A power internet of things penetration testing method based on dynamic attack surface analysis
By employing dynamic attack surface analysis methods combined with cellular automata models, the security vulnerabilities and attack impacts of power IoT systems can be assessed in real time. This addresses the problem of existing technologies being unable to adapt to the convergence of cyber-physical domains, and enables efficient penetration testing of power IoT systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- STATE GRID LIAONING SHENYANG ELECTRIC POWER SUPPLY COMPANY
- Filing Date
- 2024-12-11
- Publication Date
- 2026-05-01
AI Technical Summary
Existing technologies cannot effectively perform dynamic attack surface analysis of power Internet of Things (IoT) systems, cannot adapt to power IoT systems that integrate the information and physical domains, and traditional methods cannot assess system security vulnerabilities in real time and optimize penetration testing strategies.
By employing a dynamic attack surface analysis approach, the system's security vulnerabilities are assessed in real time by analyzing the evolution mechanism of the information and physical domains of the power Internet of Things (IoT) system. Combined with a cellular automata model, the attack propagation mechanism is deduced, the probability of impact on devices and costs are calculated, and the penetration testing method that maximizes attack effectiveness is selected.
It enables dynamic attack surface analysis of power Internet of Things (IoT) systems, real-time optimization of penetration testing schemes, improved testing efficiency and accuracy, and a comprehensive understanding of the overall impact of attacks on the system.
Smart Images

Figure CN119696870B_ABST
Abstract
Description
A Penetration Testing Method for the Power Internet of Things Based on Dynamic Attack Surface Analysis Technical Field
[0001] This invention relates to the field of power Internet of Things (IoT) security technology, and in particular to a power IoT penetration testing method based on dynamic attack surface analysis. Background Technology
[0002] The attack surface refers to the collection of all potential entry points or vulnerabilities in a system that can be exploited by attackers, including interfaces, services, protocols, and code. Understanding the attack surface is crucial for penetration testing. It helps testers identify and prioritize system weaknesses, effectively simulate attack scenarios, concentrate resources on in-depth testing of critical entry points and services, discover potential security issues, improve testing efficiency and accuracy, provide organizations with security improvement recommendations, and reduce the risk of attacks.
[0003] In existing technologies, patent CN108881272A calculates the attack cost-effectiveness ratio based on the security threat level of the target object and the difficulty of exploiting its own vulnerabilities to obtain the attack surface of the information system; patent CN116684135A, based on this, uses Bayesian networks and population evolution algorithms to calculate the posterior probability of network nodes being attacked. However, these methods only consider the vulnerabilities of the device itself and do not consider the impact of the attack on the target system, making them unsuitable for attack surface analysis of power IoT systems. Furthermore, they are static analysis methods and cannot dynamically analyze the system when a specific attack surface is encountered. The dynamic attack surface analysis method proposed in patent CN111683057A only considers the attack surface of the communication system from the perspective of message propagation, making it difficult to adapt to power IoT systems that integrate the information domain and the physical domain.
[0004] Therefore, a new penetration testing method for the power Internet of Things needs to be proposed. Summary of the Invention
[0005] This invention aims to propose a penetration testing method for the power Internet of Things (IoT) based on dynamic attack surface analysis. By analyzing the evolution mechanism of attack damage in the information and physical domains of the power IoT system, the method can assess the current security vulnerability of the system in real time, maximize attack benefits, optimize and adjust the penetration testing plan in a timely manner, and improve testing efficiency.
[0006] To achieve the above objectives, the present invention adopts the following specific technical solution: a penetration testing method for the power Internet of Things (IoT) based on dynamic attack surface analysis, wherein the power IoT system includes an information domain and a physical domain; comprising the following steps:
[0007] Based on the topology of the information domain of the power Internet of Things system, the degree of closeness between devices and the reachability of attacks are analyzed to determine the state transition relationship of devices in the information domain under attack. Based on the state transition relationship of devices in the information domain under attack, the cellular automata model is used to deduce the attack propagation mechanism in the information domain and calculate the probability of each device in the information domain being affected. Based on the asset value of each device and the probability of being affected, the degree of impact on the information domain under specific attack scenarios is calculated.
