring the assessment mechanism's ability to adapt and optimize in response to changing risk situations.
[0152] This invention proposes a multi-level perception triggering system that includes three levels of assessment triggering, enabling different levels of safety risk classification and judgment for underwater systems, and providing feedback and reprocessing capabilities for risks.
[0153] This invention proposes a dynamic assessment adjustment that includes anomaly indicators coupled with potential risks and dynamic reassessment based on risk level information. It has a certain ability to predict and handle risks, and will dynamically adjust weights and time windows according to the risk situation.
[0154] Example 2
[0155] A computer device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the dynamic safety assessment method for underwater systems in Embodiment 1.
[0156] Example 3
[0157] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the dynamic safety assessment method for underwater systems in Embodiment 1.
[0158] Example 4
[0159] A computer program product includes a computer program that, when executed by a processor, implements the steps of the dynamic safety assessment method for underwater systems in Embodiment 1.
[0160] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided by this invention can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided by this invention may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided by this invention may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0161] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0162] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. Furthermore, those skilled in the art will recognize that, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A dynamic safety assessment method for underwater systems, characterized in that, include: Step 1: Determine the ship's current status; The state of the ship includes: a closed state and an open state; Step 2: If the ship is in a non-sealed state, proceed to step 5; Step 3: When the ship is in a closed state, calculate the preliminary risk value of the system; Step 4: Determine the event status based on the preliminary risk value; the event status includes: critical event, critical event, and safety event; Step 5: When the event status is a safety event, determine the abnormality of the risk value of each indicator and obtain the judgment result; the indicators include: quantitative indicators and qualitative indicators; Step 6: If the judgment result is abnormal, then proceed to step 13; Step 7: If the judgment result is normal, output the risk value of each indicator; Step 8: If the event status is a critical event or a critical event, then proceed to step 13; Step 9: Determine the abnormal risk threshold based on the risk value of each indicator; Step 10: When the risk level of an indicator is greater than the abnormal risk level threshold, it is determined to be an abnormal indicator, and the process proceeds to step 13. Step 11: Determine the potential risk indicator class of the abnormal indicator based on the aforementioned risk level anomaly threshold; Step 12: Adjust the risk level of indicators in the same indicator class based on the potential risk indicator class to obtain the updated risk level of the indicators; Step 13: Calculate the weights of quantitative indicators using information entropy; Step 14: Calculate the weights of qualitative indicators using information entropy; Step 15: Calculate the initial weights of the quantitative indicators using the weights of information entropy based on the quantitative indicators; Step 16: Calculate the initial weights of the qualitative indicators based on the information entropy weights; Step 17: Calculate the risk level at the current time n based on the initial weights of the quantitative indicators and the initial weights of the qualitative indicators; Step 18: Dynamically adjust the number of time windows; Step 19: Calculate the final risk level based on the adjusted number of time windows and the risk level at the current time n.
2. The dynamic safety assessment method for underwater systems according to claim 1, characterized in that, In step 3, the preliminary risk value of the system is calculated using the following formula: in, Indicates time window t n The level of risk at any moment Indicates the weight of quantitative indicators. This represents the risk value of a quantitative indicator. Indicates the weight of qualitative indicators. This represents the risk value of a qualitative indicator, and N represents the N moments in the time window.
3. The dynamic safety assessment method for underwater systems according to claim 1, characterized in that, The event status is determined based on the preliminary risk value using the following formula: Where ε represents the threshold for security events, V pre This indicates the preliminary risk value.
4. The dynamic safety assessment method for underwater systems according to claim 1, characterized in that, In step 5, the abnormality of the risk value of each indicator is determined, and the determination result is obtained using the following formula: in, Let the historical risk level of index i at time m be denoted as i = 1, 2, ..., 8; m = 1, 2, ..., M. This represents the average risk value over M historical moments. This represents the risk value of indicator i at the current time n.
5. The dynamic safety assessment method for underwater systems according to claim 1, characterized in that, The expression for the risk level of the updated indicator in step 12 is as follows: in, Indicators The correlation coefficient for index j is α∈{0.6,0.8,1}. This represents the risk value of indicator i at the current time n.
6. The dynamic safety assessment method for underwater systems according to claim 1, characterized in that, The expression for the risk level at the current time n in step 17 is as follows: in, This represents the initial weight of quantitative index i. This represents the initial weight of qualitative index j. This represents the risk value of quantitative indicator i at the current time n. This represents the risk value of the qualitative indicator j at the current time n.
7. The dynamic safety assessment method for underwater systems according to claim 6, characterized in that, The final risk level in step 19 is expressed as follows: Where N' = N + ΔN, N is the number of sub-time windows of the current time window, ΔN is the number of time windows that need to be dynamically increased or decreased after calculation, k is the control factor, and e is a constant.
8. A computer device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor executes the computer program to implement the steps of the method according to any one of claims 1-7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1-7.
10. A computer program product, comprising a computer program, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method described in any one of claims 1-7.
Citation Information
Patent Citations
Risk assessment for industrial systems using big data
CN104142679A
Base station, user equipment and method for controlling quality of experience based on feedback of user equipment
CN107659955A