Failure chain quantitative analysis and risk assessment method and system based on multi-level security model
By constructing a directed acyclic graph through a multi-level safety model and conducting risk quantification and network analysis, the lack of identification and risk assessment of dynamic failure paths in complex social and technical systems is solved, and a comprehensive and accurate analysis of accidents and precise control of risks are achieved, thereby improving the level of safety management.
Patent Information
- Application Number
- CN202510790606.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-26
AI Technical Summary
Existing technologies have shortcomings in the dynamic failure path identification, quantitative risk assessment, networked integrated analysis and model verification of complex socio-technical systems, making it difficult to achieve comprehensive and accurate analysis of accidents and precise control of risks.
A multi-level security model is used to construct a directed acyclic graph to identify multi-dimensional failure chains. The Delphi method and hierarchical analysis method are combined to quantify risks. A directed weighted failure propagation network is constructed to perform topological feature analysis. Through reverse tracing and forward propagation path verification, critical failure chains and propagation paths are identified.
It has achieved an in-depth understanding and precise control of risks in complex social and technological systems, provided scientific risk control strategies, and improved accident prevention capabilities and safety management levels.
Smart Images

Figure BDA0005448344890000106 
Figure BDA0005448344890000108 
Figure BDA0005448344890000151
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of safety analysis and risk assessment of complex social-technical systems, and specifically to a method and system for dynamic failure chain identification, quantitative evaluation and networked integrated analysis based on a multi-level causal model, which is particularly suitable for accident cause analysis, failure propagation path identification, key risk factor identification and risk control strategy formulation of high-risk industrial systems (i.e., social-technical systems, also involving personnel, management and technical facilities) such as offshore oil platforms, chemical plants, nuclear power facilities, aerospace and large transportation hubs. The present invention aims to address the shortcomings of existing technologies in systematically extracting multi-dimensional failure chains, scientifically quantifying their risk contributions, integrating and analyzing the network structure characteristics of failure chains, and verifying the reliability of accident cause analysis and risk assessment results. By proposing a comprehensive analysis method that integrates reverse accident cause tracing and forward risk propagation path verification, the present invention provides technical support for improving the safety management level and accident prevention capabilities of complex systems. Background Art
[0002] With the rapid development of modern industrial technology and the continuous expansion of system scale, the safe operation of complex socio-technical systems has become a core issue in ensuring social stability and sustainable economic development, and is the cornerstone of the sustainable development of modern industrial society. However, due to the inherent high complexity, tight coupling between components, the dynamic nature of human-machine-environment interactions, and the severity of potential accident consequences, these systems face diverse and severe risk challenges, posing a significant challenge to traditional safety analysis and risk management methods.
[0003] Traditional linear accident causal models (such as the "domino model") or analysis methods based on single failure modes (such as fault tree analysis (FTA) and event tree analysis (ETA), while important in analyzing specific failure modes and linear causal relationships, often fall short when faced with systemic accidents caused by multiple factors, cross-level interactions, and dynamic interactions. These traditional methods struggle to fully reveal the complete evolutionary path and complex causal network of systemic accidents caused by the interaction of deep-seated, high-level factors such as organizational management deficiencies, poor decision-making, and a poor safety culture with specific technical failures, human errors, and environmental factors. This leads to inaccurate and incomplete analyses of disasters and accidents.
[0004] The AcciMap (Accident Map) model, a widely used theoretical framework for systemic accident analysis, effectively identifies and reveals the widespread, cross-level contributing factors and organizational management deficiencies behind accidents by deconstructing sociotechnical systems into multiple interconnected layers, from macro-level government regulations and policies, industry oversight, to meso-level organizational management and decision-making, and finally to micro-level technology and operations, physical processes, and equipment environments. This multi-layered perspective helps fundamentally understand the systemic root causes of accidents.
[0005] However, despite the significant theoretical advantages of the AcciMap model, the current application practice of the AcciMap model still largely remains at the level of qualitative description, post-analysis, and graphical display. In actual application, there are still key limitations that restrict the depth and breadth of active risk prediction and precise risk control. It generally lacks the ability to accurately identify and systematically extract the dynamic propagation paths of failure events between different levels, making it difficult to conduct objective and quantitative comparative assessments of the risk contributions of different failure paths. It also fails to fully utilize advanced tools such as network science to analyze the overall structural characteristics and key vulnerabilities of the failure propagation network. These limitations restrict the depth and breadth of the application of the AcciMap model in active risk prediction, early identification of key risk factors, quantitative risk assessment, and the formulation of evidence-based, high-priority risk control strategies. Specifically, existing technologies have obvious deficiencies in the following key aspects:
[0006] 1. Inadequate identification and extraction of dynamic propagation paths, particularly the lack of a standardized methodological framework for the systematic identification and extraction of multi-dimensional failure chains (MDFCs): The ability to accurately identify and systematically extract the dynamic propagation paths of failure events across different hierarchical levels is generally lacking. The ability to automatically or semi-automatically identify and extract complete, logically coherent, and hierarchically constrained multi-dimensional failure chains (MDFCs) from high-level root causes to underlying accident consequences, based on clear propagation rules (especially hierarchical constraints), is insufficient. Currently, this capability primarily relies on the analyst's experience and subjective judgment. This not only impacts analysis efficiency but can also lead to the omission or misjudgment of critical failure paths, directly impacting the depth of understanding of accident evolution mechanisms and contributing to inaccurate accident analysis.
[0007] 2. Lack of quantitative assessment of risk contributions and deficiencies in the construction of a quantitative risk assessment indicator system: Traditional AcciMap analysis results often present causal relationships graphically, making it difficult to objectively and quantitatively compare and assess the risk contributions of different failure paths. The lack of a standardized, operational, and well-interpreted quantitative assessment system for multi-dimensional, cross-level failure chains that comprehensively considers key risk influencing factors such as the likelihood of failure propagation, the severity of accident consequences, and the effectiveness or penetration of existing system defense barriers makes it difficult for decision-makers to determine risk control priorities and resource allocation priorities. This also lacks a scientific basis for identifying critical risk paths and weak links among the numerous potential failure paths.
[0008] 3. Lack of network integrated analysis capabilities, and deficiencies in systemic risk network analysis: Failure to fully utilize advanced tools such as network science to integrate discrete failure chains into a unified complex network model for analysis. AcciMap itself usually does not provide the function of integrating all identified failure paths into a complex network model that can reflect all potential failure paths in the system and their mutual relationships. There is a lack of effective means to use network science theories and methods (such as centrality analysis, community discovery, etc.) to deeply explore the network topology characteristics, identify key failure nodes and key propagation links, and the overall network structure vulnerability. This makes it difficult to reveal the overall structural characteristics of the failure propagation network, key vulnerabilities, and risk convergence and diffusion patterns from a global perspective, limiting in-depth insights into systemic risks.
[0009] 4. Gaps in interaction effect assessment and model coverage integrity verification. There are deficiencies in the quantitative assessment of failure chain interactions: There is a lack of objective quantitative assessment methods, indicators, and verification mechanisms for the complex interactions that may exist between different failure chains (for example, the synergistic risk enhancement effects caused by sharing certain common failure factors), as well as whether the constructed AcciMap model and its analysis results fully capture the main risks of the system, coverage integrity, and effectiveness. This makes it difficult to guide the continuous optimization and improvement of the model.
[0010] 5. Insufficient model validation and prediction capabilities: AcciMap is primarily a post-cause tracing analysis tool. It lacks a mechanism for comparing and verifying reverse "cause tracing" results with forward risk propagation simulations or predictions. This makes it difficult to enhance the reliability of analysis results and insight into future risks, making continuous improvement and verification of the model difficult.
