A system security analysis method, system, and device

By introducing time and accuracy assessment, expert scoring, and interval hesitant fuzzy set theory, the coupling variability of functional units in complex systems is quantified, potential accidents are identified and prevented, the problem of insufficient quantitative analysis in existing technologies is solved, and system security is improved.

CN118839340BActive Publication Date: 2025-12-12CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410799646.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-20
Publication Date
2025-12-12
Estimated Expiration
2044-06-20

AI Technical Summary

Technical Problem

Existing methods for analyzing the safety of complex systems rely on subjective expert assessments, lack quantitative analysis, and are unable to effectively identify resonant links between system functions, making it difficult to prevent potential accidents.

Method used

By introducing time and precision to evaluate the performance of each functional unit, using expert scoring and interval hesitant fuzzy set theory to calculate variability scores, combining association rule algorithms to quantify coupling variability, setting functional coupling variability thresholds to identify key units and setting barriers to prevent functional resonance.

Benefits of technology

It enables quantitative security analysis of complex systems, identifies key functional units, reduces the subjectivity of expert evaluation, improves system mission security, and prevents accidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118839340B_ABST
    Figure CN118839340B_ABST
Patent Text Reader

Abstract

The application discloses a kind of system security analysis method, system and equipment, method includes: system task is decomposed, each subtask is determined as the functional unit of the system;The performance of each functional unit is evaluated using time and precision, the output variability score of each functional unit is obtained by introducing expert score, then the potential coupling of each functional unit performance change is analyzed, and the functional coupling variability score of each functional unit is obtained in combination with the output variability score;Threshold value of functional coupling variability score is set, when exceeding the threshold value of functional coupling variability score, system will occur functional resonance, so as to identify the key functional unit in system, and set barrier for the key functional unit to prevent potential accidents from happening.The application fuses subjective and objective factors to analyze the safety of system, solves the technical problems that cannot give quantitative analysis results due to excessive dependence on expert subjective evaluation, and lacks theory or process to construct functional resonance.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the field of complex system analysis, and more particularly, to a system safety analysis method, system and device. BACKGROUND

[0002] Complex system safety analysis is a multidisciplinary and cross-field research direction, aiming to understand, predict, evaluate and ultimately reduce or control the safety risks that may occur in complex systems. The safety problem of complex equipment system has at least the following obvious characteristics or differences: first, the unsafe consequences of complex equipment system are more serious. Once a major accident occurs in the task due to safety hidden danger, the consequences are not only equipment damage, economic loss and personnel casualty, but also the loss of national and national strategic significance; second, the use environment of complex equipment system is more harsh, often needs to work normally in extreme weather, electromagnetic interference and other harsh service environment, which greatly increases the probability of equipment failure and brings challenges to safety evaluation; finally, the interaction relationship between the internal parts of complex equipment system is more. Due to the coupling effect of different safety item failure modes, it is difficult to quantitatively evaluate the safety. In summary, these unique characteristics and challenges of complex equipment system on safety problem require more comprehensive safety analysis method.

[0003] Currently, common safety analysis models include Hazard and operability study (HAZOP), Failure mode and effects analysis (FMEA), Event tree analysis (ETA), Fault tree analysis (FTA), Bow-tie model, etc. However, these accident causation models have limitations in analyzing safety problems of complex systems, and ignore the complex interactions between components in the system and potential risks that may be caused by the interactions. For a ship system with human-machine-environment coupling characteristics, a nonlinear system method should be used to deeply study the mutual influence between risk factors and determine the key factors affecting the safe operation of the system. The Functional resonance analysis method (FRAM) is a safety analysis method based on system causation theory and stochastic resonance theory. The method believes that an accident is usually caused by the coupling performance change between functions in the system exceeding the acceptable range of normal operation of the system. However, the existing FRAM method still has the following two deficiencies: first, in identifying the performance variation phenotype of system functions, it often relies on the experience of experts and has strong subjectivity and uncertainty, so there is a lack of a reasonable means to process evaluation information; second, in analyzing the coupling relationship between upstream and downstream functions, it cannot give the analysis results from a quantitative point of view, and this limitation brings great difficulty to identify resonance links.

[0004] Therefore, it is urgent to overcome the technical defects of the prior art. SUMMARY

[0005] In view of the above defects or improvement needs of the prior art, the present application provides a system safety analysis method, system and device, which aims to analyze the safety of the system by fusing subjective and objective factors, and solves the technical problems that the quantitative analysis results cannot be given due to excessive dependence on expert subjective evaluation, and there is a lack of theory or process to construct functional resonance.

