Cross-layer attack risk quantification method for cyber-physical system
By obtaining the topological relationship between the information layer and the physical layer asset of the industrial control system in the information physical system, mining information layer vulnerabilities and combining security weights, quantifying cross-layer attack-protecting game link risks, the shortcomings of traditional FMEA methods in cross-layer attack evaluation are solved, and the systematic identification of cross-layer attack risks are realized and the evaluation of security measures is achieved.
Patent Information
- Application Number
- CN202510804847.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-06-17
AI Technical Summary
It is difficult for the existing technology to effectively evaluate and quantify the risks of cross-layer attacks in information physics systems. The traditional FMEA method is single in the analysis dimension and cannot fully identify and quantify the interaction risks between the information layer and the physical layer, making it difficult to support priority decisions when facing cross-layer attacks.
A cross-layer attack risk quantification method for information physical systems is adopted. By obtaining the topological relationship between the information layer and the physical layer assets of the industrial control system, browses of the information layer assets are explored, and the dependence relationship between the information layer and the physical layer is established. Combining the security weights of the information layer and the physical layer, FMEA is used to quantify the risk value of each cross-layer attack-protect game link, expanding the analysis dimension of traditional FMEA, identifying the cross-layer attack chain and optimizing security measures.
It realizes systematic identification and quantification of cross-layer attack risks in information physical systems, avoids manual omissions, supports the priority ranking of cross-layer attack risks, effectively evaluates the necessity of security measures in information layer and physical layer, and enhances the security assessment capabilities of industrial control systems.
Smart Images

Figure CN120455144A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of industrial control system security and relates to a cross-layer attack risk quantification method for cyber-physical systems. Background Art
[0002] Digital transformation has significantly improved the openness and interconnectedness of Industrial Automation and Control Systems (IACS). The coupling between the information layer and the physical layer has become increasingly tight, exhibiting typical characteristics of a cyber-physical system (CPS). However, the deep integration of the information layer and the physical layer has also made IACS face unprecedented security challenges. The gradual opening up of traditional closed industrial environments, the increasing complexity of IACS system structures, the blurring of network boundaries, and the diversification of external threats have made IACS a key target for cyberattacks. In recent years, cross-layer attacks on critical infrastructure have occurred frequently. Attackers have infiltrated the physical layer through vulnerabilities in the information layer, causing production disturbances, equipment damage, and even safety accidents, posing a serious threat to industrial production safety.
[0003] Therefore, how to construct a cross-layer attack risk quantification method for cyber-physical systems and effectively evaluate the sufficiency and necessity of information layer security measures and physical layer security measures is an urgent problem that technical personnel in this field need to solve. Summary of the Invention
[0004] In view of this, the present invention proposes a cross-layer attack risk quantification method for cyber-physical systems. The FMEA covers information layer attacks, physical layer failures and cross-layer propagation paths, systematically identifies the implicit cross-layer attack chain of CPS, avoids manual omissions, and uniformly quantifies the "attack-protection" risk from a game perspective, which can effectively evaluate the sufficiency and necessity of information layer security measures and physical layer security measures.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] The present invention discloses a cross-layer attack risk quantification method for cyber-physical systems, comprising the following steps:
[0007] S1: Obtain the topological relationship between the information layer assets and physical layer assets of the industrial control system CPS;
[0008] S2: extracting the dependency relationship between information layer assets and physical layer assets based on the industrial control system architecture and historical work records, and quantifying the dependency strength according to preset indicators;
[0009] S3: Exploit vulnerabilities in information layer asset 1, determine a first potential attack type for information layer asset 1 based on the vulnerabilities, determine vulnerabilities in related information layer asset 2 and their corresponding second potential attack types based on the topological relationship of information layer asset 1, and determine whether information layer asset 2 is an attack entry point. If so, obtain the information layer asset attack chain and its quantization factor, and proceed to S4. If not, repeat S3 with information layer asset 2 as the new information layer asset 1.