[0011] These limitations collectively restrict the depth and breadth of the application of the AcciMap model in proactive risk prediction, early identification of key risk factors, quantitative risk assessment, and the formulation of evidence-based, high-priority risk control strategies, making it difficult for disaster accident analysis based on traditional AcciMap to achieve ideal accuracy and guidance.
[0012] Therefore, there is an urgent need for a new technical solution that can overcome these limitations and effectively integrate the macro-level insights of multi-level system safety models with the quantitative analysis capabilities of micro-level failure propagation paths. This solution should be able to systematically identify and extract multi-dimensional failure chains, scientifically quantify their risk contributions, construct and analyze the complex networks of failure propagation, and enhance the reliability of the analysis results through innovative verification mechanisms. This will enable a more comprehensive and in-depth understanding of the risks of complex socio-technical systems, as well as more precise and efficient management and control, ultimately improving overall safety performance and accident prevention capabilities. Summary of the Invention
[0013] This invention aims to address the inaccurate and incomplete nature of existing accident analysis for complex socio-technical systems. Specifically, it addresses the significant limitations of the traditional AcciMap model in dynamic failure path identification, quantitative risk assessment, networked integrated analysis, and validation and iterative optimization of analysis results. To this end, this invention provides a method and system for quantitative failure chain analysis and risk assessment based on a multi-level safety model, aiming to achieve a deeper understanding of complex system risks and more accurate and efficient management and control.
[0014] To achieve the above objectives, the technical solutions adopted by the present invention are mainly summarized as follows:
[0015] The present invention provides a failure chain quantitative analysis and risk assessment method based on a multi-level security model. The method is applied to complex socio-technical systems. The core steps include:
[0016] 1. Systematic Hierarchical Causal Model Construction and Multidimensional Failure Chain (MDFC) Identification: First, a hierarchical AcciMap model is constructed based on historical accident data, domain expert knowledge, and the specific structure and operational characteristics of the target system. This AcciMap model is then formalized as a directed acyclic graph (DAG). Based on this graph structure, a set of multidimensional failure chains (MDFCs) is systematically identified and extracted, from high-level root failures (such as management deficiencies and decision-making errors) to low-level specific accident consequences, according to preset node attributes (such as failure modes and precipitating conditions), clear hierarchical division criteria, and the system's internal failure propagation logic and hierarchical constraint rules. This process aims to overcome the subjectivity and incompleteness of failure path identification in traditional methods.
[0017] 2. Multi-dimensional failure chain (MDFC) risk quantification: For each extracted MDFC, obtain its quantitative score based on key risk assessment dimensions including failure propagation probability (P), accident consequence severity (S) and system defense barrier penetration (D). The specific score can be obtained using expert evaluation methods such as the Modified Delphi Method. Then, the analytic hierarchy process (AHP) or other appropriate weight determination methods are used to calculate the weight coefficients of each risk assessment dimension element P, S, and D, and perform necessary logical consistency verification to ensure the rationality of the weight. Finally, based on the weighted sum model (or other applicable multi-attribute decision-making model), calculate the comprehensive failure chain importance index of each MDFC. This enables an objective and quantitative comparison of the risk contributions of different failure paths.
[0018] 3. Failure Propagation Network Construction and Topological Characteristic Analysis: All identified MDFCs are integrated to construct a complex failure propagation network topology, with various failure events as network nodes and the causal relationships between them as directed edges. Subsequently, based on the comprehensive failure chain importance index of each MDFC calculated in the previous step, the edges in the network are assigned at least one weight based on the maximum risk contribution or cumulative risk flux, thus forming a directed weighted failure network. This weighted network is then subjected to in-depth topological characteristic analysis, with various network topological characteristic metrics calculated and analyzed. These metrics include (but are not limited to): node degree and strength, average path length and network diameter, weighted clustering coefficient, weighted betweenness centrality of nodes, structural hole indicators (such as effective size and restriction degree), overall network efficiency, rich-club coefficient, and faction or community structure. These analyses help to reveal the overall structural characteristics of the network, key failure nodes, core propagation paths, and risk aggregation and diffusion patterns from a global perspective.
[0019] 4. Risk assessment, verification and control decision support: Combined with MDFC comprehensive failure chain importance index Based on the topological characteristics of the failure propagation network and the analysis results, the team first identified key failure chains, key failure nodes, and core propagation paths through reverse causal tracing (tracing back upstream from the accident consequences). Then, they innovatively employed a forward risk propagation path analysis method (starting from identified or potential risk sources and high-level failure factors, searching for propagation paths with high-risk indicators within the constructed weighted failure network) to compare and verify the key results identified through reverse tracing, thereby deepening their understanding and achieving a closed-loop and iterative optimization of the accident analysis and risk assessment process.
[0020] 5. To further deepen the analysis, this method also includes calculating the interaction effect index (IE) between different MDFCs to identify and evaluate the synergistic risk enhancement effects that may arise when multiple failure chains occur concurrently or interact. At the same time, the coverage of the AcciMap model (C Accimap ), which is used to quantitatively evaluate the degree to which the constructed AcciMap model captures the known risks or potential risk scenarios of the system, and to guide the continuous improvement and perfection of the model.
[0021] Through the implementation of the above technical solutions, the present invention can more accurately and deeply identify the key risk factors (including key failure chains, key failure nodes and key transmission paths), weak links and main risk transmission patterns in the target socio-technical system. Based on these analysis results, the present invention can generate targeted, hierarchical and operational risk control and prevention measures. The purpose is to effectively reduce the risks faced by the system by disconnecting the propagation of key failure chains, strengthening the defense capabilities of key nodes, or optimizing the overall security management system of the system, thereby providing strong technical support and decision-making basis for the formulation of scientific and effective risk prevention and control strategies, and ultimately improving the overall security management level and risk resistance capabilities of complex socio-technical systems.
[0022] On the other hand, the present invention also provides a multi-dimensional failure chain risk analysis and control system that implements the above method, and the system includes the various units described in claim 7 of the claims. The system generally includes but is not limited to the following core functional units: a data interface and model construction unit (responsible for data input, processing, and construction and formalization of the AcciMap model), a multi-dimensional failure chain identification and extraction unit (responsible for automatic or semi-automatic extraction of MDFCs based on rules), a risk quantification unit (responsible for risk dimension scoring, weight calculation, and I FCk comprehensive calculation of failure propagation networks), network modeling and analysis unit (responsible for the construction, weighting and topological feature calculation of failure propagation networks), and risk assessment, verification and decision support unit (responsible for integrating analysis results, supporting two-way verification, generating reports and assisting decision making).
[0023] The beneficial effects of the present invention are mainly reflected in:
[0024] 1. Systematic and multi-layered: By building and analyzing multi-layered safety models (such as AcciMap), we can deeply explore the underlying root causes of accidents, such as organization and management, and clearly demonstrate the propagation of failures from high-level to low-level levels, overcoming the one-sidedness of traditional methods that are often limited to direct causes.
[0025] 2. Dynamic and path-based: The static causal model is innovatively transformed into a dynamic multi-dimensional failure chain (MDFC), accurately depicting the complete path of accident evolution and dynamic propagation characteristics, which helps to understand the complex mechanism of accident occurrence.
[0026] 3. Quantification and objectivity: The failure chain importance index (I FC ), and combined with AHP and Delphi method to determine weights and expert scoring, it achieved scientific and objective quantification of the failure chain risk level, providing a basis for risk ranking and resource allocation.
[0027] 4. Networking and key point identification: By constructing a directed weighted failure network and applying complex network topology analysis methods (such as weighted centrality indicators), it is possible to identify key failure nodes, key edges (propagation paths), and structural vulnerabilities in the network at both the overall and local levels, providing precise targets for risk control.