[0006] To achieve the above object, according to one aspect of the present application, a system safety analysis method is provided, which comprises:

[0007] decomposing the system task, and determining each subtask as a functional unit of the system;

[0008] The performance of each functional unit is evaluated by time and precision, an expert score is introduced to obtain the output variability score of each functional unit, and the potential coupling of the performance variation of each functional unit is analyzed, and the output variability score is combined to obtain the functional coupling variability score of each functional unit.

[0009] A functional coupling variability score threshold is set, when the functional coupling variability score threshold is exceeded, the system will resonate, thereby identifying the key functional unit in the system, and setting a barrier for the key functional unit to prevent potential accidents.

[0010] As a further improvement and supplement to the above scheme, the present application also includes the following additional technical features.

[0011] Preferably, the method of decomposing the system task and determining each subtask as a functional unit of the system comprises:

[0012] The hierarchical task analysis method is used to decompose the system task, and the functional units of the system are described from input, output, time, control, resources and prerequisites, and the connection and interaction between each functional unit is analyzed and established.

[0013] Preferably, the method of evaluating the performance of each functional unit by time and precision comprises:

[0014] The performance of each functional unit is divided into four categories according to the degree of functional variability change, namely, too early, on time, too late and no occurrence; at the same time, the precision is divided into three categories, namely, accurate, acceptable and inaccurate.

[0015] Preferably, the method of introducing an expert score to obtain the output variability score of each functional unit comprises:

[0016] The expert is invited to score the time and precision variability probability of each functional unit respectively, and an interval value hesitant fuzzy set is constructed to obtain the evaluation value of the expert on the time variability and precision variability probability of each functional unit;

[0017] The interval value hesitant fuzzy set is aggregated using an interval hesitant fuzzy weighted average operator to obtain the decision benchmark of the variability probability of each functional unit;

[0018] The Euclidean distance and similarity between the interval value hesitant fuzzy set and the decision benchmark are used to determine the preference weight of the expert on each functional unit;

[0019] The variability score of each functional unit is calculated using the preference weight and the evaluation value of the expert on the time variability and precision variability probability of each functional unit.

[0020] Preferably, the method of analyzing the potential coupling of performance variation of each functional unit and combining the output variability score to obtain the functional coupling variability score of each functional unit comprises:

[0021] determining the influence relationship of upstream and downstream of each functional unit, and calculating the time coupling coefficient and the precision coupling coefficient of the upstream and downstream functional output variation according to the promotion degree, and combining the output variability score to quantify the coupling variability of each functional unit;

[0022] The promotion degree is the promotion degree of the probability of functional variation of the downstream functional unit if the upstream functional unit has functional variation.

[0023] Preferably, the method of calculating the time coupling coefficient and the precision coupling coefficient of the upstream and downstream functional output variation according to the promotion degree comprises:

[0024] Converting the historical accident investigation report into a Boolean matrix of functional unit variation information to confirm whether the time or precision changes in the accident;

[0025] The Boolean matrix is used as an accident data set to collect the case where the upstream functional unit has variation and the downstream functional unit also has variation;

[0026] The promotion degree of time and precision is obtained respectively, and the upstream and downstream functional coupling variability score is calculated.

[0027] Preferably, when the promotion degree is greater than 1, it indicates that the upstream and downstream functional coupling variability has an amplification effect; when the promotion degree is less than 1, it indicates that the upstream and downstream functional coupling variability has a damping effect; and when the promotion degree is equal to 1, it indicates that the upstream functional output has no influence on the downstream functional output.

[0028] Preferably, the barrier set for the key functional unit comprises:

[0029] Setting physical barriers, functional barriers, symbolic barriers and intangible barriers.

[0030] According to another aspect of the present application, a system for system safety analysis is provided, and the system comprises:

[0031] A decomposition module is configured to decompose system tasks, and the decomposition module determines each subtask as a functional unit of the system;

[0032] A scoring module is configured to evaluate the performance of each functional unit by using time and precision, introduce expert scoring to obtain the output variability score of each functional unit, analyze the potential coupling of performance variation of each functional unit, and combine the output variability score to obtain the functional coupling variability score of each functional unit;

[0033] a judging module, configured to set a functional coupling variability score threshold, when the functional coupling variability score threshold is exceeded, the system will have functional resonance, so as to identify the key functional unit in the system;

[0034] a barrier module, configured to set a barrier for the key functional unit, so as to prevent potential accidents.

[0035] According to another aspect of the present application, a device for system safety analysis is provided, the device comprising:

[0036] one or more processors;

[0037] a storage device, configured to store one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the system safety analysis method as described above.