[0008] Monitor the physical domain state of the power Internet of Things (IoT) system, calculate the trend of physical domain state changes after the system is attacked based on the state-space equation; determine the state transition relationship of physical domain nodes under attack based on the direction of power flow propagation; based on the state transition relationship of physical domain nodes under attack, use cellular automata model to deduce the attack propagation mechanism in the physical domain and calculate the probability of each physical domain node being affected; calculate the degree of impact on the physical domain under specific attack scenarios based on the asset value of each physical domain node and the probability of being affected.
[0009] The attack difficulty is assessed by comprehensively considering factors such as the difficulty of the attack script, the ease of using the attack tools, and the level of understanding of the target object; security vulnerabilities in the power Internet of Things system equipment are scanned, the exploitability of the equipment vulnerabilities is calculated based on the CVSS vulnerability evaluation index, and the attack cost is calculated based on the attack difficulty and the severity of the equipment vulnerabilities.
[0010] Based on the degree of impact on the information domain and physical domain of the power Internet of Things (IoT) system under specific attack scenarios, the overall impact on the power IoT system under specific attack scenarios is derived.
[0011] Based on the attack cost and overall impact, select the attack method that maximizes the attack effectiveness for penetration testing.
[0012] Furthermore, the analysis of the degree of closeness between devices and attack reachability, and the determination of the state transition relationships of information domain devices under attack, specifically include:
[0013] The degree of closeness between information domain devices is represented by H. i,j This can be expressed as follows:
[0014]
[0015] Where, θ i,j This represents the percentage of information exchange between device i and device j across all devices in the entire information domain.
[0016] The attack reachability between information domain devices is represented by topological centrality E. i,j It indicates that the topological centrality E i,j It can be expressed as follows:
[0017]
[0018] Where, α i,j n represents the number of device nodes between device i and device j. i The state transition relation S represents the number of devices connected to device i, n represents the total number of devices in the information domain, and l represents the communication distance; S represents the state transition relation S when a device in the information domain is attacked. i,j It can be represented as:
[0019] S i,j =ω1H i,j +ω2E i,j (3)
[0020] Wherein, ω1 and ω2 represent the weights of the two factors: the degree of closeness between devices and the attack reachability between devices.
[0021] Furthermore, based on the state transition relationships of information domain devices under attack, the cellular automata model is used to deduce the attack propagation mechanism in the information domain and calculate the probability of each device in the information domain being affected; based on the asset value of each device and the probability of being affected, the degree of impact on the information domain under a specific attack scenario is calculated, specifically including:
[0022] The probability P of each device j in the information domain being affected j It can be expressed as follows:
[0023]
[0024] The degree of impact R of the specific attack scenario a on the information domain c (a) can be expressed as follows:
[0025]
[0026] in This represents the asset value of information domain device i; 'a' represents a specific attack scenario.
[0027] Furthermore, the monitoring of the physical domain state of the power Internet of Things system, based on the state-space equation, calculates the trend of changes in the physical domain state after the system is attacked, specifically including:
[0028] The physical domain states include at least current, voltage, and power states;
[0029] The state-space equation is expressed as follows:
[0030]
[0031] in Let x represent the sensor attack and actuator attack suffered by the physical domain at time k, respectively; where x k Represents the physical domain state, u k For control commands, y k w is a sensor variable. k v k Let A represent system noise; B be the system matrix; C be the control matrix; and C be the output matrix. The state estimator is established as shown in the following equation:
[0032]
[0033] Where L k+1 Represents the gain matrix; defines the discrete state space of the physical domain; Q = {q 0 ,q 1 ,q 2 ,...,q π}, q 0 π represents the normal state of the physical domain, and π represents the sum of the discrete states of the abnormal states of the physical domain; based on the estimated state... Determine whether the physical state has changed.
