Method and system for generating multiple security requirements for petroleum refining system based on Secure Tropos

The Secure Tropos method is used to generate security requirements for the oil refining system, which solves the time-consuming and subjective problems of existing technologies, realizes fast and accurate security requirement generation, and improves the safety protection capabilities of oil refining equipment.

CN119493548BActive Publication Date: 2025-09-05HUAZHONG UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410944358.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-15
Publication Date
2025-09-05
Estimated Expiration
2044-07-15

AI Technical Summary

Technical Problem

Existing security requirements generation methods in petroleum refining plants are time-consuming, highly subjective, and have poor scalability. They are unable to quickly obtain comprehensive and accurate security requirements and cannot effectively respond to dynamic and time-varying security threats, resulting in petroleum refining plants facing security risks from cyber attacks.

Method used

The Secure Tropos method is used to functionally divide the petroleum refining system, establish a security entity and data interaction model, derive security constraints by combining data flow and control flow characteristics, generate security requirements through model checking, and perform automated verification using Secure Tropos software.

Benefits of technology

It reduces the complexity of large-scale system security requirement modeling, quickly generates high-quality security requirements that meet functional requirements and relevant standards, improves safety protection capabilities and efficiency, and ensures the safe operation of oil refining units.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119493548B_ABST
    Figure CN119493548B_ABST
Patent Text Reader

Abstract

The present invention discloses a Secure Tropos-based method and system for generating multiple security requirements for a petroleum refining system. This method, which belongs to the field of security engineering, analyzes the dependencies and security threats between system functional modules involved in the entire process of a petroleum refining unit, targeting its security protection objectives. The method also analyzes the structure and data interaction types of the petroleum refining unit to establish a security entity and data interaction model. The method analyzes data flow and control flow characteristics to determine corresponding functional requirements, and derives security constraints based on the security protection objectives. The established security entity and data interaction model is then subjected to model checking, automatically generating an inspection report. The report content is then analyzed for security constraint violations to determine public and special security requirements. This invention can rapidly generate high-quality security requirements for petroleum refining units that meet functional requirements and relevant standards, significantly improving efficiency, effectiveness, and accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of safety engineering in chemical industry production, and more specifically, relates to a method and system for generating multiple safety requirements of a petroleum refining system based on SecureTropos. Background Art

[0002] Petroleum products are fundamental to national development and people's livelihoods. Petroleum refining plants, as critical industrial infrastructure, are responsible for processing, separating, and converting crude oil into various petroleum products. However, with the development of industrial control systems, new sensor networks, and data communication technologies, the operation of petroleum refining plants faces increasing security risks and has become a common target for cyberattacks. Because the products of petroleum refining plants are flammable and explosive, cyberattacks are highly likely to cause major production accidents. Therefore, leveraging emerging technologies to ensure the safe operation of petroleum refining plants has become a research priority.

[0003] Comprehensive and accurate security requirements generation is an important foundation for ensuring the safe operation of petroleum refining plants and deploying safety protection measures. Existing security requirements generation methods often combine risk analysis and requirements engineering, which generally suffer from problems such as long time consumption, strong subjectivity, poor scalability, and excessive security design. For petroleum refining plants, security requirements generation must not only consider traditional physical security of chemical production, but also the security requirements of industrial control systems, communication networks, regulatory standards, business continuity, and other aspects. In addition, due to the dynamic and time-varying nature of security threats to petroleum refining plants during operation, higher requirements are placed on the timeliness and generation efficiency of security requirements. However, when applied to large-scale petroleum refining plants, current security requirements generation methods are unable to quickly obtain comprehensive and accurate security requirements. Summary of the Invention

[0004] In response to the above-mentioned deficiencies or improvement needs of the existing technology, the present invention provides a method and system for generating multiple security requirements for petroleum refining systems based on Secure Tropos, which can reduce the complexity of large-scale system security requirement modeling, quickly generate high-quality security requirements that meet functional requirements and relevant standards, and greatly improve efficiency, effectiveness and accuracy.

[0005] To achieve the above objectives, according to a first aspect of the present invention, a method for generating multiple security requirements for a petroleum refining system based on Secure Tropos is provided, comprising:

[0006] S1, determine the security protection objectives, dependency types and security threats of the oil refining unit;

[0007] S2. Functionally dividing the petroleum refining system into a monitoring system, a power system, a human-computer interaction system, and refining equipment; and establishing a security entity and data interaction model for the petroleum refining system in Secure Tropos software based on the security protection objectives, security threat types, and dependency types. Dividing the petroleum refining system into a reaction and regeneration subsystem, a fractionation subsystem, and an absorption and stabilization subsystem according to the petroleum refining process flow; and establishing a security entity and data interaction model for the petroleum refining system, as well as a security entity and data interaction model for each subsystem, in Secure Tropos software based on the security protection objectives, security threat types, and dependency types.