[0038] Overall, compared with the prior art, the above technical solutions conceived by the present application have the following beneficial effects:

[0039] The system safety analysis method provided by the present application quantifies the variability of functions and couplings by using subjective expert experience and objective accident data, introduces interval hesitant fuzzy weighted average operators and Euclidean distances in interval hesitant fuzzy set theory, reduces the experience difference when experts evaluate the variability of functions, at the same time, uses the lift in the association rule algorithm as the coupling coefficient of the variability of upstream and downstream functions, so as to more objectively describe the mutual influence between each functional unit, at the same time, can analyze the potential risks of the system in the process of executing tasks, identify the weak links in the system, so as to improve the task safety of the system and prevent accidents. BRIEF DESCRIPTION OF DRAWINGS

[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0041] Figure 1 is a system safety analysis method flowchart provided by embodiment one;

[0042] Figure 2 is a schematic diagram of the overall structure of a submarine combat system and the relationship between each subsystem in embodiment one;

[0043] Figure 3 is a schematic diagram of using hierarchical task decomposition to analyze a submarine open-sea training task in embodiment one;

[0044] Figure 4is a schematic diagram of a FRAM function network of a submarine long-range training task in embodiment one;

[0045] Figure 5 is a schematic diagram of a function resonance coupling result in embodiment one;

[0046] Figure 6 is a schematic diagram of a resonance link prone to accidents in a submarine training task in embodiment one;

[0047] Figure 7 is a schematic diagram of a system security analysis system provided in embodiment two;

[0048] Figure 8 is a schematic diagram of a system security analysis device provided in embodiment three. DETAILED DESCRIPTION

[0049] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application. In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as they do not conflict with each other.

[0050] Embodiment one

[0051] Although FRAM has been widely used in safety analysis in the fields of aviation, maritime, railway transportation, construction and the like, its application in ship task safety is still less.

[0052] The system security analysis method of the present application will be further described in detail below with reference to a specific example of a certain submarine.

[0053] A system security analysis method, the method comprising the following processes, as shown in Figure 1

[0054] S101: decompose the system task, and determine each subtask as a function unit of the system.

[0055] A security analysis is performed on a long-range training task of a certain submarine. The subject content of the training is continuous attack of a single submarine on multiple sea surface targets. The combat system of the submarine includes an information system, a command and control system, a weapon system and a communication network system. Figure 2 The overall structure of the submarine combat system and the relationship between the subsystems are shown. The submarine long-range training task can be subdivided into multiple subtasks, and the hierarchical task analysis method (HTA) is used for disassembly analysis, and the result is shown in Figure 3 .​

[0056] Ten typical subtasks of submarine long-range training are identified by HTA, which are not executed in a fixed order, but are flexibly interleaved in the same task profile. Each subtask is determined as a functional unit of the system, including checking equipment (F1), diving (F2), steering travel (F3), target identification (F4), environment perception (F5), information fusion (F6), communication (F7), command (F8), checking weapons (F9), and launching weapons (F10). These functional units are not simply connected in series, but interact in the form of input and output, together forming a functional network of submarine long-range training tasks. The FRAM functional network diagram of submarine long-range training tasks is shown in FIG. 1. Figure 4

[0057] S102: The performance of each functional unit is evaluated using time and precision, expert scores are introduced to obtain the output variability scores of each functional unit, and the potential coupling of the performance changes of each functional unit is analyzed to obtain the functional coupling variability scores of each functional unit.

[0058] Two phenotypes, time and precision, are used to describe the performance changes of the functional units. Time is divided into four categories: too early, on time, too late, and not occurring, and precision is divided into three categories: accurate, acceptable, and inaccurate. Experts are invited to score the likelihood of time and precision changes for each functional unit, with a score range of 0.00-1.00 and a fluctuation interval of no more than 0.20. The output variability of each functional unit is calculated using the interval hesitant fuzzy weighted average operator and the Euclidean distance.

[0059] Time and precision are used as the phenotypes of the upstream function output. Time includes four levels: on time, too early, too late, and not occurring, and precision includes three levels: accurate, acceptable, and inaccurate. The language of the above functional variability is converted into specific scores, as shown in Table 1. Five experts with rich experience in submarine design are invited to evaluate the output variability of each functional unit. These experts score the range of time and precision changes, as shown in Table 2 for F2 "Diving". The expert weight values are calculated using the interval hesitant fuzzy weighted average operator IVHFWA and the Euclidean distance, and the output variability scores of each function are obtained, as shown in Table 3.

[0060] Table 1 Variability scores of function output

[0061]

[0062] Table 2 Expert interval score results (F2 is taken as an example)

[0063]

[0064]

[0065] Variability scores of each function in Table 3

[0066]

[0067] S103: Set a function coupling variability score threshold, when the function coupling variability score exceeds the threshold, the system will resonate, thereby identifying the key functional units in the system, setting barriers for the key functional units to prevent potential accidents.