[0034] Furthermore, based on the direction of power flow propagation, the specific state transition relationships of a physical domain node under attack are determined as follows:
[0035] The state transition relationship of a physical domain node under attack can be expressed by the following formula:
[0036]
[0037] F i,j (x k F represents the direction of power flow propagation at a physical domain node in a power system. i,j (x k )>0 or F j,i (x k )<0 indicates that the direction of the electric current is from physical domain node i to physical domain node j; while F i,j (x k ) = 0 indicates that there is no electrical current transmission between the two physical domain nodes;
[0038] in, Representing state From a normal state to an abnormal state; μ τ This represents the influencing factor under different abnormal states; the more severe the abnormal state, the higher the influencing factor μ. τ The larger the value of μ, the better. τ ∈[0,1].
[0039] Furthermore, by using a cellular automata model to deduce the attack propagation mechanism in the physical domain, the probability of each physical domain node being affected is calculated, specifically including:
[0040] The probability of each physical domain node being affected It can be expressed as follows:
[0041]
[0042] Furthermore, the calculation of the impact level of the physical domain under a specific attack scenario based on the asset value of each physical domain node and the probability of being affected specifically includes:
[0043] The degree of influence of the physical domain under the specific attack scenario It can be expressed as follows:
[0044]
[0045] according to The asset value of physical domain node i can be obtained under a specific attack scenario. The degree of influence of the physical domain below
[0046] Furthermore, the assessment of attack difficulty involves scanning for security vulnerabilities in the power IoT system equipment, calculating the exploitability of equipment vulnerabilities based on the CVSS vulnerability evaluation index, and calculating the attack cost based on the attack difficulty and the exploitability of equipment vulnerabilities.
[0047] Attack Cost a It can be calculated based on the exploitability Ex of the device vulnerability and the attack difficulty Ad;
[0048] The exploitability Ex of a device vulnerability can be calculated using the following formula based on the vulnerability definition in CVSS:
[0049] Ex=20×S_AV×S_AC×S_AU (11)
[0050] Where S_AV, S_AC, and S_AU represent the vulnerability's access vector, access complexity, and access permissions, respectively;
[0051] Attack difficulty Ad is calculated by comprehensively considering the attack script difficulty weight AS, the attack tool usability difficulty AE, and the degree of understanding of the target object OU. Attack difficulty Ad can be expressed by the following formula:
[0052] Ad=1-(1-AS)(1-AE)(1-OU) (12)
[0053] Attack Costa It can be expressed as follows:
[0054]
[0055] Furthermore, the step of selecting the attack method that maximizes the attack effectiveness for penetration testing based on attack cost and overall impact specifically includes:
[0056] The overall impact level is obtained by adding the impact levels of the information domain and physical domain of the power Internet of Things system under a specific attack scenario;
[0057] The overall impact of the power Internet of Things system under the specific attack scenario can be expressed by the following formula:
[0058]
[0059] Where R a , and These represent the overall impact, information domain impact, and physical domain impact on the power Internet of Things system under a specific attack scenario a.
[0060] Define the attack cost-effectiveness ratio d(a):
[0061]
[0062] For penetration testing, select the attack method Action that maximizes the attack cost d(a). Action is expressed as follows:
[0063] Action = arg max a∈[1,m] d(a) (16).
[0064] A power IoT penetration testing system based on dynamic attack surface analysis is provided to implement a power IoT penetration testing method based on dynamic attack surface analysis, comprising:
[0065] The information domain analysis module is used to analyze the degree of closeness between devices and the reachability of attacks based on the topology of the information domain of the power Internet of Things system, and to determine the state transition relationship of information domain devices under attack; based on the state transition relationship of information domain devices under attack, it uses a cellular automata model to deduce the attack propagation mechanism in the information domain and calculate the probability of each device in the information domain being affected; based on the asset value of each device and the probability of being affected, it calculates the degree of impact on the information domain under a specific attack scenario.
[0066] The physical domain analysis module is used to monitor the physical domain state of the power Internet of Things (IoT) system. Based on the state-space equation, it calculates the trend of physical domain state changes after the system is attacked; it determines the state transition relationship of physical domain nodes under attack based on the direction of power flow propagation; based on the state transition relationship of physical domain nodes under attack, it uses a cellular automata model to deduce the attack propagation mechanism in the physical domain and calculates the probability of each physical domain node being affected; based on the asset value of each physical domain node and the probability of being affected, it calculates the degree of impact on the physical domain under specific attack scenarios.