[0008] S3, determining corresponding functional requirements based on the data flow and control flow characteristics of the oil refining system, and obtaining corresponding security constraints in combination with the security protection objectives; and importing the security constraints into each model respectively;

[0009] S4, perform model inspection on each model separately to obtain the corresponding inspection report; perform security constraint violation analysis on the inspection report of the security entity and data interaction model of the petroleum refining system and the inspection report of the security entity and data interaction model of each subsystem respectively to obtain the public safety requirements of the petroleum refining system and the special security requirements of each subsystem.

[0010] According to a second aspect of the present invention, there is provided a system for generating multiple security requirements for a petroleum refining system based on Secure Tropos, comprising: a computer-readable storage medium and a processor;

[0011] The computer-readable storage medium is used to store executable instructions;

[0012] The processor is configured to read the executable instructions stored in the computer-readable storage medium and execute the method according to the first aspect.

[0013] According to a third aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to execute the method according to the first aspect.

[0014] In general, the above technical solutions conceived by the present invention can achieve the following beneficial effects compared with the prior art:

[0015] The method provided by the present invention applies Secure Tropos to the security requirements analysis of petroleum refining equipment, establishes a security entity and data interaction model based on the environmental constraints, dependency relationships, security threats and other factors of the petroleum refining equipment, and derives security constraints in combination with data flow and control flow characteristics. Combined with automated model checking, it quickly generates security requirements for the petroleum refining equipment that meet functional requirements and relevant standards, thereby improving the security protection capabilities of the petroleum refining equipment; a formal modeling language is used in the modeling process, which helps to accurately capture and express the security requirements of the system and avoid ambiguity or ambiguity; in addition, the method considers the interactions and dependencies between multiple parties in the requirements modeling, supports the traceability of requirements, and tracks the entire process of requirements from conceptual design to implementation; in summary, the method provided by the present invention can reduce the complexity of large-scale system security requirements modeling, quickly generate high-quality security requirements that meet functional requirements and relevant standards, and greatly improve efficiency, effectiveness and accuracy. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A flow chart of a method for generating multiple security requirements for a petroleum refining unit based on Secure Tropos provided in an embodiment of the present invention;

[0017] Figure 2 A schematic diagram of the distribution relationship of four dependencies in a petroleum refining device provided by an embodiment of the present invention;

[0018] Figure 3 Schematic diagram of the security entity and data interaction model of the oil refining system provided by an embodiment of the present invention;

[0019] Figure 4 A schematic diagram of the security entity and data interaction modeling process of a petroleum refining unit subsystem provided by an embodiment of the present invention;

[0020] Figure 5 A schematic diagram of a security entity and data interaction model of a reaction regeneration system provided in an embodiment of the present invention;

[0021] Figure 6 A schematic diagram of a security constraint generation process combining data flow and control flow features provided in an embodiment of the present invention;

[0022] Figure 7 A schematic diagram of the UML-based security specification generation process provided in an embodiment of the present invention;

[0023] Figure 8 A schematic diagram of a UML graphical expression of the security constraint attributes of a CSR1 safety-critical component provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the present invention and are not intended to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below may be combined with each other as long as they do not conflict with each other.

[0025] Secure Tropos is an agent-oriented security requirements engineering method. By decomposing the object system into different participants and analyzing their functional goals, data resources, security mechanisms, security threats and other related entities one by one, it provides a systematic method for integrating security issues into the early development of security requirements, allowing developers to build safe and reliable software and hardware systems. In addition, because Secure Tropos has many exclusive modeling tools and supports formal verification, it helps to quickly generate comprehensive and accurate security requirements for large-scale oil refining plants with high efficiency, good effect and scalability. Based on this, an embodiment of the present invention provides a method for generating multiple security requirements for oil refining systems based on Secure Tropos. Figure 1 Shown, including:

[0026] S1. Determine the security protection objectives, dependency types and security threats of petroleum refining equipment.

[0027] Specifically, the security objectives of the oil refining device can be selected according to actual needs, and the embodiments of the present invention do not limit this to a single one. As an example, preferably, the security objectives include: accessibility, integrity, confidentiality, authentication, and utility, a total of five categories.

[0028] Of the five security objectives mentioned above, accessibility, integrity, and confidentiality are traditional security objectives within the information security field and are a consensus within the industry. Authenticity, as a supplement to the security objectives, requires user identity authentication before any system operation is performed, ensuring that system operations are performed only by authorized users. Utility, as a supplement to the security objectives, requires that both system data transmission and action execution meet functional requirements. For example, when a network attack successfully launches a denial of service (DoS) attack, the primary security objective is compromised. This is because the DoS attack blocks data transmission, preventing instructions from reaching the receiving end within the specified time. Consequently, the actuator fails to receive the instructions and therefore fails to execute the action, ultimately failing to meet functional requirements. During this process, the blocked data can still be transmitted through the channel and is not rejected (accessibility is met), data fields are not intercepted or deleted (integrity is met), data is not leaked to third parties (confidentiality is met), and the authentication mechanism is not bypassed or compromised (authentication is met). Therefore, the other four security objectives are met, with only utility not being met.