[0068] In this embodiment, the FP-Growth algorithm is used to determine the influence relationship between upstream and downstream functions, and the time coupling coefficient and precision coupling coefficient of the output change of upstream and downstream functions are calculated according to the lift, thereby quantifying the coupling variability between functions.

[0069] From a variety of channels, including but not limited to official accident reports, academic journals, network materials, etc., 89 submarine accident cases from 1938 to 2023 were widely collected. Then the FP-Growth algorithm was used to mine the internal relationship between upstream and downstream function changes, and the minimum support threshold was set to 0.06 and the minimum confidence threshold was set to 0.3. The item set that meets the above two requirements is selected as the frequent item set, and the coupling coefficient between upstream and downstream functions is calculated using the lift and As shown in Table 4.

[0070] Table 4 Coupling coefficients of upstream and downstream function output changes

[0071]

[0072]

[0073] (5) Analyze the function resonance coupling results. According to the variability score of the upstream function and the coupling coefficient between the upstream and downstream functions, the coupling variability score of the upstream and downstream functions is calculated and plotted into a bar chart, as shown in Figure 5 The threshold is set to 10, and when the coupling variability score of the upstream and downstream functions exceeds the threshold, it is considered that there is function resonance. From Figure 5 it can be found that F3 "steering driving", F4 "target recognition", F5 "environment perception", F6 "intelligence fusion" and F8 "command" resonate, in addition, 2 resonance links are observed: F3→F4→F6→F8 and F5→F6→F8, the performance changes of the functions on these links may trigger submarine accidents.

[0074] (6) In-depth analysis and monitoring of key functions and links of the system. Figure 6 The resonance link that easily causes accidents in the submarine training task is shown. From Figure 6 It can be seen from the figure that there are five key functions in the system, which are F3 "steering driving", F4 "target recognition", F5 "environment perception", F6 "intelligence fusion" and F8 "command". When the submarine is maneuvering underwater, it is easy to produce roll when encountering cross waves, and it may produce pitch when encountering head waves. If the reaction of the driver is slow or the steering is wrong, the submarine may deviate from the route, causing the sonar and other detection devices to be unable to accurately obtain the target position, increasing the risk of collision with other ships or underwater obstacles, so the function resonance may occur between F3 and F4. In addition, if the chart data is not updated in time or the surrounding environment is not fully understood, the intelligence processed by the crew may have problems of insufficient accuracy and reliability, causing the route planning to be wrong, increasing the risk of collision and grounding accidents, so the function resonance may occur between F5 and F6. In addition, when identifying targets, due to the failure of radar, infrared, photoelectric, sonar, ESM and other sensors or the limited detection distance, the intelligence center may make mistakes when processing information fusion, forming an unsafe track, so the function resonance may occur between F4 and F6. The intelligence information received by the submarine may come from multiple sensors and data sources, which needs to be comprehensively processed to establish a comprehensive situation awareness. However, the technical errors of intelligence personnel or the insufficient communication with the command department will affect the command decision, which may cause the submarine to enter dangerous waters or cause a mine accident, so the function resonance may occur between F6 and F8.

[0075] Among the five key functions, F3 and F5 have a root influence on the safety of the submarine and may be the potential source of accidents. Historical experience shows that collision is one of the types of submarine accidents that occur most frequently, and the main reason is that the hydrological information guarantee is insufficient and the driver's reaction to the surrounding situation is not timely, which verifies the effectiveness of the present application. Therefore, F3 and F5 need to be monitored and corresponding barrier measures need to be taken to suppress their performance fluctuations. For example, for F3, intelligent auxiliary systems such as automatic steering system and centralized control system can be introduced as physical barriers; artificial intelligence algorithms such as path planning and dynamic obstacle avoidance can be used to maintain stable navigation as functional barriers; a yaw warning system can be designed to assist the driver to correct the deviation of the heading as a symbolic barrier; the driver is encouraged to participate in simulation drills and actual emergency disposal drills to improve the steering ability and response ability as intangible barriers. For F5, advanced radar systems can be introduced to monitor the surrounding waters as physical barriers; an environment big data center can be established and the chart surveying and mapping work can be improved as functional barriers.

[0076] F6 is connected to the most resonance links and is greatly affected by the output of upstream functions, so the performance fluctuation is easy to gather at this function unit. In order to prevent accidents, corresponding barrier measures must be taken. A strict intelligence screening and verification mechanism can be established as a physical barrier; the communication between intelligence personnel and the command department is strengthened as a functional barrier; the interface of the intelligence display console is optimized to improve the cognitive efficiency of the intelligence personnel on the situation as a symbolic barrier; and the skill training and safety awareness training of the intelligence personnel are carried out regularly as an invisible barrier.