[0067] The attack cost calculation module is used to assess the attack difficulty using expert experience, scan for security vulnerabilities in power Internet of Things system devices, calculate the exploitability of device vulnerabilities based on CVSS vulnerability evaluation indicators, and calculate the attack cost based on the attack difficulty and the exploitability of device vulnerabilities.
[0068] The attack decision module is used to calculate the current attack surface of the system based on the cost of attack implementation and the degree of impact on the information and physical domains of the power Internet of Things system, and to select the attack method that maximizes the attack benefits for penetration testing.
[0069] The present invention can achieve the following technical effects:
[0070] This invention proposes a dynamic attack surface analysis method for cyber-physical systems of the power Internet of Things (IoT). It simulates the potential impact of attacks in real time, dynamically evaluates the system's attack surface, and optimizes penetration testing schemes in real time with the goal of maximizing attack benefits, thereby improving testing efficiency.
[0071] This invention uses cellular automata to extrapolate the impact of attacks on the information and physical domains of the power Internet of Things. It analyzes the impact on the information domain from the degree of closeness between devices and the reachability of attacks, and calculates the state transition relationships of physical domain nodes under attack from the physical domain state. This provides a comprehensive understanding of the overall impact of attacks on the system and solves the problem of the one-sidedness of existing attack surface analysis methods.
[0072] Traditional attack surface calculation methods only consider attack cost and vulnerability exploitability. This invention comprehensively considers three parameters—attack cost, vulnerability exploitability, and the overall impact of the attack on the system—to calculate the attack surface, which is more in line with the goal of discovering security risks through penetration testing of power Internet of Things (IoT) cyber-physical systems. Attached Figure Description
[0073] Figure 1 is a flowchart of the overall process of the power Internet of Things penetration testing method disclosed in this invention;
[0074] Figure 2 is a flowchart of the steps of the power Internet of Things penetration testing method disclosed in this invention. Detailed Implementation
[0075] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and do not constitute a limitation thereof.
[0076] This invention proposes a penetration testing method for the power Internet of Things (IoT). By simulating the harm of attacks on the information and physical domains of the power IoT, the impact of the attacks is calculated. Combining the exploitability of system vulnerabilities and the difficulty of attack implementation, the attack surface under different attack strategies is dynamically calculated, and the attack method that maximizes the current attack benefit is selected for penetration testing.
[0077] Referring specifically to Figure 1-2, a penetration testing method for the power Internet of Things (IoT) based on dynamic attack surface analysis is presented. The power IoT system includes an information domain and a physical domain; the information domain is a general term for the power information system; the physical domain is a general term for the power physical system; and physical domain nodes refer to devices within the physical domain.
[0078] The specific steps are as follows:
[0079] Step 1: Based on the topology of the information domain of the power Internet of Things system, analyze the degree of closeness between devices and the reachability of attacks to determine the state transition relationship of devices in the information domain under attack; based on the state transition relationship of devices in the information domain under attack, use the cellular automata model to deduce the attack propagation mechanism in the information domain and calculate the probability of each device in the information domain being affected; based on the asset value of each device and the probability of being affected, calculate the degree of impact on the information domain under a specific attack scenario.
[0080] The propagation impact of information domain attacks considers two factors: the degree of closeness between devices and the reachability of attacks between devices;
[0081] The degree of closeness between information domain devices is represented by H. i,j This can be expressed as follows:
[0082]
[0083] Where, θ i,j This represents the proportion of information exchange between device i and device j in the total number of devices in the information domain; where the attack reachability between devices in the information domain is represented by topological centrality E. i,j It indicates that the topological centrality E i,j It can be expressed as follows:
[0084]
[0085] Where, α i,j n represents the number of device nodes between device i and device j.i The state transition relation S represents the number of devices connected to device i, n represents the total number of devices in the information domain, and l represents the communication distance; S represents the state transition relation S when a device in the information domain is attacked. i,j It can be represented as:
[0086] S i,j =ω1H i,j +ω2E i,j (3)
[0087] Wherein, ω1 and ω2 represent the weights of the two factors: the degree of closeness between devices and the attack reachability between devices.