[0010] S4: obtaining control instructions between the information layer assets and the physical layer assets according to the dependency relationship between the information layer assets and the physical layer assets, and forwardly predicting the physical layer asset damage chain and its quantification factor based on the abnormal state of the control instructions;
[0011] S5: Based on the information layer asset attack chain and the physical layer asset damage chain, and in combination with the security weights of the information layer and the physical layer, a cross-layer attack-protection game link is established;
[0012] S6: Based on the quantitative factors of the information layer asset attack chain, the quantitative factors of the physical layer asset damage chain, and the security weights of the information layer and physical layer, use FMEA to quantify the risk value of each cross-layer attack-protection game link.
[0013] Preferably, the information layer assets in S1 include one or more of the following: software assets, network assets, protocol assets, and data assets.
[0014] Preferably, the physical layer assets in S1 include one or more of the following: sensor assets, actuator assets, and production equipment assets.
[0015] Preferably, in S2, the association mode factor and the impact timeliness factor are used as preset indicators to quantify the dependency intensity.
[0016] Preferably, in the information layer attack chain of S3:
[0017] Quantify the vulnerability maturity V of the information layer asset attack chain based on the vulnerability of the information layer asset 2 matu and exploit complexity C comp ;
[0018] Attack entry exposure L based on the attack entry quantification information layer asset attack chain expo .
[0019] Preferably, the second information layer asset in S3 is an adjacent or upper-level information layer asset associated with the first information layer asset.
[0020] Preferably, the step S4 includes: obtaining the damage consequences of the physical layer assets in the physical layer asset damage chain to quantify the degree of physical impact Sphys .
[0021] Preferably, the security weights of the information layer and the physical layer are the capability coefficients of the information layer security measures and the physical layer security measures in the cross-layer attack-protection game link to detect and handle attack types.
[0022] Preferably, the information layer security measures include one or more of the following: encryption protocol, network isolation, intrusion detection, zero trust architecture, role authority management; the physical layer security measures include one or more of the following: status monitoring system, actuator authority control, and redundancy check.
[0023] Preferably, the calculation formula for quantifying the risk value of each cross-layer attack-protection game link using FMEA in S6 is:
[0024]
[0025] Where CRI is the risk value of the cross-layer attack-protection game link; L expo is the exposure of the attack entrance, which is quantified based on the attack entrance; V matu is vulnerability maturity, C comp is the vulnerability exploitation complexity, which is obtained based on the vulnerability quantification of the information layer asset 2; I s is the dependency strength between information layer assets and physical layer assets, I s The larger the value, the greater the value of the physical layer assets that the information layer assets lead to; S phys D is the physical consequence level, which is obtained by quantifying the damage consequences of physical layer assets in the physical layer asset damage chain; cyber is the information layer security weight, which is quantified based on the attack detection capability of information layer security measures; D phys is the security weight of the physical layer, which is quantified based on the fault detection capability of the physical layer security measures; α and β are adjustment factors.
[0026] It can be seen from the above technical solutions that, compared with the prior art, the beneficial effects of the present invention include:
[0027] The present invention achieves the expansion of analysis dimensions, innovates cross-layer analysis tools, and further enhances quantitative models. For the first time, a cross-layer "attack-protection" chain is defined in FMEA, supporting the "network attack causing physical failure" scenario unique to CPS, covering information layer attacks, physical layer failures, and cross-layer propagation paths. Construct an information layer-physical layer dependency matrix, quantify the dependency strength between information layer assets and physical layer assets, and systematically identify the implicit cross-layer attack chain of CPS to avoid manual omissions. Integrate information security indicators (such as attack entry exposure and vulnerability maturity) with traditional RPN, unify the "attack-protection" risks from a quantitative game perspective, support the priority sorting of cross-layer attack risks, and effectively evaluate the sufficiency and necessity of information layer security measures and physical layer security measures. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only embodiments of the present invention. Those skilled in the art can also derive other drawings based on the provided drawings without inventive effort.
[0029] Figure 1 A flowchart of a method for quantifying cross-layer attack risks in cyber-physical systems provided by an embodiment of the present invention;
[0030] Figure 2 This is a diagram of the IACS architecture provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0031] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0032] In order to fully explain the specific embodiments of the present invention, the cyber-physical system and the Failure Mode and Effect Analysis (FMEA) method are first described as follows:
[0033] The cyber-physical system (CPS) is divided into the information layer and the physical layer, and the two layers use a complex association and interaction mechanism to realize data upload and download.