[0077] In order to further verify the superiority of the improved FRAM method designed in the patent in analyzing system safety problems, it is compared with FTA, FMEA, Bow-tie, system-theoretic process analysis (STPA) and other methods, as shown in Table 5.

[0078] Table 5 Comprehensive comparison of different safety analysis methods

[0079]

[0080]

[0081] In combination with the embodiment of the application, there is also a preferred implementation scheme, specifically, the method for decomposing the system task and determining each subtask as a functional unit of the system comprises:

[0082] The hierarchical task analysis method is used to decompose the system task, describe the functional unit of the system from input, output, time, control, resource and premise, analyze and establish the connection and interaction relationship between each functional unit.

[0083] In the first embodiment, the HTA method is used to identify the functional unit in the FRAM model, and the task is decomposed into each operation or activity that the system needs to complete. These operations or activities are presented in the form of a hierarchical structure, thereby helping to understand the task characteristics and process of the system.

[0084] In the first embodiment, the "six-angle model of function" is used to comprehensively describe each function. The model covers six dimensions: input (I), output (O), time (T), control (C), resource (R) and premise (P). The interaction relationship of each function in the six dimensions is analyzed, the potential association chain between functions is identified, and a system function network diagram is established, so as to realize the visualization of the system safety analysis process.

[0085] In combination with the embodiment of the application, there is also a preferred implementation scheme, specifically, the method for evaluating the performance of each functional unit by using time and precision comprises:

[0086] The performance of each functional unit is divided into four types of early, on time, late and not occurring according to the degree of functional variability, and the accuracy is divided into three types of accurate, acceptable and inaccurate.

[0087] The performance of each functional unit is divided into four types of early, on time, late and not occurring according to the degree of functional variability, and the accuracy is divided into three types of accurate, acceptable and inaccurate.

[0088] In combination with the embodiments of the present application, there is also a preferred implementation scheme, specifically, the method for introducing expert scores to obtain the output variability scores of each functional unit comprises:

[0089] The interval score of the time and accuracy variability probability of each functional unit is invited to an expert to form an interval value hesitant fuzzy set, and the evaluation value of the time variability and accuracy variability probability of each functional unit is obtained;

[0090] The interval value hesitant fuzzy set is aggregated by using an interval hesitant fuzzy weighted average operator to obtain the decision benchmark of the variability probability of each functional unit;

[0091] The preference weight of the expert for each functional unit is determined through the Euclidean distance and similarity between the interval value hesitant fuzzy set and the decision benchmark;

[0092] The variability score of each functional unit is calculated by using the preference weight and the evaluation value of the time variability and accuracy variability probability of each functional unit.

[0093] The calculation steps of the functional variability based on the interval hesitant fuzzy set theory are as follows:

[0094] (1) The interval score of the functional i of the kth expert is obtained, and the interval hesitant fuzzy elements on the four time variability levels and the three accuracy variability levels are obtained:

[0095]

[0096] Wherein, and are the interval left scores of the kth expert on the time and accuracy variability probability of the functional i, and are the interval right scores of the kth expert on the time and accuracy variability probability of the functional i, t is the time variability level number, and p is the accuracy variability level number.

[0097] The set of variation probability scores of each expert on function i constitutes an interval-valued hesitant fuzzy set h k (i).

[0098] (2) Calculate the score function of interval-valued hesitant fuzzy element:

[0099]

[0100] (3) Calculate the decision criteria h mean (i) by interval-valued hesitant fuzzy weighted average operator (IVHFWA) operator

[0101]

[0102] where, is the mapping function of h , w = (w1, w2, …, w k ) T is the weight vector of h .

[0103] All expert weights are considered equal, i.e. Use the IVHFWA operator to aggregate the score set h k (i) of all experts (k = 1, 2, …, l) to obtain the decision criteria h mean (i) of the variation probability of function i, i.e.:

[0104] h mean (i) = f IVHFWA (h1(i), h2(i), …, h l (i))

[0105] (4) Determine the weight of the preference information of the experts on function i by calculating the Euclidean distance and similarity between the score of each expert on the variation probability of function i and the decision criteria h mean (i). The expression of Euclidean distance is:

[0106]

[0107] where d(i) is the Euclidean distance between the score set h k (i) of the kth expert and the decision criteria h mean (i), and n represents the number of evaluation variation levels, which is 7.

[0108] Similarity reflects the degree of the expert's grasp of the possibility of the variation range of function i. The expression of similarity is:

[0109] s(i) = 1 - d(i)

[0110] Calculate the weight of the expert according to the similarity

[0111]

[0112] (5) Based on the weight obtained by the above method, the variability score B of function i can be calculated i :

[0113]

[0114] Wherein, is the weight of the kth expert on the score of function i, and respectively, and β t and β p are the scores of time and accuracy.