[0088] Then, using a cellular automata model, the attack propagation mechanism in the information domain is deduced, and the probability of each device in the information domain being affected, P, is calculated. j It can be expressed as follows:
[0089]
[0090] The degree of impact R of a specific attack scenario a on the information domain c (a) can be expressed as follows:
[0091]
[0092] in This represents the asset value of information domain device i; 'a' represents a specific attack scenario.
[0093] Step 2: Monitor the physical domain state of the power Internet of Things system; calculate the trend of physical domain state changes after the system is attacked based on the state-space equation; determine the state transition relationship of physical domain nodes under attack based on the direction of power flow propagation; use cellular automata model to deduce the attack propagation mechanism in the physical domain based on the state transition relationship of physical domain nodes under attack, and calculate the probability of each physical domain node being affected; calculate the degree of impact on the physical domain under specific attack scenarios based on the asset value of each physical domain node and the probability of being affected.
[0094] The physical domain states include at least current, voltage, and power states;
[0095] The state-space equation is expressed as follows:
[0096]
[0097] in Let x represent the sensor attack and actuator attack suffered by the physical domain at time k, respectively; where x k Represents the physical domain state, uk For control commands, y k w is a sensor variable. k v k Let A represent system noise; B be the system matrix; C be the control matrix; and C be the output matrix. The state estimator is established as shown in the following equation:
[0098]
[0099] Where L k+1 The gain matrix is represented by Q, which defines the discrete state space of the physical domain; Q = {q 0 ,q 1 ,q 2 ,...,q π}, q 0 π represents the normal state of the physical domain, and π represents the sum of the discrete states of the abnormal states of the physical domain; based on the estimated state... Determine whether the physical state has changed.
[0100] Determine the state transition relationships of a physical domain node under attack based on the direction of power flow propagation;
[0101] The state transition relationship of a physical domain node under attack can be expressed by the following formula:
[0102]
[0103] F i,j (x k F represents the direction of power flow propagation at a physical domain node in a power system. i,j (x k )>0 or F j,i (x k )<0 indicates that the direction of the electric current is from physical domain node i to physical domain node j; while F i,j (x k ) = 0 indicates that there is no electrical current transmission between the two physical domain nodes;
[0104] in, Representing state From a normal state to an abnormal state; μ τ This represents the influencing factor under different abnormal states; the more severe the abnormal state, the higher the influencing factor μ. τ The larger the value of μ, the better. τ ∈[0,1].
[0105] Using a cellular automata model, we simulate the attack propagation mechanism in the physical domain, calculate the probability of each physical domain node being affected, and the probability of physical domain node j being affected. It can be expressed as follows:
[0106]
[0107] Based on the asset value of each physical domain node and the probability of being affected, the degree of impact on the physical domain under a specific attack scenario is calculated.
[0108] according to The asset value of physical domain node i can be obtained under a specific attack scenario. The degree of influence of the physical domain below The extent of the impact of the physical domain in specific attack scenarios It can be expressed as follows:
[0109]
[0110] Step 3: Evaluate the attack difficulty based on indicators such as the difficulty of the attack script, the ease of using the attack tools, and the level of understanding of the target object; scan for security vulnerabilities in the power Internet of Things system equipment, calculate the exploitability of the equipment vulnerabilities based on the CVSS vulnerability evaluation index, and calculate the attack cost based on the attack difficulty and the severity of the equipment vulnerabilities.