[0029] The types of system dependencies are determined in sequence based on system functional modules, control loops, data flows and time sequences, that is, the dependency relationships between system components are determined based on physical layer functional components and information layer data transmission channels.

[0030] The type of system dependency can be selected according to actual needs, and the embodiment of the present invention does not limit this to a unique type. As an example, preferably, the types of dependency include: timing dependency, data dependency, component dependency, and functional dependency, a total of four categories.

[0031] The distribution of the above four dependencies in the oil refining unit is shown as follows: Figure 2As shown. The petroleum refining unit contains multiple system functional modules, among which the dependency relationship between functional modules is the functional dependency. For example, when the main air system and the flue gas turbine system are both turned on and reach the expected state, the crude oil supply system will be turned on to deliver crude oil to the regeneration system. Dependency is realized through 0-1 coding during the modeling process. For example, the opening and closing of the main air system (MA) are coded as MA01 and MA00 respectively, the opening and closing of the flue gas turbine (GT) are coded as GT01 and GT00 respectively, and the opening and closing of the crude oil supply system (OS) are coded as OS01 and OS00 respectively. Then the opening condition of the regeneration system (RRS) can be set as (MA01∪GT01∪…∪XX01)∪OS01, where XX01 represents the opening of other system functional modules parallel to the main air system and the flue gas turbine system, ∪ is a parallel symbol, and the above If any of the above conditions is not met, the anti-reinforcement system will not activate. Furthermore, each functional module consists of multiple control loops, each of which contains three types of control components: sensors, controllers, and actuators. The dependencies between control components are known as component dependencies. The channels between control components contain a large number of data streams, and their processes include data acquisition, data encoding, data transmission, and data decoding. The dependencies between these processes are known as data dependencies. The data between each two processes is continuous and multi-group, so there is a temporal relationship. The dependencies between measurement data of different time series are known as temporal dependencies. All four dependency relationships are implemented through 0-1 encoding in the subsequent modeling process.

[0032] Identify typical security threats that need to be considered based on information security incidents in oil refining plants.

[0033] The types of security threats can be selected according to actual needs, and the embodiments of the present invention do not limit this to a unique one. As an example, preferably, security threats include: denial of service, false data injection, eavesdropping, replay, malware, and virus, a total of 6 categories.

[0034] The six typical security threats listed above are the most common, potentially harmful, and impactful types of security threats targeting the chemical industry over the past decade. They cover over 98% of cyberattack scenarios targeting chemical systems.

[0035] S2, functionally dividing the oil refining system into a monitoring system, a power system, a human-computer interaction system, and refining equipment, and establishing a security entity and data interaction model for the oil refining system in Secure Tropos software based on the security protection objectives, security threat types, and dependency categories;

[0036] The petroleum refining system is divided into a reaction regeneration subsystem, a fractionation subsystem, and an absorption stabilization subsystem according to the petroleum refining process flow; based on the security protection objectives, security threat types, and dependency types, the security entity and data interaction model of the petroleum refining system, as well as the security entity and data interaction model of each subsystem are established in the Secure Tropos software.

[0037] The following describes the process of establishing the security entity and data interaction model of the petroleum refining system and the process of establishing the security entity and data interaction model of each subsystem.

[0038] (1) The process of establishing the security entity and data interaction model of the petroleum refining system is as follows:

[0039] Analysis of the structure and data interaction types of petroleum refining equipment: The structure of a petroleum refining unit is mainly divided into the monitoring system, power system, human-computer interaction, and refining equipment. The monitoring system is used to monitor the status of a series of production-related systems; the power system is used to ensure the power supply of the petroleum refining unit; the human-computer interaction system allows operators to monitor production conditions in the workshop, issue specific control commands, and perform human intervention in emergency situations to ensure production safety. Refining equipment includes a series of components such as containers, connectors, sensors, and actuators, which are generally controlled objects. The data interaction types of petroleum refining units can be divided into monitoring data, operation data, power system data, and safety data.

[0040] During the modeling process, the monitoring system, power system, human-computer interaction, and refining equipment are set as first-level participants (Actor); monitoring data, operation data, power system data, and safety data are set as first-level resources (Resource).

[0041] In the monitoring system, the monitoring function and control function are set as the first-level functional goals (Goal), and the catalyst, wastewater composition, emission, energy and water consumption, communication, regeneration system, fractionation system, absorption stabilization system, distributed control system (DCS), safety instrument (SIS), alarm device and valve are set as the second-level functional goals (Goal); in the monitoring system, the data interaction types generated include monitoring data, operation data and safety data;

[0042] In the power system, power energy control is the first-level functional goal (Goal); power maintenance, monitoring and control, and power efficiency are set as the second-level functional goals (Goal); supervisory control system SCADA, emergency power system, voltage regulation, switchgear and circuit breakers, transformers, protective relays, and energy management system are set as the third-level functional goals (Goal); in the power system, the data type generated is power system data;

[0043] In human-computer interaction, "communication with oil refining equipment" is set as a functional goal. To achieve this goal, four types of data resources are required, including monitoring data, operation data, power system data, and safety data.