[0028] 5. Comprehensiveness and Decision Support: Integrating advanced analytical capabilities such as sensitivity analysis, failure chain interaction effect analysis, and AcciMap model coverage assessment, the system can provide more comprehensive and in-depth risk insights and ultimately generate practical and guiding risk control measures to effectively support safety management decisions.
[0029] 6. Practicality and operability: The method and system framework proposed in this invention have clear logic, clear steps, and strong operability. They can be effectively applied to the actual accident prevention and risk management work of complex and high-risk systems such as offshore oil platforms, helping to improve their overall safety performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings in the embodiments of the present invention are briefly introduced below.
[0031] Figure 1 The present invention provides an overall flow chart of a failure chain quantitative analysis and risk assessment method based on a multi-level security model.
[0032] Figure 2 Schematic diagram of the principle of extracting multi-dimensional failure chains (MDFC) from the AcciMap model in an embodiment of the present invention.
[0033] Figure 3 This is a schematic diagram of the principle flow of the core innovative steps of “forward risk propagation path analysis” and “reverse MDFC verification” in the embodiment of the present invention.
[0034] Figure 4This is a block diagram of the main functional modules of the multi-dimensional failure chain risk analysis and control system provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0035] It should be understood that the specific embodiments described herein are intended only to explain the present invention and are not intended to limit the present invention. The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Those skilled in the art will recognize that the described embodiments are merely examples and are not intended to limit the scope of the present invention.
[0036] Example 1: A method for quantitative analysis and risk assessment of failure chains based on a multi-level security model
[0037] Reference Figure 1 This embodiment provides a failure chain quantitative analysis and risk assessment method based on a multi-level safety model, applicable to complex socio-technical systems such as offshore oil platforms. This method aims to provide a deep understanding of the causal mechanisms of accidents, the propagation paths of failures, and the overall risk profile of the system through a series of systematic and quantitative steps, and to provide decision support for the development of effective risk control measures. The method primarily includes the following core steps:
[0038] Step S101: constructing a system hierarchical causal model and identifying multi-dimensional failure chains (MDFCs).
[0039] The core purpose of this step is to structure and hierarchically sort out the accident-causing factors of complex systems and identify key failure sequences that conform to specific propagation logic, namely multi-dimensional failure chains (MDFCs). This step further includes:
[0040] S101a: Build a layered and multi-level security model (AcciMap model).
[0041] This step begins with in-depth data collection and analysis for a specific target socio-technical system (e.g., the Deepwater Horizon offshore oil platform accident as a case study). Data collection comes from a wide range of sources, including but not limited to official accident investigation reports (such as those from the U.S. Coast Guard (USCG) and the Bureau of Ocean Energy Management, Regulation, and Enforcement (BOEMRE)), relevant academic research literature, industry safety standards and specifications (such as API standards), internal enterprise safety management system documents, operating procedures, equipment maintenance records, and historical similar accident cases. Furthermore, a team of domain experts is assembled, each with extensive practical experience and theoretical knowledge in the design, construction, operation, maintenance, safety management, emergency response, and accident investigation of the target system (e.g., an offshore oil platform). Through comprehensive analysis of this multi-source information, combined with in-depth interviews and discussions with the expert team, or through structured knowledge acquisition methods (such as the Delphi method and focus groups), a hierarchical AcciMap model is constructed that reflects the complexity of the system's accident causation.
[0042] The AcciMap model deconstructs sociotechnical systems into multiple layers with inherent logical connections and mutual influences. Drawing on the classic theories of scholars such as Rasmussen and Waterson, in this embodiment, the AcciMap model can be divided into at least the following six typical layers (but not limited to these, and can be adjusted and refined based on the actual system characteristics):
[0043] 1. Government policy and budget level (L1): This level involves macro factors such as the formulation and implementation of laws and regulations at the national or regional level, the promulgation of industry safety standards, the direction of regulatory policies, and budget investment in safety research and infrastructure.
[0044] 2. Regulatory agencies and associations (L2): This covers the performance of industry regulatory bodies (e.g., BOEMRE), classification societies (e.g., ABS), industry associations (e.g., IADC) and other institutions in terms of regulation formulation, standard implementation supervision, safety inspections, qualification certification, and information sharing.
[0045] 3. Company management (L3): This refers to the decisions and actions of the company responsible for the accident (such as BP) and its major contractors (such as Transocean and Halliburton) in terms of safety policy formulation, safety management system construction and implementation, resource (human, material, and financial) allocation, safety culture cultivation, contract management, and supply chain risk control.
[0046] 4. Technical and operational management level (L4): involves meso-level management and technical activities such as specific project management processes, engineering design and construction plans, formulation and implementation of operating procedures and maintenance plans, personnel training and qualification management, risk assessment and implementation of control measures, formulation and drills of emergency plans, and work permit systems.
[0047] 5. Physical process and personnel activity layer (L5): Involves the specific operating behaviors, decision-making, communication and coordination, perception and response to equipment status and environmental conditions, and actual changes in physical process parameters (such as pressure, temperature, and flow) of on-site operators (such as drilling team leaders, operators, engineers, etc.) in specific work scenarios.
[0048] 6. Equipment and environment layer (L6): involves the design, manufacture, installation, maintenance status and inherent defects of specific physical equipment (such as BOP, cement system, drill pipe, various sensors, alarm system, etc.), as well as the influence of external working environment conditions (such as weather, sea conditions, geological conditions, etc.).
[0049] When building the AcciMap model, it's necessary to identify specific failure events, unsafe behaviors, unsafe conditions, potential defects, incorrect decisions, and management vulnerabilities at each level that are associated with accidents. The direct causal relationships between these factors, as well as between factors at different levels, are then analyzed. These causal relationships are typically represented in the AcciMap diagram using directed arrows, pointing from cause to effect (i.e., the direction of failure propagation).
[0050] S101b: The AcciMap model is formalized as a directed acyclic graph (DAG).
[0051] Each identified failure event, condition, or factor in the AcciMap model constructed in step S101a is represented as a graph node v. Each node is assigned a unique identifier and clear descriptive text. The causal relationship between nodes (i.e., the directed arrows in the AcciMap graph) is converted into a directed edge e=(v in the directed graph). i ,v j ), representing the cause node v i Points to the result node v j Thus, a directed graph G = (V, E) is formed, where V is the set of all failed nodes and E is the set of all causal edges.
[0052] To ensure the effectiveness of the subsequent path search algorithm and avoid logically infinite loops, this directed graph must be acyclic, or a directed acyclic graph (DAG). If directed loops appear during the initial formalization process due to complex feedback loops or iterative effects in the system, these loops must be properly "broken" through careful analysis and judgment by domain experts. These methods may include: identifying and removing maintaining or regulating feedback edges that are not logically part of the direct causal chain; treating certain rapidly iterating, tightly coupled causal loops as a lumped "compound event node" with a specific failure mode; or identifying and disconnecting unreasonable reverse causal connections based on the strict temporal logic of event occurrence.
[0053] During the formalization process, it is crucial to accurately assign each node v∈V in the graph G to its specific hierarchical attribute l(v)∈L in the AcciMap model. For example, levels L1 through L6 can be assigned values from 1 to 6, where smaller values represent higher levels of management or decision-making (i.e., closer to the root cause), and larger values represent lower levels (i.e., closer to the direct physical process or accident consequences). This precise assignment of hierarchical attributes is the foundation for applying hierarchical constraints during subsequent MDFC extraction.
[0054] S101c: Determine the source node set and the accident node set.