[0111] Attack Cost a It can be calculated based on the exploitability Ex of the device vulnerability and the attack difficulty Ad;
[0112] The exploitability Ex of a device vulnerability can be calculated using the following formula based on the vulnerability definition in CVSS:
[0113] Ex=20×S_AV×S_AC×S_AU (11)
[0114] Where S_AV, S_AC, and S_AU represent the vulnerability's access vector, access complexity, and access permissions, respectively;
[0115] Attack difficulty Ad is calculated by comprehensively considering the attack script difficulty weight AS, the attack tool usability difficulty AE, and the degree of understanding of the target object OU. Attack difficulty Ad can be expressed by the following formula:
[0116] Ad=1-(1-AS)(1-AE)(1-OU) (12)
[0117] Attack Cost a It can be expressed as follows:
[0118]
[0119] Step 4: Based on the degree of impact on the information domain and physical domain of the power Internet of Things system under a specific attack scenario, determine the overall impact on the power Internet of Things system under the specific attack scenario;
[0120] The overall impact of the power Internet of Things system under the specific attack scenario can be expressed by the following formula:
[0121]
[0122] Where R a , and These represent the overall impact, information domain impact, and physical domain impact of a specific attack scenario a on the power Internet of Things system.
[0123] Step 5: Based on the attack cost and overall impact, select the attack method that maximizes the attack effectiveness for penetration testing.
[0124] Define the attack cost d(a):
[0125]
[0126] For penetration testing, select the attack method Action that maximizes the attack cost d(a). Action is expressed as follows:
[0127] Action = argmax a∈[1,m] d(a)(16)
[0128] During the testing process, the above steps are repeated continuously, and the attack strategy and penetration testing plan are adjusted in real time according to changes in system status in order to achieve dynamic optimization of the test.
[0129] This invention also proposes a power IoT penetration testing system based on dynamic attack surface analysis, used to implement a power IoT penetration testing method based on dynamic attack surface analysis, including:
[0130] The information domain analysis module is used to analyze the degree of closeness between devices and the reachability of attacks based on the topology of the information domain of the power Internet of Things system, and to determine the state transition relationship of information domain devices under attack; based on the state transition relationship of information domain devices under attack, it uses a cellular automata model to deduce the attack propagation mechanism in the information domain and calculate the probability of each device in the information domain being affected; based on the asset value of each device and the probability of being affected, it calculates the degree of impact on the information domain under a specific attack scenario.
[0131] The physical domain analysis module is used to monitor the physical domain state of the power Internet of Things (IoT) system. Based on the state-space equation, it calculates the trend of physical domain state changes after the system is attacked; it determines the state transition relationship of physical domain nodes under attack based on the direction of power flow propagation; based on the state transition relationship of physical domain nodes under attack, it uses a cellular automata model to deduce the attack propagation mechanism in the physical domain and calculates the probability of each physical domain node being affected; based on the asset value of each physical domain node and the probability of being affected, it calculates the degree of impact on the physical domain under specific attack scenarios.
[0132] The attack cost calculation module is used to assess the attack difficulty using expert experience, scan for security vulnerabilities in power Internet of Things system devices, calculate the exploitability of device vulnerabilities based on CVSS vulnerability evaluation indicators, and calculate the attack cost based on the attack difficulty and the exploitability of device vulnerabilities.
[0133] The attack decision module is used to calculate the current attack surface of the system based on the cost of attack implementation and the degree of impact on the information and physical domains of the power Internet of Things system, and to select the attack method that maximizes the attack benefits for penetration testing.
[0134] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0135] Although embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
[0136] The specific embodiments of the present invention described above do not constitute a limitation on the scope of protection of the present invention. Any other corresponding changes and modifications made in accordance with the technical concept of the present invention should be included within the scope of protection of the claims of the present invention.