[0044] In the refining equipment, "data interaction" is set as the functional goal. In order to achieve this goal, two types of data resources are required, including monitoring data and operation data. The final security entity and data interaction model of the petroleum refining system is as follows: Figure 3 shown.

[0045] It's worth noting that actors, resources, and functional goals are all settings within the SecureTropos software. In this invention, first-level actors only include the monitoring system, power system, human-computer interaction, and refinery equipment; first-level resources only include monitoring data, operational data, power system data, and security data. The oil refinery system security entity and data interaction model established within SecureTropos software is used to elicit public safety requirements (CSRs).

[0046] (2) The process of establishing the security entity and data interaction model of each subsystem is as follows:

[0047] The petroleum refining process is decomposed into the reaction regeneration system RRS, fractionation system FS and absorption stabilization system ASS. The three subsystem security entities and data interaction models are established in the Secure Tropos software. The modeling process is as follows: Figure 4 As shown. The present invention takes the reaction regeneration system RRS as an example to illustrate its security entity and data interaction model as shown in Figure 5 shown.

[0048] In the safety entity and data interaction model of the reaction regeneration system (RRS), there are three secondary actors: the reaction regeneration system, the fractionation system, and the control center. The fractionation system (FS) is adjacent to the reaction regeneration system (RRS). The RRS product directly enters the FS for reaction, so there is an interactive relationship between them. The control center receives monitoring data from the reaction regeneration system and sends control instructions to it to regulate the system's operation.

[0049] In the secondary participant (Actor) reaction regeneration system, "providing information to the control center" is set as the primary functional goal (Goal), and "receiving static data", "receiving dynamic data", "analyzing received data" and "sending analyzed data" are set as the secondary functional goals (Goal). The secondary resources (Resource) required include - static data of the reaction and regeneration system, distillation system operation data, catalyst monitoring data, waste component monitoring data, waste component safety data, communication quality and safety data, control system monitoring data, control system operation data, safety instrument operation data, alarm device operation data, valve operation data and other operation data; the secondary resources (Resource) generated include - dynamic data of the reaction and regeneration system, reaction and regeneration system operation data, and reaction and regeneration system safety data.

[0050] In the secondary actor fractionation system, "interacting with the reaction system" is set as the primary functional goal (Goal), and "receiving reaction system data" and "sending data to the reaction system" are set as the secondary functional goals (Goal). The required data resources include reaction system dynamic data, reaction system operation data, reaction system safety data and fractionation system operation data, all of which are set as secondary resources (Resource).

[0051] In the secondary actor control center, "interact with the anti-reinforcement system" is also set as the first-level functional goal (Goal), and "accept anti-reinforcement system data" and "send data to the anti-reinforcement system" are set as the second-level functional goals (Goal). The required data resources include the dynamic data of the anti-reinforcement system and the dynamic data of the control system, which are all set as second-level resources (Resource).

[0052] Among them, the reaction regeneration system and the fractionation system, as second-level actors, can be set as the dependent and the reaction regeneration system as the dependent, since the input of the fractionation system depends on the output of the reaction regeneration system. The interaction data types between the two include fractionation system operation data, reaction regeneration system dynamic data, reaction regeneration system operation data, and reaction regeneration system safety data. As second-level actors, the reaction regeneration system and the control center, as second-level actors, can be set as the dependent and the control center as the dependent, since the operation of the reaction regeneration system is regulated by the control center. The interaction data types between the two include reaction regeneration system dynamic data and control system dynamic data. The above six types of interaction data are all set as second-level resources.

[0053] Specifically, the resource transmission between the dependent and the dependent may have multiple security objectives and security mechanisms. Figure 5 In the resource transmission between the reaction regeneration system and the control center shown, the security protection goals of both the dependent and the dependent include integrity, availability, authentication, and utility. Each security protection goal is supported by a corresponding security mechanism. For example, to ensure integrity, the security mechanisms considered include storage backup, data encryption, data transmission backup, function list backup, and control configuration backup.

[0054] It is worth noting that the security entity and data interaction model of the fractionation system FS and the absorption stabilization system ASS can be established with reference to the security entity and data interaction model of the reaction regeneration system RRS;

[0055] For example, in the security entity and data interaction model of the fractionation system FS, three secondary actors (Actors) are set, namely the fractionation system, the reaction and regeneration system, and the control center. In the secondary actor (Actor) fractionation system, "providing information to the control center" is set as the first-level functional goal (Goal), and "receiving static data", "receiving dynamic data", "analyzing received data" and "sending analyzed data" are set as the second-level functional goals (Goal); the generated second-level resources (Resource) include the dynamic data of the fractionation system, the operation data of the fractionation system, and the safety data of the fractionation system; in the secondary actor (Actor) reaction and regeneration system, "interacting with the fractionation system" is set as the first-level functional goal (Goal), and "receiving data from the fractionation system" and "sending data to the control center" are set as the second-level functional goals (Goal). The required data resources include the dynamic data of the fractionation system, the operation data of the fractionation system, the safety data of the fractionation system, and the operation data of the fractionation system, which are all set as secondary resources. In the secondary actor control center, "interacting with the fractionation system" is set as the primary functional goal, and "receiving fractionation system data" and "sending data to the fractionation system" are set as secondary functional goals. The required data resources include the dynamic data of the fractionation system and the dynamic data of the control system, which are all set as secondary resources.