[0055] Within the constructed directed acyclic graph G, the starting and ending points of the analysis need to be defined based on pre-set screening criteria. These criteria can be based on the node's hierarchical attributes, the node's typical role in known incident chains (for example, whether it is a recognized root cause type or final incident type), and the node's nature description. This identifies two special sets of nodes:
[0056] Source node collection These nodes are typically located at higher levels of the AcciMap model (e.g., L1 "Government Policy and Budget Layer" and L2 "Regulators and Associations Layer") and represent the root causes, initial flaws, or systemic management vulnerabilities in the system that are believed to trigger a series of subsequent cascading failures. For example, in the analysis of the Deepwater Horizon accident, failure nodes related to regulatory policy exemptions and insufficient regulatory resources due to budget cuts can be identified as source nodes.
[0057] Accident node collection These nodes are typically located at lower levels of the AcciMap model (e.g., L5 "Physical Processes and Human Activities" and L6 "Equipment and Environment") and represent the ultimate undesirable top-level consequences of the system (Top Events), such as blowouts, explosions, major oil spills, casualties, etc., or the specific physical events or equipment failures that directly led to these top-level events. For example, in the Deepwater Horizon accident, nodes related to the failure of the BOP (Blowout Preventer) to successfully seal the well and the loss of wellhead integrity were identified as accident nodes.
[0058] The accurate definition of the source node and the accident node provides a clear starting point and end point for the subsequent MDFC path search.
[0059] S101d: Extracting multi-dimensional failure chains (MDFC).
[0060] Reference Figure 2 This step uses a path search algorithm in graph theory, such as a depth-first search (DFS) or breadth-first search (BFS) algorithm modified to adapt to hierarchical constraints, to systematically extract all paths starting from any source node v from the directed acyclic graph G constructed in step S101b. s ∈s, finally any accident node v t Each such path is considered as a potential multi-dimensional failure chain (MDFC).
[0061] During the path search process, the preset system failure propagation logic must be strictly applied, and this logic should prioritize the principle of decreasing or maintaining the hierarchy. If a numerical value is used to represent the hierarchy (e.g., L1=1, L2=2, ..., L6=6, the smaller the value, the higher the hierarchy), then for any directly connected node pair (v i ,v i+1 ), its hierarchical attribute value should usually satisfy l(v i )≤l(v i+1 ). This means that failures are preferentially propagated from higher levels to the same or lower levels. In addition, in order to ensure that the extracted chain truly reflects the "multi-dimensional" characteristics, that is, it spans different system levels, it is usually required that the entire path must reflect at least one significant leap from a higher level to a lower level. For example, it can be required that the source node v s The level is strictly higher than the accident node v t The level, i.e. l(v s ) <l(v t )(coded by numerical value).
[0062] All directed paths from the source node to the accident node that meet the above conditions are identified as an MDFC and collected into the MDFC set {FC k}. Each MDFCFC k Each represents a complete, logically coherent, and system-level constraint-compliant failure propagation sequence, starting from a high-level root cause, propagating and evolving through a series of intermediate failure events, ultimately leading to a specific, low-level accident consequence. To effectively control the computational complexity of path search, especially in graphs with a large number of nodes and edges, users can set a maximum path length (e.g., an upper limit on the number of nodes or edges a path can contain) as a cutoff condition for the search algorithm. Figure 2 It schematically shows how to identify and extract an MDFC that complies with hierarchical constraints (e.g., arrows are generally downward or horizontal) and spans multiple levels from an abstract multi-level causal model.
[0063] Step S102: Quantify the multi-dimensional failure chain risk.
[0064] This step aims to perform a quantitative risk assessment on each multi-dimensional failure chain (MDFC) extracted in step S101d, objectively distinguishing the contribution of different failure chains to the overall system risk. This lays the foundation for edge weighting and identification of key risk factors in subsequent network construction. This step further includes:
[0065] S102a: Scoring of the three risk factors P, S, and D.
[0066] For each MDFC identified in step S101d, it is recorded as FC k In this step, a team of experts in relevant fields will be organized to conduct independent, anonymous quantitative scoring. The composition of the expert team should ensure that they have comprehensive and in-depth knowledge and experience in the design, construction, operation, maintenance, safety management, emergency response, and accident investigation of the target socio-technical system (such as an offshore oil platform). The scoring process adopts the modified Delphi method to improve the objectivity and consistency of the scoring. The preset risk assessment dimension set includes at least the following three core risk elements:
[0067] Failure propagation probability (P): Evaluates the specific failure chain FC k Starting from its initial root cause failure event (source node), it propagates along the causal path described in the chain, and ultimately leads to the overall probability of the top-level accident event it points to. The assessment must comprehensively consider the conditional probability of each link in the chain, external influencing factors, and the effectiveness of existing control measures.
[0068] Severity of accident consequences (S): Evaluate the severity of a specific failure chain FC kOnce a pre-set top-level accident event occurs, the severity of the comprehensive losses it may cause to personnel safety (such as the number of casualties and the degree of injury), environmental ecology (such as the scope of pollution and the difficulty of recovery), equipment assets (such as direct economic losses and indirect production suspension losses), and organizational reputation.
[0069] System defense barrier penetration (D): Evaluate specific failure chains FC k During the propagation of a failure chain, the system's existing defenses, including various safety barriers (such as technical safeguards, safety instrumented systems (SIS), physical isolation), management and control procedures (such as operating procedures, maintenance systems, and emergency plans), and human intervention (such as operator emergency response and external rescue), at each link or along the entire path, failed to effectively prevent, detect, or mitigate the development of this failure chain and ultimately lead to an accident. A higher score indicates the greater the likelihood that the existing defense system will be "penetrated" or "bypassed" by this failure chain.
[0070] When scoring, experts should use a predefined Likert scale with clear descriptors and explicit grading criteria, such as a 1-5 scale. Level 1 typically represents the lowest risk scenario (e.g., P—very low probability, S—minor consequences, D—extremely difficult to penetrate / highly defended), while level 5 represents the highest risk scenario (e.g., P—extremely high probability, S—catastrophic consequences, D—extremely easy to penetrate / almost no defense). The scoring process typically involves multiple rounds (e.g., 2-3) of anonymous scoring, statistical feedback, and iterative revisions. After each round, the organizers collect all expert scores and calculate statistical metrics such as the mean, median, standard deviation, and coefficient of variation for each dimension. These statistical results, along with the processed anonymous expert opinions (especially for cases with significant discrepancies in scores), are fed back to the expert panel. Experts can review and revise their scores based on this feedback. This iterative process continues until the expert panel's opinions reach a pre-defined convergence criterion (e.g., the coefficient of variation for a particular score falls below a pre-set threshold, or the variance between two consecutive rounds of scoring is sufficiently small). Finally, the arithmetic mean or median of the expert scores of each dimension after convergence is adopted as the MDFCFC k The final quantitative score in the three dimensions of P, S, and D.
[0071] S102b: Determine the weight coefficient using the analytic hierarchy process (AHP).
[0072] In order to determine the relative importance of the three risk assessment dimensions of P, S, and D in the comprehensive assessment of the importance of the failure chain, this step uses the Analytic Hierarchy Process (AHP) to calculate their weight coefficients.
[0073] Invite the same or another group of experienced experts or decision makers to systematically compare the P, S, and D criteria against each other, with the overall objective of determining the overall risk contribution of a multi-dimensional failure chain. This comparison uses a 1-9 scale (as proposed by Saaty et al.), where 1 indicates both criteria are equally important, 9 indicates that the former is significantly more important than the latter, and the reciprocal indicates a negative relationship. Based on the results of these pairwise comparisons, a 3x3 positive and negative judgment matrix A is constructed.