Claims
1. A penetration testing method for the power Internet of Things (IoT) based on dynamic attack surface analysis, wherein the power IoT system includes an information domain and a physical domain; characterized in that, Includes the following steps: Based on the topology of the information domain of the power Internet of Things (IoT) system, this study analyzes the inter-device connectivity and attack reachability to determine the state transition relationships of devices under attack. Based on these state transition relationships, a cellular automata model is used to deduce the attack propagation mechanism in the information domain and calculate the probability of each device being affected. Based on the asset value and probability of each device being affected, the degree of impact on the information domain under specific attack scenarios is calculated. The study monitors the physical domain state of the power IoT system and calculates the trend of physical domain state changes after an attack based on the state-space equation. Based on the direction of power flow propagation, the state transition relationships of physical domain nodes under attack are determined. Based on these state transition relationships, a cellular automata model is used to deduce the attack propagation mechanism in the physical domain and calculate the probability of each physical domain node being affected. Based on the asset value and probability of each physical domain node being affected, the degree of impact on the physical domain under specific attack scenarios is calculated. The attack difficulty is assessed by comprehensively considering the difficulty of the attack script, the ease of using the attack tool, and the level of understanding of the target object; security vulnerabilities in the power IoT system are scanned, and the exploitability of the device vulnerabilities is calculated based on the CVSS vulnerability evaluation index; the attack cost is calculated based on the attack difficulty and the severity of the device vulnerabilities; and the overall impact on the power IoT system under a specific attack scenario is determined based on the degree of impact on the information domain and physical domain of the power IoT system. Based on the attack cost and overall impact, select the attack method that maximizes the attack effectiveness for penetration testing.
2. The penetration testing method for the power Internet of Things based on dynamic attack surface analysis according to claim 1, characterized in that, The analysis of the inter-device proximity and attack reachability to determine the state transition relationships of information domain devices under attack specifically includes: where the inter-device proximity is used as... This can be expressed as follows: (1) Among them, This represents the proportion of information exchange between device i and device j in the total number of devices in the information domain; where the attack reachability between devices in the information domain is represented by topological centrality. Represents topological centrality It can be expressed as follows: (2) Among them, This represents the number of device nodes between device i and device j. This indicates the number of devices connected to device i. Indicates the number of all devices in the information domain. Indicates communication distance; state transition relationships when information domain devices are attacked. It can be represented as: (3) Among them, , This indicates the weight of two factors: the degree of closeness between devices and the attack reachability between devices.
3. The power Internet of Things penetration testing method based on dynamic attack surface analysis according to claim 2, characterized in that, The process involves using a cellular automata model to deduce the attack propagation mechanism in the information domain based on the state transition relationships of the attacked devices, and calculating the probability of each device in the information domain being affected. Based on the asset value of each device and the probability of being affected, the degree of impact on the information domain under a specific attack scenario is calculated, specifically including the probability of each device j in the information domain being affected. It can be expressed as follows: (4) The specific attack scenario The degree of impact on the information domain It can be expressed as follows: (5) Among them This represents the asset value of information domain device i; This represents a specific attack scenario.
4. The power IoT penetration testing method based on dynamic attack surface analysis according to claim 3, characterized in that, The physical domain state of the monitored power Internet of Things system is calculated based on the state-space equation to determine the changing trend of the physical domain state after an attack. Specifically, the physical domain state includes at least current, voltage, and power states. The state-space equation is expressed as follows: (6) Among them , These represent sensor attacks and actuator attacks suffered by the physical domain at time k, respectively; where Represents the physical domain state. For control commands, For sensor variables, , Let A represent system noise; B be the system matrix; C be the control matrix; and C be the output matrix. The state estimator is established as shown in the following equation: (7) Among them Represents the gain matrix; defines the discrete state space of the physical domain; , This represents the normal state of the physical domain. This represents the sum of discrete states representing anomalies in the physical domain; based on the estimated states... Determine whether the physical state has changed.