[0115] In combination with the embodiments of the application, there is also a preferred implementation scheme, specifically, the method for analyzing the potential coupling of the performance changes of each functional unit and obtaining the functional coupling variability score of each functional unit in combination with the output variability score comprises:

[0116] Determine the influence relationship of upstream and downstream of each functional unit, and calculate the time coupling coefficient and accuracy coupling coefficient of the output change of upstream and downstream functions according to the promotion degree, and quantify the coupling variability of each functional unit in combination with the output variability score;

[0117] The promotion degree is the promotion degree of the probability of the functional variation of the downstream functional unit if the functional variation of the upstream functional unit occurs.

[0118] In combination with the embodiments of the application, there is also a preferred implementation scheme, specifically, the method for calculating the time coupling coefficient and accuracy coupling coefficient of the output change of upstream and downstream functions according to the promotion degree comprises:

[0119] Convert the historical accident investigation report into a Boolean matrix of functional unit variability information, and confirm whether the time or accuracy changes in the accident;

[0120] Make the Boolean matrix an accident data set, collect the case where the upstream functional unit has a variation and the downstream functional unit also has a variation;

[0121] Respectively obtain the promotion degree of time and accuracy, and calculate the coupling variability score of upstream and downstream functions.

[0122] In combination with the embodiments of the present application, there is also a preferred implementation scheme, specifically, when the promotion degree is greater than 1, it indicates that there is an amplification effect of upstream and downstream functional coupling variability; when the promotion degree is less than 1, it indicates that there is a damping effect of upstream and downstream functional coupling variability; when the promotion degree is equal to 1, it indicates that the upstream function output has no effect on the downstream function output.

[0123] In the first embodiment, the FP-Growth algorithm is used to determine the influence relationship between upstream and downstream functions, and the time coupling coefficient and the precision coupling coefficient of the upstream and downstream function output change are calculated according to the promotion degree, so as to quantify the coupling variability between functions. The coupling variability calculation steps based on association rule mining are as follows:

[0124] (1) Convert the historical accident investigation report into a Boolean matrix T of functional variability information f :

[0125]

[0126] Wherein, f is the total number of functions. t 1i in the matrix indicates whether the function i changes in time in the accident, t 2i indicates whether the function i changes in accuracy in the accident. If it changes, it is recorded as 1; otherwise, it is recorded as 0.

[0127] (2) Take the Boolean matrix T f as the accident data set. If the upstream function i changes, the downstream function j also changes, and this situation is recorded as rule i→j. The support degree S(i→j) of the rule i→j is:

[0128]

[0129] Wherein, n(i,j) is the number of accidents in which the upstream function i and the downstream function j change simultaneously, and N is the total number of accidents.

[0130] The confidence C(i→j) of the rule i→j is:

[0131]

[0132] Wherein, S(i) is the support degree of the upstream function i.

[0133] The promotion degree L(i→j) of the rule i→j is:

[0134]

[0135] Wherein, S(j) is the support degree of the upstream function j. The meaning of the promotion degree L(i→j) is that the occurrence of the upstream function i mutation promotes the occurrence probability of the downstream function j mutation. When L(i→j)>1, it indicates that there is an amplification effect of the upstream and downstream function coupling variability; when L(i→j)<1, it indicates that there is a damping effect of the upstream and downstream function coupling variability; when L(i→j)=1, it indicates that the upstream function output has no effect on the downstream function output.

[0136] (3) Based on the above method, the promotion degrees of time and precision are obtained, so as to calculate the upstream and downstream function coupling variability score C ij :

[0137]

[0138] Wherein, B i is the variability score of the upstream function, and are the promotion degrees of time and precision respectively.

[0139] In combination with the embodiments of the application, there is also a preferred implementation scheme, specifically, the barrier is set for the key function unit, and the barrier includes:

[0140] The physical barrier, the function barrier, the symbolic barrier and the intangible barrier are set.

[0141] The physical barrier is set by a physical means to prevent the occurrence of an unexpected event; the function barrier sets a prerequisite to prevent behavior from occurring; the symbolic barrier reminds the operator of potential dangers through symbols, signs or warning systems; and the intangible barrier includes management systems, laws and regulations, guidelines and other measures.

[0142] In the system safety analysis method in the first embodiment, subjective expert experience and objective accident data are comprehensively utilized to quantify the variability of the functions and the coupling, interval hesitant fuzzy weighted average operators and Euclidean distances in interval hesitant fuzzy set theory are introduced to reduce the experience difference of the experts when evaluating the function variability; meanwhile, the promotion degree in the association rule algorithm is used as the coupling coefficient of the upstream and downstream function variability, so that the mutual influence between the function units can be more objectively described.