[0074] Then, by calculating the maximum eigenvalue λ of the judgment matrix max and its corresponding normalized eigenvector, which is the required weight coefficient ω P 、ω S 、ω D and ensure that the sum of these weight coefficients is 1 (i.e. ω P +ω S +ω D =1). In order to test the logical consistency of the judgment made by the experts when constructing the judgment matrix, a consistency test is required. First, calculate the consistency index CI = (λ max -n) / (n-1), where n is the order of the matrix, here n = 3. Next, find the average random consistency index (RI) corresponding to the order n (for a 3-order matrix, RI is typically 0.58). Finally, calculate the consistency ratio (CR) = CI / RI. The CR value is generally required to be less than or equal to 0.10. If CR > 0.10, it indicates poor consistency of the judgment matrix, and experts should review and adjust their pairwise comparison judgments until the CR value meets the requirements.
[0075] S102c: Calculate failure chain importance index
[0076] Each MDFCFC obtained in step S102a k P k 、S k 、D k The score value and the weight coefficient ω determined in step S102b P 、ω S 、ω D , the linear weighted sum model is used to calculate the comprehensive importance index of the failure chain
[0077]
[0078] Should The index comprehensively reflects the failure chain FC k The higher the value, the greater the risk contribution of the failure chain and the more worthy of attention.
[0079] Step S103: constructing a failure propagation network and analyzing topological characteristics.
[0080] This step aims to integrate all identified and quantified MDFCs into a unified, directed, weighted complex network model and conduct an in-depth topological analysis of this network to reveal the overall structure and key characteristics of systemic risk. This step further includes:
[0081] S103a: Failure propagation network construction and topology feature analysis.
[0082] The set of all multi-dimensional failure chains {FC k First, traverse all MDFCs and collect all the non-repeated failure event nodes (i.e., nodes in the AcciMap model) that have appeared in them to form the node set V' of the constructed network. Then, traverse all MDFCs again. If any MDFCFC k In the failure event node v i Is the failure event node v j The direct predecessor node (that is, there is a directed connection v in the chain i →v j , then build a slave node v in the network i To node v j The directed edge (v i ,v j )∈E′. If a direct causal relationship between a pair of nodes appears in multiple MDFCs, during the initial topology construction phase, they correspond to only one directed edge in the network (i.e., duplicate edges are merged). This forms the initial, weightless directed failure propagation network topology G′=(V′,E′).
[0083] S103b: Assign edge weights.
[0084] The importance index I of each MDFC calculated in step S102c is obtained. FCk , for each directed edge (v i ,v j ) assign one or more weight values ω ij The present invention supports at least the following two main weight definition rules. Users can select one of them as the main analysis weight according to the analysis purpose, or calculate them simultaneously for subsequent comparative analysis:
[0085] Maximum risk contribution weight: For any edge in the network (v i ,v j ), whose weight is defined as all MDFCFCs containing this edge kThe corresponding failure chain importance index The maximum value of , that is:
[0086]
[0087] The weight is used to represent the i ,v j ) to propagate the highest potential risk level. This emphasizes that even if an edge participates in only one extremely important failure chain, it should be given a high weight, consistent with the principle of focusing on the worst-case scenario in risk management. This weight definition is intended to highlight the highest potential risk level propagated through the connection.
[0088] Cumulative risk flux weight: For any edge in the network (v i ,v j ), whose weight is defined as all MDFCFCs containing this edge k The corresponding failure chain importance index The sum of , that is:
[0089]
[0090] The weight is used to represent the flow through the specific causal connection (v i ,v j ) cumulative risk importance or risk flux. If an edge is a common link in multiple different (especially medium- and high-risk) failure chains, its cumulative weight will be high, indicating that the connection acts as a frequent or multi-source risk propagation channel in the system. This weight definition is intended to characterize the cumulative risk importance or risk flux flowing through the connection.
[0091] After assigning selected weights to all edges, a directed weighted failure propagation network G′=(V′, E′, W) is formed. The network's topology and the characteristics of key nodes can be visualized through subsequent network analysis. The calculated network topology characteristic index analysis results can be intuitively presented on the network diagram through methods such as node size, color, or edge thickness, thereby helping to understand the network's structure and risk distribution.
[0092] S103c: Network topology feature analysis.
[0093] For this constructed directed weighted failure propagation network G′, we use complex network analysis theory and corresponding computational tools (e.g., Python's NetworkX library or analysis modules integrated into the software) to calculate and analyze various network topology characteristic indicators. These indicators help to reveal the structural characteristics of the network from different perspectives, identify key nodes and edges, assess network vulnerabilities, and understand the propagation pattern of risks. The calculated indicators should at least include:
[0094] 1. Degree Centrality:
[0095] degree The number of edges pointing to node i indicates the number of direct sources that the node is affected by the failure of other nodes.
[0096] out degree The number of edges starting from node i represents the potential number of other nodes that can be directly caused to fail by the node.
[0097] Total degree The total number of connections to the node.
[0098] Degree distribution (P(k)): Analyze the probability distribution characteristics of node degrees in the network, such as whether they conform to the power law distribution (P(k) ~ k -γ ), which helps determine whether the network is "scale-free." Scale-free networks are generally robust to random failures but are very vulnerable to failures or attacks on a small number of highly connected "hubs."
[0099] 2. Strength Centrality:
[0100] Penetration strength The sum of the weights of all edges pointing to node i measures the total risk input received by the node (which can be either the highest risk or the cumulative risk, depending on the chosen weight definition).
[0101] Strength The sum of the weights of all edges starting from node i measures the total risk output that the node may cause.
[0102] Total strength The total weighted connectivity of the node.
[0103] Strength distribution (P(S)): Analyzes the distribution characteristics of node strength, which is similar to degree distribution and can reveal the structural characteristics of weighted networks and the weighted influence of key nodes.
[0104] 3. Path and distance indicators:
[0105] Average weighted shortest path length (L ω ): The average value of the weighted shortest path length between all reachable node pairs in the network. When calculating, the weight of the edge ω is usually ij The reciprocal of 1 / ω ij As the "cost" or "distance" of the path d ij .but Where N is the number of nodes, d ω(i,j) is the weighted shortest path length from node i to node j. The smaller L ω It usually indicates that the network has a "small-world" characteristic, which means that failures can quickly propagate to other parts of the network with less "risk cost".
[0106] Network diameter The maximum value of the weighted shortest path length between any two reachable nodes in the network, that is, It represents the maximum “risk cost” or the longest “risk path” required for risk to spread in the network.
[0107] 4. Aggregation indicators:
[0108] Weighted clustering coefficient Measures the degree of interconnection between node i's neighboring nodes, while also taking into account the weight of the connecting edges. For example, the definition proposed by Barrat et al. can be used: The average weighted clustering coefficient of the network is the average weighted clustering coefficient of all nodes A high clustering coefficient combined with a small average path length is a typical characteristic of a small-world network. In a failure chain network, it may indicate the existence of some highly correlated local failure modes where internal failures are easily propagated.
[0109] 5. Centrality Indicators:
[0110] Weighted betweenness centrality Measures the importance of node v as a "bridge" or "intermediary" in the network. The weighted betweenness centrality of a node is equal to the number of weighted shortest paths between all other node pairs (s, t) in the network that pass through the node v. The number of all weighted shortest paths The sum of the proportions of: When calculating, the definition of the shortest path is based on the inverse of the edge weight ( or other selected weights) as path costs. Nodes with high weighted betweenness centrality are key intervention points for controlling the propagation of high-risk failure chains.
[0111] 6. Structural Hole Spanners:
[0112] Effective size (ES) i ) measures the degree of non-redundant connections that node i has within its neighboring network. Nodes with high effective size often connect different parts of the network that are otherwise less connected, spanning so-called "structural holes" and potentially playing a unique bridging role in the spread of information or risk.
[0113] Network Constraints (C i) measures the degree of closure within the neighbor network of node i and the degree of dependence of node i on specific neighbors. Nodes with low constraints generally have more structural holes and greater autonomy and influence in the network.