5. The power IoT penetration testing method based on dynamic attack surface analysis according to claim 4, characterized in that, Determining the state transition relationship of a physical domain node under attack based on the direction of electric current propagation specifically includes the following: The state transition relationship of a physical domain node under attack can be expressed by the following formula: (8) This indicates the direction of power flow propagation in the physical domain nodes of the power system. or This indicates that the direction of the power flow is from physical domain node i to physical domain node j; and This indicates that there is no electrical current transfer between the two physical domain nodes; where, Representing state From a normal state to an abnormal state; This represents the influencing factors under different abnormal states; the more severe the abnormal state, the higher the influencing factor. The larger the value, and 。 6. The power IoT penetration testing method based on dynamic attack surface analysis according to claim 5, characterized in that, Using a cellular automata model, the attack propagation mechanism in the physical domain is simulated, and the probability of each physical domain node being affected is calculated, specifically including: the probability of each physical domain node being affected. It can be expressed as follows: (9)。 7. The power IoT penetration testing method based on dynamic attack surface analysis according to claim 6, characterized in that, The calculation of the impact degree of the physical domain under a specific attack scenario based on the asset value of each physical domain node and the probability of being affected specifically includes: the impact degree of the physical domain under the specific attack scenario. It can be expressed as follows: (10) According to The asset value of physical domain node i can be obtained under a specific attack scenario. The degree of influence of the physical domain below 。 8. The power IoT penetration testing method based on dynamic attack surface analysis according to claim 7, characterized in that, The assessment of attack difficulty involves scanning for security vulnerabilities in power IoT system devices, calculating the exploitability of device vulnerabilities based on CVSS vulnerability evaluation metrics, and calculating the attack cost based on the attack difficulty and the exploitability of device vulnerabilities. The attack cost specifically includes... Based on the exploitability of device vulnerabilities and attack difficulty Calculation; Exploitability of device vulnerabilities Vulnerabilities defined by CVSS can be calculated using the following formula: (11) of which 、 、 These represent the vulnerability's access vector, access complexity, and access permissions, respectively; attack difficulty. Weighting based on the difficulty of the attack script Difficulty of using attack tools The degree of understanding of the target audience Overall calculation, attack difficulty It can be expressed as follows: (12) Attack cost It can be expressed as follows: (13)。 9. The power IoT penetration testing method based on dynamic attack surface analysis according to claim 1, characterized in that, The process of selecting the attack method that maximizes attack effectiveness for penetration testing based on attack cost and overall impact specifically includes: the overall impact is derived by adding the impact levels of the information domain and physical domain of the power IoT system under a specific attack scenario; the overall impact of the power IoT system under a specific attack scenario can be expressed by the following formula: (14) of which 、 For specific attack scenarios The overall impact of the power Internet of Things system, including its impact in the information domain and the physical domain; defining the attack cost-effectiveness ratio. : (15) Choose to make the attack cost-effective The largest attack method Conduct penetration testing. It can be expressed as follows: (16)。 10. A power Internet of Things penetration testing system based on dynamic attack surface analysis, characterized in that, A penetration testing method for the power Internet of Things (IoT) based on dynamic attack surface analysis as described in any one of claims 1-9, comprising: an information domain analysis module, used to analyze the degree of closeness between devices and attack reachability based on the topology of the information domain of the power IoT system, and determine the state transition relationships of devices in the information domain under attack; based on the state transition relationships of devices in the information domain under attack, use a cellular automata model to deduce the attack propagation mechanism in the information domain, and calculate the probability of each device in the information domain being affected; and calculate the degree of impact on the information domain under a specific attack scenario based on the asset value of each device and the probability of being affected; and a physical domain analysis module, used to monitor the power IoT... The system's physical domain state is analyzed using state-space equations to calculate the trend of physical domain state changes after an attack. Based on the direction of power flow propagation, the state transition relationships of physical domain nodes under attack are determined. Based on these state transition relationships, a cellular automata model is used to deduce the attack propagation mechanism in the physical domain and calculate the probability of each physical domain node being affected. Based on the asset value of each physical domain node and the probability of being affected, the degree of impact on the physical domain under a specific attack scenario is calculated. An attack cost calculation module is used to assess the attack difficulty using expert experience, scan for security vulnerabilities in the power IoT system equipment, calculate the exploitability of device vulnerabilities based on CVSS vulnerability evaluation indicators, and calculate the attack cost based on the attack difficulty and the exploitability of device vulnerabilities. An attack decision module is used to calculate the current attack surface of the system based on the attack implementation cost and the degree of impact on the information and physical domains of the power IoT system, and select the attack method that maximizes attack effectiveness for penetration testing.
Citation Information
Patent Citations
Attack surface modeling method and device for redundant information system
CN108881272A
Method for transmitting and sharing threat information based on dynamic attack surface
CN111683057A