[0034] FMEA is a key method in the field of equipment system safety analysis. FMEA analyzes each possible failure of mechanical equipment (note: mechanical equipment does not possess CPS characteristics), determines its potential consequences, and analyzes the effectiveness of existing preventive or detection measures to generate a comprehensive risk qualitative analysis method. Based on the magnitude of the risk, targeted improvements are implemented to reduce the likelihood of failure, enhance the ability to detect failures, mitigate their impact, and improve their controllability, ensuring the long-term continuous operation of the equipment.
[0035] Traditional FMEA has two shortcomings when applied to cross-layer attack modeling and risk analysis in industrial cyber-physical systems:
[0036] Only physical device failures are analyzed, ignoring the information layer and cross-layer interaction risks, resulting in a single analysis dimension.
[0037] The risk priority number RPN (formula S·O·D) is not included in information security indicators. When quantifying the risk of CPS cross-layer attacks, it is insufficient to support priority decisions.
[0038] In order to overcome the above-mentioned shortcomings of traditional FMEA, an embodiment of the present invention provides a cross-layer attack risk quantification method for cyber-physical systems.
[0039] like Figure 1 As shown, the method of the embodiment of the present invention mainly includes the following steps:
[0040] S1: Obtain the topological relationship between the information layer assets and physical layer assets of the industrial control system CPS;
[0041] S2: Extract the dependency between information layer assets and physical layer assets based on the industrial control system architecture and historical work records, and quantify the dependency intensity based on preset indicators;
[0042] S3: Discover vulnerabilities in information layer asset 1, determine the first potential attack type of information layer asset 1 based on the vulnerabilities, determine the vulnerabilities of related information layer asset 2 and their corresponding second potential attack types based on the topological relationship of information layer asset 1, and determine whether information layer asset 2 is an attack entry point. If so, obtain the information layer asset attack chain and its quantification factor, and proceed to S4. If not, information layer asset 2 is treated as the new information layer asset 1 and S3 is repeated.
[0043] S4: Obtain control instructions between information layer assets and physical layer assets based on their dependency relationships, and forward-predict the physical layer asset damage chain and its quantification factor based on the abnormal status of the control instructions;
[0044] S5: Based on the information layer asset attack chain and the physical layer asset damage chain, and combining the security weights of the information layer and the physical layer, a cross-layer attack-protection game chain is established;
[0045] S6: Based on the quantitative factors of the information layer asset attack chain, the quantitative factors of the physical layer asset damage chain, and the security weights of the information layer and physical layer, use FMEA to quantify the risk value of each cross-layer attack-protection game link.
[0046] In one embodiment, the information layer assets in S1 include one or more of the following: software assets, network assets, protocol assets, and data assets.
[0047] In this embodiment, software assets generally include SCADA software, PLC control logic, HMI interface, etc.; network assets include communication protocols, routers, firewalls, etc.; data assets include real-time databases, historical databases, identity authentication information, etc.
[0048] In one embodiment, the physical layer assets in S1 include one or more of the following: sensor assets, actuator assets, and production equipment assets.
[0049] In this embodiment, sensor assets include temperature sensors, pressure sensors, flow sensors, lidars, etc.; actuator assets include circuit breakers, frequency regulators, etc.; production equipment includes pumps, motors, reactors, etc.
[0050] In one embodiment, based on the asset list, a two-dimensional matrix (columns: information layer assets, rows: physical layer assets) between information layer assets and physical layer assets is established to visualize the dependency between the information layer and the physical layer in the CPS and convey the potential paths of cross-layer attacks. The dependency between information layer assets and physical layer assets is extracted from system architecture diagrams, communication protocol documents, fault history records, system logs, and network traffic monitoring data, and the dependencies between assets are marked in a table, as shown in Table 1.