[0056] In the security entity and data interaction model of the absorption stabilization system ASS, three secondary participants (Actors) are set, namely the absorption stabilization system, the fractionation system and the control center. In the secondary participant (Actor) absorption stabilization system, "providing information to the control center" is set as the first-level functional goal (Goal), and "receiving static data", "receiving dynamic data", "analyzing received data" and "sending analyzed data" are set as the second-level functional goals (Goal); the generated secondary resources (Resource) include the absorption stabilization system dynamic data, the absorption stabilization system operation data, and the absorption stabilization system safety data; in the secondary participant (Actor) fractionation system, "interacting with the absorption stabilization system" is set as the first-level functional goal (Goal), and "receiving absorption stabilization system data" and "sending data to the absorption stabilization system" are set. The required data resources include the absorption and stabilization system dynamic data, the absorption and stabilization system operation data, the absorption and stabilization system safety data, and the absorption and stabilization system operation data, all of which are set as secondary resources. In the secondary actor control center, "interacting with the absorption and stabilization system" is set as the first-level functional goal, and "receiving absorption and stabilization system data" and "sending data to the absorption and stabilization system" are set as the second-level functional goals. The required data resources include the absorption and stabilization system dynamic data and the control system dynamic data, all of which are set as second-level resources.

[0057] The three subsystem security entities and data interaction models established in the Secure Tropos software are used to derive special security requirements SSR.

[0058] It can be understood that in the process of establishing the above-mentioned oil refining system security entity and data interaction model and the security entity and data interaction model of each subsystem, the corresponding first-level or second-level participants, functional objectives and resource types are all exemplary illustrations. The present invention does not make a unique limitation on this. Those skilled in the art can select various types according to the actual situation of the oil refining system. For example, some data resources of some oil refining systems may not be easy to obtain, and such data resources may not be used in the corresponding modeling process.

[0059] S3, determining corresponding functional requirements based on the data flow and control flow characteristics of the oil refining system, and obtaining corresponding security constraints in combination with the security protection goals; and importing the security constraints into each model respectively.

[0060] Specifically, the data flow and control flow characteristics in the petroleum refining unit are analyzed, and the corresponding functional requirements are determined. The security constraints are derived in combination with the security protection goals, and the security constraints are introduced into the subsystem security entity and data interaction model. The process is as follows: Figure 6shown.

[0061] The types of data stream features can be selected according to actual needs, and the embodiments of the present invention do not limit this to a unique type. As an example, preferably, the types of data stream features include: real-time, continuity, diversity, and sparsity, a total of 4 categories;

[0062] Specifically, real-time refers to a system's ability to process and respond to data within a very short timeframe after data generation or an event occurs. This requires efficient algorithms and low-latency processing mechanisms to ensure timely data processing and analysis. Continuity refers to the uninterrupted transmission of data streams throughout a complete execution cycle, requiring the system to continuously process data to avoid performance degradation or crashes. Diversity refers to the diverse types and formats of data streams, including structured, semi-structured, and unstructured data. Sparsity refers to the fact that many data points in a data stream may be sparse or zero-valued, or have low data density. Therefore, effective storage and processing methods are required to cope with large amounts of sparse data and avoid excessive consumption of computing resources. For example, one characteristic of a denial-of-service (DoS) attack is the significant consumption of the target system's computing resources, reducing the efficiency of data transmission and processing, and ultimately paralyzing the target system.

[0063] The types of control flow features can be selected according to actual needs, and the embodiments of the present invention do not limit this to uniqueness. As an example, preferably, the types of control flow features include: sequential, conditional, cyclic, branching, abnormal, recursive, and concurrency, a total of 7 categories;

[0064] Specifically, sequentiality refers to the execution of instructions in a program, one by one, in the order in which they appear in the code. This is the most basic form of control flow, ensuring that the program proceeds as expected. Conditionality refers to the determination of which portion of the program code to execute based on the truth of a condition, enabling the program to execute the appropriate code based on different circumstances. Looping refers to the repeated execution of a section of code until a condition is met, which is used to handle tasks that require repetitive execution. Branching refers to the branching of a program based on certain conditions, allowing it to choose different execution paths under different circumstances. Exceptions refer to the ability of a program to catch and handle exceptions or errors, rather than crashing the program, enhancing its robustness and error handling capabilities. Recursion refers to the ability of a function to call itself directly or indirectly. Concurrency refers to the ability of a program to execute multiple tasks or processes simultaneously, improving its execution efficiency and responsiveness. Control flow determines the order and manner in which a program executes. Common network virus attacks can directly affect the program itself, for example by modifying operating conditions to cause the system to enter an infinite loop or by inserting special symbols to disrupt the program's normal control flow characteristics, thereby disrupting normal execution and virus detection capabilities.