[0143] Embodiment two:

[0144] The second embodiment provides a system safety analysis system, as shown in Figure 7 The system includes:

[0145] A decomposition module is configured to decompose system tasks, and each subtask is determined as a function unit of the system.

[0146] The scoring module is configured to evaluate the performance of each functional unit by using time and precision, introduce expert scoring to obtain output variability scores of each functional unit, and analyze potential coupling of performance variation of each functional unit and combine the output variability scores to obtain functional coupling variability scores of each functional unit.

[0147] The judging module is configured to set a functional coupling variability score threshold, and when the functional coupling variability score exceeds the threshold, the system will have functional resonance, so that a key functional unit in the system is identified.

[0148] The barrier module is configured to set a barrier for the key functional unit to prevent potential accidents.

[0149] In the second embodiment, subjective expert experience and objective accident data are comprehensively utilized to quantify the variability of functions and couplings in the system safety analysis system, interval hesitant fuzzy weighted average operators and Euclidean distances in interval hesitant fuzzy set theory are introduced to reduce the experience difference of experts in evaluating functional variability, and the lift in the association rule algorithm is used as a coupling coefficient of upstream and downstream functional variability to more objectively describe the mutual influence between functional units.

[0150] Embodiment three:

[0151] A system safety analysis device, as shown in Figure 8 The device includes:

[0152] One or more processors;

[0153] A storage device configured to store one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method for system safety analysis according to any one of the embodiments.

[0154] Figure 8 The system safety analysis device structure diagram provided in this embodiment is shown. Figure 8 An exemplary system safety analysis device block diagram suitable for implementing embodiments of the present application is shown.

[0155] Figure 8 The system safety analysis device shown is only an example and should not limit the function and use range of the embodiments of the present application.

[0156] As shown in Figure 8 The system safety analysis device is in the form of a general device. Components of the system safety analysis device can include but are not limited to one or more processors or processing units, memory, and bus connecting different system components including memory and processing unit.

[0157] A bus refers to one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0158] The equipment used for system security analysis typically includes a variety of computer-readable media. These media can be any available media that can be accessed by the equipment that can be modified by the intelligent logging interpretation model, including volatile and non-volatile media, and portable and non-portable media.

[0159] The memory may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory. The device for system security analysis may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system may be used to read and write non-removable, non-volatile magnetic media (…). Figure 8 Not shown; usually referred to as a "hard drive"). Although Figure 8 Not shown, disk drives for reading and writing to removable non-volatile disks (e.g., "floppy disks") and optical disc drives for reading and writing to removable non-volatile optical discs (e.g., CD-ROMs, DVD-ROMs, or other optical media) may be provided. In these cases, each drive may be connected to a bus via one or more data media interfaces. The memory may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.

[0160] A program / utility having a set (at least one) of program modules can be stored, for example, in memory. Such program modules include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules typically perform the functions and / or methods described in the embodiments of this invention.

[0161] The system security analysis device can also communicate with one or more external devices such as a keyboard or a pointing device, a display, etc. which enable a user to interact with the system security analysis device, and / or one or more devices that enable the system security analysis device to communicate with one or more other devices, such as a network card, a modem, etc. This communication can occur via an input / output (I / O) interface. Also, the intelligent well interpretation model correction device can communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet, via a network adapter. As shown, the network adapter communicates with the other components of the system security analysis device via the bus. It should be appreciated that the system security analysis device can be a part of another device or be a stand-alone device. It should also be appreciated that the system security analysis device can be connected to one or more devices via one or more networks, such as a LAN or a WAN, or the Internet, for example. The system security analysis device can be a part of another device or be a stand-alone device. It should also be appreciated that the system security analysis device can be connected to one or more devices via one or more networks, such as a LAN or a WAN, or the Internet, for example. Figure 8

[0162] The processing unit performs various function applications and data processing by running programs stored in the memory, such as implementing the system security analysis method provided by any embodiment of the present application. That is, the system task is decomposed, each subtask is determined as a functional unit of the system, the performance of each functional unit is evaluated by using time and precision, the output variability score of each functional unit is obtained by introducing expert scoring, the potential coupling of the performance change of each functional unit is analyzed, and the functional coupling variability score of each functional unit is obtained by combining the output variability score. A functional coupling variability score threshold is set, when the functional coupling variability score threshold is exceeded, the system will have functional resonance, thereby identifying the key functional unit in the system, setting a barrier for the key functional unit, and preventing potential accidents from occurring.