[0051] Table 1 Dependency example
[0052]
[0053] For example, the dependency relationship between the information layer asset "Modbus TCP communication protocol" and the physical layer asset "PLC controller" is: the PLC controller relies on the Modbus protocol to receive control instructions.
[0054] In one embodiment, the dependency strength in S2 is defined as the degree of association between information layer assets and physical layer assets. The degree of association is quantified by two indicators: the mode of association (such as direct or indirect) and the timeliness of impact. The quantification basis is shown in Table 2.
[0055] Table 2 Quantitative basis of dependency intensity
[0056]
[0057] Dependence intensity is I s From the attacker’s perspective, this indicator represents the value of the attack path. s A larger value indicates that the value of the physical layer assets to which the information layer assets lead is greater, and the associated information layer assets are more valuable and more likely to become high-priority attack targets. The CPS asset dependency strength is visualized using a matrix, as shown in Table 3.
[0058] Table 3 Example of dependency strength
[0059] Information layer / physical layer PLC controller pressure sensor motor ModbusTCP communication protocol 3 — — Real-time Database — 3 — User identity authentication system — — 3
[0060] In one embodiment, S3-S5 are the modeling process of the "attack-defense" chain. "Attack-defense" chain modeling involves analyzing the potential paths an attacker can take from the information layer to the physical layer to successfully infiltrate and compromise the system, as well as the series of security measures that need to be bypassed or penetrated during this process. The present invention utilizes an improved FMEA method to implement "attack-defense" chain modeling.
[0061] Traditional FMEA focuses only on the failure of physical layer assets and lacks the assessment of information layer assets (software, network, data) and cross-layer interaction risks. In order to be applicable to CPS cross-layer attack chain modeling, this paper expands the traditional FMEA analysis dimensions, specifically including:
[0062] ① New information layer attack mode, expanding threats such as man-in-the-middle attacks on information layer assets, data tampering, and identity forgery as causes of physical layer failures;
[0063] ②Based on the dependency relationship and dependency strength between the information layer and the physical layer, conduct CPS cross-layer attack impact analysis. The specific modeling steps of the "attack-protection" chain are as follows:
[0064] Step 1: According to the CPS dependency intensity (I s ) matrix, select the information layer and physical layer assets with dependency intensity of "high level" and "medium level" as modeling objects.
[0065] Step 2: Analyze the potential attack types of the modeled object as a starting point for failure mode analysis. Since an attack is considered successful only if a threat successfully exploits a vulnerability, the potential attack type depends on the vulnerabilities of the information layer assets in the modeled object. For example, the PLC and actuator communicate via the Modbus TCP protocol. Modbus / TCP is plaintext communication and has the protocol vulnerability of "no encryption or authentication enabled." Therefore, the potential attack type is the exploitation of protocol vulnerabilities, which can manifest in man-in-the-middle attacks, replay attacks, and other forms. Typical attack types are shown in Table 4.
[0066] Table 4 Typical attack types
[0067]
[0068]
[0069] Step 3: Based on the asset topology relationship of CPS, reversely analyze the adjacent or upper-level information layer assets associated with the information layer assets in step 2, and analyze the vulnerabilities of the adjacent or upper-level information layer assets (used to quantify the vulnerability maturity V matu and exploit complexity C comp ) and its potential attack type as the information layer cause. If the information layer asset concerned in this step still has associated upper-level information layer assets, continue to analyze vulnerabilities and potential attack types until the attack entrance is analyzed (used to quantify the attack entrance exposure L expo ), typical attack entrances are shown in Table 5.
[0070] Table 5 Typical attack entrances
[0071]
[0072]
[0073] Step 4: Obtain the control relationship between the information layer assets and the physical layer assets from the dependency matrix. This control relationship is achieved through control instructions (such as valve opening, speed increase). Therefore, analyze the abnormal status of the control instructions between the information layer assets and the physical layer assets (such as control instruction delay, tampering, duplication, etc.), and positively predict the damage chain of the physical layer assets, abnormal status, such as excessive speed, equipment damage, and even process disturbances (used to quantify the degree of physical impact S phys ).