[0065] Starting from the characteristics of data flow and control flow, the corresponding functional requirements are determined, and combined with the safety protection goals to generate safety constraints. Table 1 gives an example of safety constraint generation for the reaction regeneration system (RRS):

[0066] Table 1 Example of safety constraint generation for the reaction regeneration system RRS

[0067]

[0068]

[0069] It should be noted that the four types of data flow features and the seven types of control flow features are common concepts in fields such as computer science and technology, network security, and automation. The present invention does not propose these concepts, but rather integrates them to provide a more comprehensive, targeted, and systematic approach to generating security constraints.

[0070] The generated security constraint content is imported into the subsystem security entity and data interaction model, and a connection relationship is established with the corresponding security protection goals and secondary functional goals, thus completing all security entity and data interaction modeling work.

[0071] It is worth noting that the security constraint is a setting in the Secure Tropos software, into which the required security constraint content can be written.

[0072] S4, perform model inspection on each model separately to obtain the corresponding inspection report; perform security constraint violation analysis on the inspection report of the security entity and data interaction model of the petroleum refining system and the inspection report of the security entity and data interaction model of each subsystem respectively to obtain the public safety requirements of the petroleum refining system and the special security requirements of each subsystem.

[0073] Specifically, model checking is performed on the established oil refining system security entity and data interaction model, as well as the three subsystem security entity and data interaction models, and a check report is generated. Based on the check report, corresponding security requirements are obtained.

[0074] Model checks are performed on the security entity and data interaction model of the petroleum refining system and the security entity and data interaction models of the three subsystems established in the Secure Tropos software. After the check passes, a model check report will be automatically generated. The report content is analyzed for security constraint violations to obtain security requirements. Among them, the security requirements obtained from the system structure and data interaction model of the petroleum refining unit are common security requirements (CSRs), and the security requirements obtained from the subsystem security entity and data interaction model are special security requirements (SSRs).

[0075] The following is an example of analyzing the security constraint violations of the inspection report to obtain security requirements.

[0076] For the security entity and data interaction model of the petroleum refining system, some of the model check contents are shown in Table 2:

[0077] Table 2 Examples of some content of model checking for the security entity and data interaction model of the petroleum refining system

[0078]

[0079] At this point, we have obtained the model check content: "Attackers rely on malware in human-computer interaction to inject unauthorized false data into the operational data required by the DCS, thereby destroying its integrity and practicality." We conducted a security constraint violation analysis. The analysis was completed manually, and the steps and corresponding analysis content are as follows:

[0080] Step 1: Identify the violation, the violated security objectives, and the security constraints. The details are as follows:

[0081] Violation: Unauthorized operation

[0082] Violated security objectives: integrity, effectiveness

[0083] The security constraints violated are: 1. Provide required data; 2. Ensure data timing is accurate; 3. Ensure data integrity; 4. Ensure timing is verifiable; 5. Ensure functional execution is complete

[0084] Step 2: Analyze the background and causes of the security constraint violation, including:

[0085] Background 1: Employees rely on human-computer interaction systems to access and operate;

[0086] Context 2: The goal of the human-computer interaction system is to communicate with the oil refining unit;

[0087] Context 3: A large number of employees have access to the system and have permission to access but not to operate;

[0088] Context 4: A small number of employees may have both access rights and operation rights;

[0089] Reason 1: Current authentication mechanisms are inadequate, allowing attackers to impersonate employees.

[0090] Reason 2: The current permission setting mechanism is imperfect and lacks separation of duties and permission restrictions.

[0091] Step 3: Derive security requirements based on the reasons and integrate them. The specific contents include:

[0092] Safety requirements SR1, SR2, and SR3 are derived from reason 1, including:

[0093] SR1: Implement multi-factor authentication for employees logging into human-computer interaction systems;

[0094] SR2: Enhance login session management to detect and prevent session hijacking;

[0095] SR3: Regularly update and audit authentication mechanisms to ensure they meet current security standards.

[0096] Safety requirements SR4, SR5, SR6, and SR7 are derived from reason 2, including:

[0097] SR4: Requires operator approval for all operations above a certain application level;

[0098] SR5: Restrict employee permissions so that they can only access the human-computer interaction system but not operate it;

[0099] SR6: Ensure that sensitive tasks require double confirmation, involving at least two different employees;

[0100] SR7: Regularly audit operation records to ensure that operations comply with the principle of separation of duties;

[0101] By integrating the above seven security requirements, we obtain a complete security requirement: "Follow the principle of separation of duties, ensure that the execution of sensitive tasks requires the participation of multiple personnel, and limit the permissions of each employee so that they can only access and operate necessary systems." Because this requirement is derived from the model check report of the oil refining system security entity and data interaction model, it belongs to the public security requirement CSR.

[0102] Preferably, to better organize and manage security requirements, especially to enhance the structure of security requirements documents when preparing them, and to facilitate querying, updating, and subsequent maintenance, after obtaining the two types of security requirements (CSRs and SSRs), the following further steps are included: categorizing the public security requirements and special security requirements into different security requirement types based on environmental constraints. In other words, the two types of security requirements (CSRs and SSRs) are categorized.