[0114] 7. Network Efficiency
[0115] Global efficiency (E glob ): It is defined as the average value of the reciprocal of the weighted shortest path length between all pairs of nodes in the network, that is, It reflects the overall information or risk dissemination efficiency of the network.
[0116] Node local efficiency (E loc (i)): For node i, it is the global efficiency of the subgraph consisting of all its neighboring nodes. It reflects the robustness of communication or risk propagation between its neighboring nodes if node i is removed. The average local efficiency of the network is the average of the local efficiencies of all nodes.
[0117] 8. Core-edge structure indicators:
[0118] Rich Club Coefficient (φ(k)): measures the tendency of high-connectivity (high-intensity or high-degree) nodes in the network to connect to each other. Its calculation formula is where N k is the number of nodes with degree (or strength) greater than or equal to k, E k is the actual number of edges between these nodes. If the coefficient value (especially after normalization relative to a random network) is significantly larger than expected, it indicates the existence of a "rich club" phenomenon, that is, high-risk nodes tend to connect with each other, possibly forming a core structure where risk is concentrated.
[0119] 9. Cohesive subgroup analysis:
[0120] Clique Analysis: Identify cliques (fully connected subgraphs) and maximal cliques (cliques that cannot be expanded into larger cliques) in the network. Cliques represent highly cohesive substructures or risky modules in the network where failures can propagate rapidly.
[0121] Community Structure: Using community detection algorithms such as Louvain, the network is divided into several communities (modules), where nodes within a community are much more closely connected than nodes between communities. This helps identify relatively independent subsystems or failure mode groups within the system, either in terms of functionality or risk propagation.
[0122] The calculation results of these indicators help to reveal the system's vulnerabilities, key transmission paths and overall risk transmission characteristics from the network structure level.
[0123] Step S104: Risk assessment, verification and control decision support.
[0124] This step aims to comprehensively utilize the aforementioned MDFC quantification results and network topology analysis results to conduct a systematic risk assessment, and to improve the reliability of the assessment results through the innovative verification mechanism proposed in this invention, ultimately providing scientific decision-making support for the formulation of effective risk control and prevention measures.
[0125] S104a: Identify key risk factors (based on reverse causation results).
[0126] First, the importance index of each multi-dimensional failure chain (MDFC) calculated in step S102c is integrated Set all MDFCs according to their The values are sorted in descending order. Select the top several (for example, Top-N, or The MDFC whose value exceeds a preset threshold is regarded as the key failure chain of the system.
[0127] At the same time, combined with the network topology feature analysis results calculated in step S103c, key failure event nodes that play a key role in the network are identified. These nodes may include:
[0128] High penetration strength or high in-degree Nodes (risk convergence points);
[0129] With high strength or high degree Nodes (risk diffusion sources);
[0130] Has high weighted betweenness centrality Nodes (key control bottlenecks);
[0131] Nodes with high structural hole indicators (such as high effective scale and low constraint) (key information / risk transmitters).
[0132] Nodes that belong to the core structure of the network (such as members of the rich club, hub nodes of key communities).
[0133] Furthermore, the main risk propagation paths (i.e., a series of continuous directed edges) that connect these key nodes, have high weights themselves, or frequently appear in multiple key failure chains are identified.
[0134] Through the above identification, we can preliminarily outline the key factors that significantly contribute to the overall risk of the system and the structural vulnerabilities of the system.
[0135] S104b: Forward risk propagation path analysis and reverse cause verification.
[0136] Reference Figure 3 This invention aims to achieve mutual verification and deepen understanding of the root causes of accidents and risk propagation mechanisms through a two-way analysis approach. The specific operations are as follows:
[0137] 1. Select potential risk source nodes: From the directed weighted failure network G′ constructed in step S103a, select nodes based on their hierarchical attributes in the original AcciMap model (preferably nodes at higher levels such as L1 and L2) and / or their network topology characteristics (e.g., strength, etc.). Much greater than the penetration strength , or nodes judged by experts as the initial trigger of the system), and select one or more nodes as potential starting points for forward risk propagation analysis).
[0138] 2. Perform weighted path search and risk assessment: Starting from each selected potential risk source node, use a weighted path search algorithm (e.g., Dijkstra algorithm or its variants that are applicable to directed graphs and can handle positive weights, such as SPFA algorithm) to find the path to the network with the weight ω of the edge in the network. ij The reciprocal of (i.e. 1 / ω ij If you want to find a path that passes through high-risk connections, the cost is low. (The cost or distance is the lowest for each path.) The system searches for the lowest-cost path (i.e., the path that represents the highest risk or the most likely to spread) to each node in the preset set of accident nodes t. Alternatively, a path cost threshold or an upper limit on the path length (number of nodes) can be set, and all paths with a cost below the threshold or a length below the upper limit can be searched. For each found path, its cumulative cost (risk value) can be calculated, or the "bottleneck" edge (the edge with the highest weight or lowest cost) on the path can be identified.
[0139] 3. Visualization and presentation of path results: High-risk transmission paths (especially those with lower costs or higher risk values) obtained by the forward search in step S104b(2) are highlighted on the network diagram (for example, using different colors or thicker lines) to intuitively show how the risk is gradually transmitted from the identified source node to the final accident node.
[0140] 4. Comparative Analysis and Verification: Systematically compare the node sequences of the high-risk propagation paths obtained through the forward search with the node sequences of each chain in the MDFC set extracted through the reverse AcciMap analysis in step S101d. The comparison indicators may include:
[0141] i. Path overlap: For example, the Jaccard similarity coefficient (based on the proportion of shared nodes), edit distance, or longest common subsequence length between the forward path and each MDFC is calculated.
[0142] ii. Consistency of key node coverage: Check whether the forward path contains the key (high value) node and vice versa.
[0143] iii.Consistency of risk assessment results: Compare the cumulative risk value of the forward path with the corresponding MDFC values to see if there is a significant difference.
[0144] 5. Iterative optimization and deepening understanding:
[0145] i. Consistency increases confidence: If the high-risk transmission path obtained by forward analysis is consistent with one (or some) high-risk transmission paths, The MDFC of the value is highly consistent with the node sequence and risk assessment, which not only strengthens the judgment of the importance of the MDFC, but also indirectly verifies the rationality and comprehensiveness of the original AcciMap cause analysis and MDFC extraction.
[0146] ii. Difference-driven improvements: If there is a significant difference (for example, the forward analysis found a potential path that was not explicitly highlighted in AcciMap but has high risk transmission efficiency; or a path that is considered high If the MDFC does not show high transmission risk or low cost in the forward path analysis, further investigation is needed. This may indicate that: some key causal relationships or failure factors were omitted when constructing the AcciMap model; the MDFC extraction rules need to be adjusted; There may be deviations in the P, S, and D scores or weight settings; or the currently used edge weight definition fails to fully capture the true risk propagation characteristics in a specific scenario. Based on these analysis results, we can return to the previous steps (S101, S102, S103b) to make corresponding adjustments and optimizations, such as revising the AcciMap graph, re-evaluating parameters, or trying to re-analyze the network and forward path search using different edge weight definitions. This process forms an iterative improvement loop that helps to continuously deepen the understanding of system risks and improve the accuracy and reliability of the final assessment results.
[0147] S104c: Calculate the failure chain interaction effect index (IE).