[0074] Step 5: Combine the information layer asset attack chain in step 3 and the physical layer asset damage chain in step 4 to ultimately form a cross-layer attack chain from the attacker's perspective.
[0075] Step 6: For each cross-layer attack chain, analyze the information layer security measures and physical layer security measures to form a cross-layer "attack-defense" chain from the perspective of the game between attackers and defenders.
[0076] In one embodiment, the security weights of the information layer and physical layer in S6 are the coefficients of the ability of the information layer security measures and physical layer security measures in the cross-layer attack-protection game link to detect and handle attack types. This step requires a comprehensive risk analysis of each cross-layer attack-protection game link. By evaluating the combined impact of "the likelihood of an attack event under the influence of information layer security measures," "the severity of the physical impact caused by the attack," and "the detectability of information layer and physical layer security measures," the adequacy of existing information layer and physical layer security measures is evaluated, and the security measures that need to be taken are prioritized.
[0077] Traditional FMEA uses the risk priority number (RPN), as shown in Formula 1. This comprehensive indicator achieves semi-quantitative calculation of failure risk. However, it does not consider the information security weights (such as attack probability and attack detection capability) in the cross-layer "attack-defense" chain and cannot be applied to the quantitative analysis of cross-layer attack risks at the CPS system level.
[0078] RPN=S·O·D (1)
[0079] Where S is the severity of the impact of equipment physical failure;
[0080] O represents the probability of a physical device failure. Physical device failures are objective and random, and their average probability or frequency can be calculated using historical failure data. However, attacks at the information layer are subjective and malicious, and their likelihood is closely related to factors such as the exposure of the attack entry point, vulnerability maturity, exploit complexity, and asset value. Traditional methods for analyzing the probability of physical failures are not applicable to information security attacks.
[0081] D is the undetectability of physical failures of the equipment.
[0082] To this end, an embodiment of the present invention proposes a comprehensive risk quantification calculation method for a cross-layer "attack-protection" chain, as shown in Formula 2:
[0083]
[0084] Where CRI is the risk value of the cross-layer attack-protection game link;
[0085] L expo The exposure of the attack entrance is obtained based on the quantification of the attack entrance. This indicator quantifies the CPS
[0086] The system's external exposure, that is, the accessibility of attack entrances, is quantified based on Table 6.
[0087] V matu Vulnerability maturity is obtained based on the vulnerability quantification of information layer asset 2. This indicator quantifies the vulnerability's disclosure, the development of exploit tools, and the difficulty of attackers exploiting it. The quantification basis is shown in Table 7.
[0088] CC comp The complexity of vulnerability exploitation is quantified based on the vulnerability of information layer asset 2. This indicator quantifies the attacker's technical capabilities and understanding of the control system. The quantification basis is shown in Table 8.
[0089] I s The dependency strength between information layer assets and physical layer assets. This indicator quantifies the impact of information layer assets on physical layer assets. From the attacker’s perspective, this indicator indicates the attack I s The larger the value, the greater the value of the physical layer assets to which the information layer assets lead, and the value of the associated information layer assets;
[0090] S phys The physical consequence level is obtained based on the quantification of the damage consequences of the physical layer assets in the physical layer asset damage chain. The quantification basis is shown in Table 9;
[0091] D cyber The information layer security weight is obtained based on the attack detection capability of information layer security measures. This indicator quantifies the ability of information security measures to detect and deal with threats after the attack enters the CPS. The quantification basis is shown in Table 10.
[0092] D phys The security weight of the physical layer is quantified based on the fault detection capability of the physical layer security measures. This indicator quantifies the ability of the physical layer security measures to detect and control physical layer faults caused by attackers exploiting vulnerabilities. The quantification basis is shown in Table 11.
[0093] α and β are adjustment factors. If α = β, information layer security measures and physical layer security measures are of equal importance. If α > β, it indicates that stakeholders prioritize the leading role of information layer security measures and emphasize moving prevention barriers forward. If α < β, it indicates that stakeholders prioritize the emergency response capabilities of physical layer security measures and emphasize the timely detection and control of physical damage effects.