[0103] The types of security requirements can be set according to actual needs. The embodiments of the present invention do not make any unique limitations on this. As an example, preferably, the types of security requirements include: personnel management security, asset management security, access control security, cryptographic security, physical and environmental security, operational security, communication security, system development and maintenance security, supply chain security, security incident management, business management security, and compliance management security, totaling 12 categories.

[0104] It is worth noting that the classification of security requirements is based on environmental constraints. For example, the security requirement type "personnel management security" comes from the environmental constraint "human resources"; the security requirement type "access control security" comes from the environmental constraints "security measures" and "communications."

[0105] The types of environmental constraints can be determined based on relevant standards and laws and regulations. The embodiment of the present invention does not limit this to a single type. As an example, preferably, the environmental constraints include: operating conditions, emissions, communications, security measures, computing resources, network attacks, human resources, catalyst management, wastewater management, policies and regulations, energy consumption, and water consumption, totaling 12 categories.

[0106] Specifically, the operating conditions may refer to NFPA 30, the standard for storage of flammable and combustible liquids, and OSHA 29CFR, the standard for handling hazardous chemicals in the workplace; the emissions may refer to EPA 40CFR Part 60, the standard for air emissions, and ISO 14001, the standard for environmental management systems; the communications may refer to NIST SP 800-82, the guide for security of industrial control systems; the safety measures may refer to API RP 754, the standard for assessment of safety and health management systems, and IEC 61511, the standard for functional safety; the computing resources may refer to ISO / IEC 27001, the standard for information security management systems; the network attacks may refer to ISA-62443, the security standard; the human resources may refer to ANSI Z10, the standard for health and safety management systems; the catalyst management may refer to EPA 40CFR, the rule for preventing chemical accidents, and NFPA 55, the standard for gas use; the wastewater management may refer to EPA 40CFR Part 401, the standard for industrial emissions; the policies and regulations may refer to OSHA Process Safety Management Standard, the standard for handling hazardous chemicals in the workplace, and EPA Risk Management Program (RMP); the energy consumption may refer to the energy management system standard ISO 50001; the water consumption is referred to the environmental management system standard ISO 14001.

[0107] The classification and content examples of the generated public safety demand CSR are shown in Table 3:

[0108] Table 3 Classification and content examples of public safety demand CSR

[0109]

[0110] The classification and content of the special security requirement SSR mentioned above can refer to the public security requirement CSR example. You only need to replace the requirement number and security requirement content in the table.

[0111] Preferably, in order to further clarify and concretize the abstract security requirements and improve the verifiability and compliance of the security requirements, the public security requirements and special security requirements are converted into public security specifications and special security specifications respectively on a one-to-one basis.

[0112] Specifically, the above transformation can use existing tools, such as use case diagrams, sequence diagrams, state diagrams, activity diagrams, etc. in UML. The embodiment of the present invention does not impose a unique limitation on this.

[0113] The following describes the conversion process by taking the example of converting the public safety requirements and special safety requirements into public safety specifications and special safety specifications one by one using the use case diagram in UML.

[0114] The public safety requirements and special safety requirements are converted into public safety specifications and special safety specifications respectively using the use case diagram in UML:

[0115] The security key elements and security constraint attributes of the common security requirements and special security requirements are respectively identified, and converted into common security specifications and special security specifications in XML format through the UML model.

[0116] Specifically, a UML model is developed to express the common safety requirements CSR and special safety requirements SSR in a graphical way, and restore the relationship and interaction between safety requirements, among which;

[0117] The types of security-critical elements and security constraint attributes can be set according to actual needs. The embodiments of the present invention do not limit them to uniqueness. As an example, security-critical elements include security-critical components, security-critical interactions, and security-critical behaviors, a total of three types.

[0118] Safety constraint attributes include performance limitations, operating conditions, failure modes, fault tolerance requirements, and safety-related standards, a total of 5 types.

[0119] The security-critical elements of the system identified in the security requirements include components, interactions, and behaviors that have a direct impact on security. For example, for the common security requirement CSR1 (see Table 2), the identified security-critical elements are shown in Table 4:

[0120] Table 4 Example of identification of critical security elements of public security requirement CSR1

[0121]

[0122]

[0123] Specify the security constraint attributes associated with the identified security-critical elements, including performance limitations, operating conditions, failure modes, fault tolerance requirements, and security-related standards. Take the security-critical component "User Identity Management System" of Public Security Requirement CSR1 as an example. Its security constraint attribute examples are shown in Table 5:

[0124] Table 5 Example of security constraint attributes for the CSR1 security-critical component “User Identity Management System”

[0125]

[0126] Furthermore, all security constraint attributes are modeled using a use case diagram to convert security requirements into UML graphical expressions. Taking the security-critical components in the public security requirement CSR1 (see Table 3) as an example, the UML graphical expression of its security constraint attributes is as follows: Figure 8 shown.