[0163] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. Any modification, equivalent replacement, and improvement within the spirit and principle of the present application shall be included in the protection scope of the present application.​

Claims

1. A system security analysis method, characterized in that, The method includes: The system tasks are decomposed, and each subtask is identified as a functional unit of the system; The performance of each functional unit is evaluated using time and accuracy, and expert scoring is introduced. The performance of each functional unit is categorized into four types based on the degree of functional variability: time is categorized as too early, on time, too late, and not occurring; simultaneously, accuracy is categorized into three types: accurate, acceptable, and imprecise. The output variability score of each functional unit is obtained through a calculation process based on an interval hesitant fuzzy weighted average operator and Euclidean distance. The specific method is as follows: Experts were invited to score the time and precision variation probabilities of each functional unit in intervals, forming an interval-valued hesitant fuzzy set, and thus obtaining the experts' evaluation values ​​for the time and precision variation probabilities of each functional unit. The interval hesitant fuzzy set is aggregated using the interval hesitant fuzzy weighted average operator to obtain the decision criterion for the variability probability of each functional unit. By calculating the Euclidean distance and similarity between the interval-valued hesitant fuzzy set and the decision benchmark, the expert's preference weight for each functional unit is determined. Using the preference weights and the experts' evaluation values ​​of the time variation and accuracy variation probability of each functional unit, the variability score of each functional unit is calculated. Further analysis of the potential coupling of performance changes in each functional unit reveals that, using the time-precision coupling coefficient determined from historical accident data and combined with the output variability score, the functional coupling variability score of each functional unit is obtained. The specific method is as follows: Determine the upstream and downstream influence relationships of each functional unit, and calculate the time coupling coefficient and accuracy coupling coefficient of the output changes of upstream and downstream functions based on the improvement degree mined from historical accident data. The improvement degree refers to the degree to which the probability of a functional change in a downstream functional unit also occurring if a functional change occurs in an upstream functional unit. By combining the output variability score with the time coupling coefficient and the precision coupling coefficient, the functional coupling variability score of each functional unit is calculated, wherein: the functional coupling variability score of the upstream functional unit is the output variability score of the upstream function multiplied by the corresponding time coupling coefficient and precision coupling coefficient; Then, a functional coupling variability score threshold is set. When the score exceeds the threshold, the system will experience functional resonance, thereby identifying key functional units in the system. Barriers are then set for these key functional units to prevent potential accidents from occurring.

2. The system security analysis method as described in claim 1, characterized in that, The method for decomposing system tasks and identifying each subtask as a functional unit of the system includes: The hierarchical task analysis method is used to decompose the system tasks, and the functional units of the system are described from the perspectives of input, output, time, control, resources and prerequisites. The connection and interaction relationships between the functional units are analyzed and established.

3. The system security analysis method as described in claim 1, characterized in that, The method for calculating the time coupling coefficient and precision coupling coefficient of upstream and downstream functional output changes based on the lift degree includes: Historical accident investigation reports are converted into a Boolean matrix of functional unit variation information to confirm whether time or precision changed during the accident. The Boolean matrix is ​​used as an accident dataset to collect cases where upstream functional units mutate and downstream functions also mutate. The improvement in both time and accuracy is obtained, and the variability score of upstream and downstream functional coupling is calculated.

4. The system security analysis method as described in claim 1, characterized in that, When the lift is greater than 1, it indicates that there is an amplification effect on the variability of upstream and downstream functional coupling; when the lift is less than 1, it indicates that there is a damping effect on the variability of upstream and downstream functional coupling; when the lift is equal to 1, it indicates that the upstream functional output has no effect on the downstream functional output.

5. The system security analysis method as described in claim 1, characterized in that, The provision of barriers for the key functional units includes: Set up physical barriers, functional barriers, symbolic barriers, and intangible barriers.

6. A system for system security analysis, characterized in that, The system is used to implement the method as described in claim 1, the system comprising: A decomposition module is used to decompose system tasks, and the decomposition system identifies each subtask as a functional unit of the system. The scoring module is used to evaluate the performance of each functional unit using time and accuracy, and introduces expert scoring to obtain the output variability score of each functional unit; then, the potential coupling of the performance changes of each functional unit is analyzed and combined with the output variability score to obtain the functional coupling variability score of each functional unit. The judgment module is used to set a functional coupling variability score threshold. When the functional coupling variability score threshold is exceeded, the system will experience functional resonance, thereby identifying the key functional units in the system. The barrier module is used to set barriers for the key functional units to prevent potential accidents from occurring.

7. A device for system security analysis, characterized in that the device... include: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the system security analysis method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Energy storage system random configuration method considering wind power uncertainty, terminal and storage medium

    CN112564160A

  • Automatic driving performance evaluation method and device, equipment and medium

    CN116703028A