[0148] To evaluate the potential synergistic risk effects that may arise between different MDFCs due to sharing some common failure event nodes, the i and FC jThe interaction effect index (IE) between them is calculated as follows:
[0149]
[0150] Among them: JS(FC i ,FC j ) is the failure chain FC i and FC j The Jaccard similarity of the node set is calculated as follows: Used to measure the degree of structural overlap between them. and Failure Chain FC i and FC j The importance index of the two. The average value of the two represents the average risk level when they act together. C(FC i ,FC j ) is the failure chain FC i and FC j The calculated IE value is a temporal correlation coefficient or a preset coupling strength constant between the two failure chains (for example, in the absence of precise timing data, it can be simplified to 1; if it can be determined that there is a strong promoting effect between them, it can be set to a number greater than 1). The higher the calculated IE value, the stronger the synergistic risk enhancement effect between the two failure chains may be. When the shared node fails, it may activate or accelerate the propagation of both chains simultaneously, resulting in more serious consequences than considering each chain separately. Identifying failure chain combinations with high IE values facilitates more targeted joint risk control.
[0151] S104d: Evaluate AcciMap model coverage (C Accimap ).
[0152] In order to quantitatively evaluate the degree of capture and representativeness of the key failure propagation paths of the target socio-technical system by the currently constructed AcciMap model and its extracted MDFC set, this paper introduces the AcciMap model coverage index C Accimap , its calculation formula can be defined as:
[0153]
[0154] Where: n is the total number of MDFCs extracted in step S101d. i is the i-th failure chain FC i weights (in the absence of more precise information, they can be simply set to 1, indicating that all extracted chains are equally important; or they can be given different weights based on factors such as expert judgment or their contribution to historical accidents). is the importance index of the i-th failure chain. L is the system level set of the AcciMap model. W l is the importance weight of the lth system level, reflecting the criticality of this level to the overall security of the system (it can be determined by experts using methods such as AHP. For example, the high-level policy-making and regulatory level may be given a higher weight than the specific operation level). l It is the theoretical estimate or expert evaluation value of the maximum potential failure impact that may occur at the lth system level. This can be a comprehensive indicator, for example, the I corresponding to all possible and most serious failure events at this level. FC Theoretical maximum, or an upper limit on the risk tolerance or maximum impact potential of the level set based on historical data or expert judgment. Accimap The calculated value of typically ranges between 0 and 1. A higher value indicates that the currently constructed AcciMap model and the MDFCs extracted from it better cover and represent the primary risk sources and high-risk failure propagation paths in the system. A lower value may indicate that the AcciMap model is incomplete or that there are omissions in the MDFC extraction, necessitating a return to step S101 for model review and improvement to further identify potential failure events and paths. This metric provides a useful quantitative assessment of the model's effectiveness and completeness.
[0155] S104e: Generate risk assessment report and control recommendations.
[0156] Finally, the results of all the above analysis steps are summarized, including but not limited to: the list of identified critical failure chains and their Value ranking; topological characteristics (degree, strength, centrality, etc.) of key failure event nodes and their ranking; main risk propagation paths and their characteristics confirmed by bidirectional verification; failure chain combinations with high interaction effect index (IE); AcciMap model coverage C Accimap Based on this comprehensive information, a risk assessment report with clear structure, detailed content, and both illustrations and text should be compiled.
[0157] The report should clearly describe the entire process of this risk analysis, the methods and parameters used, the main results and core findings. Specifically, it should include: the location of the main risk sources of the system; the identification of key failure chains and key nodes and the analysis of their risk contribution; a description of the overall risk situation of the system (for example, whether there are "small world" or "scale-free" characteristics, whether there are risk-concentrated "rich clubs" or highly cohesive "factions" / "communities", etc.); and an assessment of the reliability of the AcciMap model and analysis results (based on two-way verification and C Accimap ).
[0158] More importantly, based on these specific analytical findings, combined with the built-in risk control knowledge base (if the system has one) or pre-set risk response rule templates, or through expert discussions, targeted, hierarchical and classified (for example, prioritizing by risk level, control urgency, and cost-effectiveness), and actionable risk control and prevention measures are proposed. These recommendations are intended to provide users with clear action guidelines, such as:
[0159] 1. For those with high I FCk We identify the key failure chains of the network value, analyze the bottleneck links in their composition (for example, a node with a particularly high P, S or D score, or an intermediary node with high centrality), and propose specific measures to block or weaken the spread of the chain.
[0160] 2. For failure event nodes identified as having high intensity, high betweenness centrality, or other key topological characteristics, it is recommended to strengthen their monitoring and early warning, improve their redundancy design, strengthen the training of relevant operators, or improve relevant management processes and regulations.
[0161] 3. For failure chain combinations with strong interaction effects (high IE values), joint prevention and control strategies should be formulated to address the possible synergistic enhancement risks.
[0162] 4. If C Accimap If the value is low, it indicates that the AcciMap model needs to be further improved to supplement the identification of potential failure events and paths.
[0163] These specific, data-backed recommendations will effectively guide the safety management practices of the target socio-technical system, optimize resource allocation, and focus on solving key risk issues, thereby effectively reducing the overall system risk and improving accident prevention capabilities.
[0164] Example 2: Multi-dimensional failure chain risk analysis and control system
[0165] Reference Figure 4 This embodiment provides a multi-dimensional failure chain risk analysis and control system 100 that implements the above-mentioned method. The system can be deployed as a standalone desktop application (for example, by using the Python language and its related libraries such as Tkinter for GUI, Pandas for data processing, NetworkX for network analysis, Matplotlib / Seaborn for plotting, etc.), or it can be used as a core functional module of an enterprise-level security management information platform, or it can provide analysis capabilities to the outside world through Web services. System 100 mainly includes the following functional units:
[0166] 1. Data interface and model building unit 101:
[0167] This unit is the entry point for the entire system to interact with external data sources and users. It is responsible for receiving and formatting basic data, as well as building and maintaining the core accident causal model. Its main functions are further broken down into:
[0168] i. Data Receiving and Importing Module: This module provides a standardized data interface for receiving and importing essential safety-related data related to the target socio-technical system (e.g., an offshore oil platform) from various sources. This data may include, but is not limited to, structured historical accident reports (e.g., a detailed analysis of the Deepwater Horizon accident investigation report to extract the accident chain and causal factors), safety audit reports, risk assessment documents (e.g., HAZOP analysis results), system design documents (e.g., process flow diagrams (PFDs) and piping and instrumentation diagrams (P&IDs)), equipment lists and maintenance records, organizational charts, job descriptions, safety management procedures and regulations, relevant industry standards, national regulations, and policy documents. Furthermore, it supports importing domain expert experience knowledge bases collected through structured questionnaires and expert interview records. Data import should support multiple common formats, such as CSV files, XML files, database connections (e.g., ODBC, JDBC), or manual user input through a graphical interface.
[0169] ii. AcciMap Model Construction and Formalization Module: Based on input multi-source data, this module assists users (or the system semi-automatically according to preset rules) in constructing a hierarchical AcciMap model of the target system. Users should be able to define the various AcciMap model layers (such as government, regulatory, company management, technical operations, physical processes, and equipment environment), the specific failure event nodes within each layer, and the causal relationships between nodes through a graphical interface or structured text (for example, defining nodes and their attributes, and the causal connections between nodes), using the module. Internally, this module automatically or under user guidance formalizes the user-constructed AcciMap model into a computer-processable directed graph data structure, strictly ensuring that the graph is a directed acyclic graph (DAG) to prepare for subsequent MDFC extraction. During the formalization process, each node is assigned a unique ID, a descriptive label, and the attributes of the AcciMap layer to which it belongs.
[0170] 2. Multi-dimensional failure chain identification and extraction unit 102:
[0171] This unit is connected to the data interface and model building unit 101, and receives the formalized AcciMap model (DAG representation) output by unit 101. Its core function is to systematically identify and extract all defined multi-dimensional failure chains (MDFCs) from the DAG based on pre-defined rules and algorithms. Specific operations include:
[0172] i. Source node and accident node determination module: receives the source node set s and accident node set t input by the user through the user interaction interface (for example, in the result display unit 106), or automatically identified according to the preset rules built into the system (for example, automatically identifying the highest-level no-in-degree nodes in the AcciMap model as source nodes and the lowest-level no-out-degree nodes as accident nodes).