[0127] (3) Generate security specifications based on the UML model and verify, record, update, and maintain them, including:

[0128] Using the UML model, the security constraint attributes of all security requirements (including public security requirements (CSRs) and special security requirements (SSRs)) are converted into XML security specifications. The analysis and export functions in the Secure Tropos software are then used to automatically generate XML files. For example, for public security requirement CSR1, the XML content of the security specification related to the user identity management system can be shown in Table 6:

[0129] Table 6 Example of XML content for the security specification of the user identity management system in CSR1

[0130]

[0131]

[0132] Furthermore, the written security specifications are reviewed and verified to ensure the completeness, accuracy and consistency of the security requirements; the review and verification may use verification techniques such as code review, simulation, fuzz testing, etc., which are not specifically specified here.

[0133] If the system structure and equipment of the oil refining unit are changed during the later maintenance, it is necessary to update the system entities and subsystem entities, generate an updated security requirement report to update and maintain the safety specifications, and ensure that the safety specifications are consistent with the actual security requirements of the system.

[0134] An embodiment of the present invention provides an electronic device, characterized by comprising: a computer-readable storage medium and a processor;

[0135] The computer-readable storage medium is used to store executable instructions;

[0136] The processor is configured to read the executable instructions stored in the computer-readable storage medium and execute the method described in any one of the above embodiments.

[0137] An embodiment of the present invention provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to execute the method described in any of the above embodiments.

[0138] It will be easily understood by those skilled in the art that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for generating multiple security requirements for a petroleum refining system based on Secure Tropos, characterized in that: include: S1, determine the security protection objectives, dependency types and security threats of the oil refining unit; S2. Functionally dividing the petroleum refining system into a monitoring system, a power system, a human-computer interaction system, and refining equipment; and establishing a security entity and data interaction model for the petroleum refining system in Secure Tropos software based on the security protection objectives, security threat types, and dependency types. Dividing the petroleum refining system into a reaction and regeneration subsystem, a fractionation subsystem, and an absorption and stabilization subsystem according to the petroleum refining process flow; and establishing a security entity and data interaction model for the petroleum refining system, as well as a security entity and data interaction model for each subsystem, in Secure Tropos software based on the security protection objectives, security threat types, and dependency types. S3, determining corresponding functional requirements based on the data flow and control flow characteristics of the oil refining system, and obtaining corresponding security constraints in combination with the security protection objectives; and importing the security constraints into each model respectively; S4, perform model inspection on each model separately to obtain the corresponding inspection report; perform security constraint violation analysis on the inspection report of the security entity and data interaction model of the petroleum refining system and the inspection report of the security entity and data interaction model of each subsystem respectively to obtain the public safety requirements of the petroleum refining system and the special security requirements of each subsystem.

2. The method according to claim 1, wherein The security protection objectives include: accessibility, integrity, confidentiality, authentication, and effectiveness; The dependencies include: data dependency, timing dependency, component dependency, and functional dependency; The security threats include: denial of service, false data injection, eavesdropping, replay, malware, and viruses.

3. The method according to claim 1 or 2, wherein: After step S4, the method further includes: converting the public safety requirements and special safety requirements into public safety specifications and special safety specifications respectively in a one-to-one correspondence.

4. The method according to claim 3, wherein The public safety requirements and special safety requirements are converted into public safety specifications and special safety specifications respectively using the use case diagram in UML: The security key elements and security constraint attributes of the common security requirements and special security requirements are respectively identified, and converted into common security specifications and special security specifications in XML format through the UML model.

5. The method according to claim 4, wherein The safety-critical elements include safety-critical components, safety-critical interactions, and safety-critical behaviors; The safety constraint attributes include performance limitations, operating conditions, failure modes, fault tolerance requirements, and safety-related standards.

6. The method according to claim 3, wherein After step S4, and before converting the public safety requirements and special safety requirements into public safety specifications and special safety specifications respectively, the method further includes: The public safety needs and special safety needs are classified according to environmental constraints and divided into different safety need types.

7. The method according to claim 6, wherein The environmental constraints include: operating conditions, emissions, communications, security measures, computing resources, cyberattacks, human resources, catalyst management, wastewater management, policies and regulations, energy consumption, and water consumption; The types of security requirements include: personnel management security, asset management security, access control security, cryptographic security, physical and environmental security, operational security, communication security, system development and maintenance security, supply chain security, security incident management, business management security, and compliance management security.

8. The method according to claim 1, wherein The data stream characteristics include: real-time, continuity, diversity, and sparsity; The control flow characteristics include: sequentiality, conditionality, cyclicity, branching, abnormality, recursion, and concurrency.

9. A multiple security requirement generation system for a petroleum refining system based on Secure Tropos, characterized in that: include: Computer-readable storage medium and processor; The computer-readable storage medium is used to store executable instructions; The processor is configured to read the executable instructions stored in the computer-readable storage medium and execute the method according to any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Modeling demand entry management method based on FMEA

    CN112256238A

  • Application development security demand generation method and system

    CN116755662A