[0094] In this embodiment, the information layer security measures include one or more of the following: encryption protocol, network isolation, intrusion detection, zero trust architecture, and role authority management; the physical layer security measures include one or more of the following: status monitoring system, actuator authority control, and redundancy check.
[0095] Table 6 Quantitative basis for attack entry exposure
[0096]
[0097] Table 7 Quantitative basis of vulnerability maturity
[0098]
[0099] Table 8 Quantitative basis for vulnerability exploitation complexity
[0100]
[0101]
[0102] Table 9 Quantitative basis for physical consequence levels
[0103]
[0104] Table 10 Quantitative basis for attack detection capability of the information layer
[0105]
[0106]
[0107] Table 11 Quantification basis of fault detection capability of the physical layer
[0108]
[0109] Compared with traditional RPN, this indicator comprehensively considers the attack entry exposure (L expo ), vulnerability maturity (V matu ), vulnerability exploitation complexity (C comp ), the information layer and the physical layer dependence intensity (I s ), physical layer impact consequences (S phys ), information layer attack detection capability (D cyber ), the fault detection capability of the physical layer (D phys ) seven dimensions, which fully reflect the attack and defense capabilities of attackers and defenders in the supply-side game process. expo 、V matu 、C comp The three indicators can characterize the attack possibility as a whole; s Indicates the priority of the target being attacked; D cyber 、D phys The two indicators comprehensively represent the security monitoring and response capabilities along the entire path from threat attack to physical destruction.
[0110] In order to demonstrate the application process of the method proposed in the present invention in detail, the fractionation tower process and the associated IACS are selected as the application objects, such as Figure 2 shown.
[0111] First, we conduct system layer modeling. The information layer assets and physical layer assets are shown in Table 12 and Table 13 respectively.
[0112] By extracting the dependency relationships, we obtain the correlation matrix between the information layer assets and the physical layer, as shown in Table 14;
[0113] The dependence strength between them is quantified according to Table 2, and the results are shown in Table 15.
[0114] Then, we conduct cross-layer “attack-defense” chain modeling, and some of the results are listed in columns 1 to 4 of Table 16;
[0115] Finally, the comprehensive risk factor was calculated according to Formula 2, and the results are listed in Table 16.
[0116] Table 12 Information layer assets
[0117] Information layer assets Description of use Engineer Station Used to configure, debug and maintain DCS controller logic and parameters Operator Station Human-machine interface (HMI), which displays real-time data and supports manual control operations DCS system server Core data processing unit, stores historical data and coordinates control logic Enterprise Management Information System Integrate production data for business management Terminal office computer Terminal devices in the office network may access the DCS system Internet Publishing Remote access interface provided to the outside world DCS controller Core device that executes control logic and communicates with physical devices via fieldbus TCP / IP Network communication protocol, supporting data transmission between DCS and upper system Modbus Industrial communication protocol, connecting DCS controllers and field devices
[0118] Table 13 Physical layer assets
[0119] Physical layer assets Description of use Temperature sensor TI-109 Sense the incoming material temperature of the distillation tower Flow sensor FIT-101 Sense the incoming flow rate of the distillation tower Flow sensor FIT-102 Sense the flow rate of the distillation tower top reflux Flow solenoid valve FV-101 Adjust the feed flow rate of the distillation tower Reflux pump P-102 Drive the overhead medium circulation of the fractionation tower
[0120] Table 14 Dependencies between information layer assets and physical layer assets
[0121]
[0122]
[0123] Table 15 Dependence intensity
[0124]
[0125]
[0126] Table 16 Comprehensive risk analysis results (partial examples)
[0127]
[0128]
[0129] Note: In this case, α=β=0.5
[0130] The above is a detailed introduction to the cross-layer attack risk quantification method for information-physical systems provided by the present invention. In this embodiment, specific examples are used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
[0131] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined in this embodiment may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown in this embodiment, but is intended to conform to the widest scope consistent with the principles and novel features disclosed in this embodiment.
Claims
1. A cross-layer attack risk quantification method for cyber-physical systems, characterized by: The steps include: S1: Obtain the topological relationship between the information layer assets and physical layer assets of the industrial control system CPS; S2: extracting the dependency relationship between information layer assets and physical layer assets based on the industrial control system architecture and historical work records, and quantifying the dependency strength according to preset indicators; S3: Exploit vulnerabilities in information layer asset 1, determine a first potential attack type for information layer asset 1 based on the vulnerabilities, determine vulnerabilities in related information layer asset 2 and their corresponding second potential attack types based on the topological relationship of information layer asset 1, and determine whether information layer asset 2 is an attack entry point. If so, obtain the information layer asset attack chain and its quantization factor, and proceed to S4. If not, repeat S3 with information layer asset 2 as the new information layer asset 1. S4: obtaining control instructions between the information layer assets and the physical layer assets according to the dependency relationship between the information layer assets and the physical layer assets, and forwardly predicting the physical layer asset damage chain and its quantification factor based on the abnormal state of the control instructions; S5: Based on the information layer asset attack chain and the physical layer asset damage chain, and in combination with the security weights of the information layer and the physical layer, a cross-layer attack-protection game link is established; S6: Based on the quantitative factors of the information layer asset attack chain, the quantitative factors of the physical layer asset damage chain, and the security weights of the information layer and physical layer, FMEA is used to quantify the risk value of each cross-layer attack-protection game link.
2. A cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: The information layer assets in S1 include one or more of the following: software assets, network assets, protocol assets, and data assets.
3. The cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: The physical layer assets in S1 include one or more of the following: sensor assets, actuator assets, and production equipment assets.
4. The cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: In S2, the association mode factor and the impact timeliness factor are used as preset indicators to quantify the dependency intensity.
5. The cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: In the S3 information layer attack chain: Quantify the vulnerability maturity V of the information layer asset attack chain based on the vulnerability of the information layer asset 2 matu and exploit complexity C comp ; Attack entry exposure L based on the attack entry quantification information layer asset attack chain expo .
6. The cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: The second information layer asset in S3 is an adjacent or upper-level information layer asset associated with the first information layer asset.
7. The cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: The S4 includes: obtaining the damage consequences of the physical layer assets in the physical layer asset damage chain, which is used to quantify the physical impact degree S phys .
8. The cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: The security weights of the information layer and the physical layer are the capability coefficients of the information layer security measures and the physical layer security measures in the cross-layer attack-protection game link to detect and handle attack types.
9. A cross-layer attack risk quantification method for cyber-physical systems according to claim 8, characterized in that: The information layer security measures include one or more of the following: encryption protocols, network isolation, intrusion detection, zero trust architecture, and role authority management; the physical layer security measures include one or more of the following: status monitoring system, actuator authority control, and redundancy check.
10. The cross-layer attack risk quantification method for cyber-physical systems according to claim 1, characterized in that: The calculation formula for quantifying the risk value of each cross-layer attack-protection game link using FMEA in S6 is: Where CRI is the risk value of the cross-layer attack-protection game link; L expo is the exposure of the attack entrance, which is quantified based on the attack entrance; V matu is vulnerability maturity, C comp is the vulnerability exploitation complexity, which is obtained based on the vulnerability quantification of the information layer asset 2; I s is the dependency strength between information layer assets and physical layer assets, I s The larger the value, the greater the value of the physical layer assets that the information layer assets lead to; S phys The physical consequence level is obtained by quantifying the damage consequences of the physical layer assets in the physical layer asset damage chain; D cyber is the information layer security weight, which is quantified based on the attack detection capability of information layer security measures; D phys is the security weight of the physical layer, which is quantified based on the fault detection capability of the physical layer security measures; α and β are regulatory factors.
Citation Information
Patent Citations
High-risk line combinational analysis method of electric power information physical system
CN113987852A
Denial of service attack method for remote state estimation of information physical system
CN115840363A
Information physics power system defense method, device and equipment based on security game
CN117134987A
Risk quantification method, device and system of electric power information physical system
CN118199960A
Information-physical fusion network attack detection method of multi-robot system
CN118523928A
Cited By
Cybersecurity architectures for multi-contextual risk quantification
US12712909B2
Cybersecurity architectures for multi-contextual risk quantification
US20250294047A1