[0173] ii. Path search and hierarchical constraint application module: Built-in efficient graph path search algorithm, such as a depth-first search (DFS) algorithm or breadth-first search (BFS) algorithm specially modified to adapt to hierarchical constraints. The algorithm starts from each selected source node v s ∈s, search for all nodes that can reach any accident node v t During the search process, the preset hierarchical evolution rules (as described in claim 2, the hierarchy reduction or preservation principle is preferred) and multi-dimensional feature requirements (such as the path must cross a preset minimum number of levels) are strictly applied.
[0174] iii. MDFC set output module: All directed paths from the source node to the accident node that meet the above search conditions and constraints are identified as an MDFC. This unit organizes all extracted MDFCs into a set {FC k}, and passes this set (usually containing detailed node sequence information for each MDFC) to the risk quantification unit 103. To prevent the computational complexity explosion caused by an overly complex network or an overly long path, the unit usually allows the user to set a maximum path length (for example, the upper limit of the number of nodes contained in the path) as the cutoff condition of the search algorithm.
[0175] 3. Risk Quantification Unit 103:
[0176] This unit receives the MDFC set {FC k Its core function is to conduct a quantitative risk assessment for each MDFC and calculate its comprehensive failure chain importance index. This unit typically contains the following submodules:
[0177] The iP, S, and D Scoring Management Module provides a user interface or data interface that allows users or connected expert assessment systems to input or import quantitative scores for each MDFC's three core risk assessment dimensions: probability of failure propagation (P), severity of accident consequences (S), and penetration of system defense barriers (D). To assist experts in objective and consistent scoring, the module provides pre-defined Likert scale scoring criteria that detail the specific meaning of different scoring levels (e.g., 1-5) for each dimension. For situations requiring multiple experts to participate in scoring, the module supports the implementation of a modified Delphi method, including the collection of anonymous scores, the aggregation of scoring opinions, the calculation and feedback of statistical results (e.g., mean and standard deviation), and multiple rounds of iterative revisions until the expert opinions reach the preset convergence criteria.
[0178] ii. AHP weight calculation module: This module is used to assist users or expert teams to use the analytic hierarchy process (AHP) to determine the relative weight coefficients ω of the three risk assessment dimensions P, S, and D when calculating the importance of the comprehensive failure chain. P 、ω S 、ω D . Users can enter the pairwise comparison judgment values of the three dimensions regarding the "contribution to the comprehensive risk of the failure chain" through the interface (for example, using the 1-9 scale method), and the system will construct a 3x3 judgment matrix based on this. The module will automatically calculate the maximum eigenvalue and corresponding normalized eigenvector (i.e., weight coefficient) of the judgment matrix and perform a consistency ratio (CR) test. If the CR value does not meet the requirements (for example, greater than 0.10), the system will prompt the user to adjust the judgment matrix.
[0179] iii.I FC Computing module: After obtaining each MDFCFC k P, S, D score values (P k 、S k 、D k ) and the weight coefficients of each dimension determined by AHP (ω P 、ω S 、ω D ) After that, the module strictly follows the preset weighted sum model formula To calculate the comprehensive failure chain importance index of each MDFC Calculated The values will serve as important inputs for subsequent network construction and risk assessment and will be attached to the corresponding MDFC data.
[0180] 4. Network Modeling and Analysis Unit 104:
[0181] This unit receives the risk quantification unit 103, to which the importance index has been added. The core function of this unit is to integrate discrete MDFCs into a holistic weighted network model and perform in-depth topological feature analysis on this network. This unit usually contains the following submodules:
[0182] i. Network construction module: This module is responsible for mapping all failure event nodes in the MDFC and the direct causal relationships between them into a directed graph. Specifically, it traverses all MDFCs and takes all non-repeated failure event nodes as the node set V′ of the network G′. For any two directly connected nodes v in the MDFC, i to v j , create a corresponding directed edge (v i ,v j )∈E′. Then, according to the weights selected by the user, the rules are defined (such as the maximum risk contribution weight or cumulative risk flux weight and each MDFC Value, assign a corresponding weight value ω to each edge in the network ij , thus forming a directed weighted failure propagation network G′=(V′,E′,W). The key topological features and risk distribution of this constructed network can be revealed through subsequent analysis and visualization methods. By rendering the network graph, analysis results such as key nodes, community structure, or risk propagation paths can be intuitively displayed.
[0183] ii. Topology analysis module: This module integrates a variety of complex network analysis algorithms (usually implemented by calling mature graph theory or network science computing libraries, such as Python's NetworkX), and is used to calculate various macro and micro topological characteristic indicators of the constructed weighted failure network, as listed in claim 4: degree centrality (in-degree, out-degree, total degree) of each node, strength centrality (in-strength, out-strength, total strength, weighted calculation based on the selected edge weight type), weighted betweenness centrality (when calculating the importance of a node as a path "bridge", the length or cost of the path is defined as the sum of the inverse of the weights of each edge on the path, that is, 1 / ω ij These metrics include the average (weighted) shortest path length and diameter of the entire network, the weighted clustering coefficient of each node, structural hole indicators (effective size, network constraints), network efficiency (global efficiency, node-local efficiency), the rich club coefficient, clique (fully connected subgraph) analysis, and community structure detection (e.g., using the Louvain algorithm). The results of these metrics help reveal system vulnerabilities and critical transmission paths at the network structural level.
[0184] iii. Visualization Interface Module: To facilitate users' intuitive understanding and exploration of the constructed failure network, this module can export network data (including nodes, edges, their attributes, and weights) into standard file formats (e.g., GEXF, GraphML, Pajek.net, etc.), enabling users to perform more advanced, interactive visualization analysis using professional third-party network visualization and analysis software (e.g., Gephi, Cytoscape, Pajek, etc.). Furthermore, this module can utilize the system's integrated drawing libraries (e.g., Python's Matplotlib combined with the Graphviz engine) to generate static or basic interactive network diagrams, which can be directly displayed in the user interaction and results display unit 106.
[0185] 5. Risk Assessment, Verification and Decision Support Unit 105:
[0186] This unit is the core output and decision support link of the entire system. It receives the importance index of each MDFC from the risk quantification unit 103. and the network topology characteristic indicator results calculated by the network modeling and analysis unit 104. Its main function is to integrate this information, conduct in-depth risk assessments, and improve the reliability of the assessment results through innovative verification mechanisms, ultimately providing decision support for the formulation of effective risk control strategies. This unit generally includes the following submodules:
[0187] i. Key Risk Factor Identification Module: This module automatically filters and identifies key factors that have a significant contribution to the overall risk of the system from a large amount of data based on preset algorithms or user-defined threshold standards. This includes: The values are sorted in descending order to identify the items with the highest risk (e.g. Top-N items, or The method can identify key failure chains (those with a risk value exceeding a certain threshold) and sort the failure event nodes in the network according to the network topology analysis results (for example, high in / out intensity, high weighted betweenness centrality, high structural hole index, etc.) to identify failure event nodes that play key roles in the network (such as risk sources, risk convergence points, or key control bottlenecks). At the same time, it can also identify the main risk propagation paths that connect these key nodes, have high weights themselves, or frequently appear in multiple key failure chains.
[0188] ii. Bidirectional analysis and verification module: implementation Figure 3The innovative logic of "Forward Risk Propagation Path Analysis" and "Reverse MDFC Verification" is shown. Users can specify potential risk source nodes. The system uses a weighted path search algorithm to simulate risk propagation within the network, identify high-risk paths, and automatically or with user assistance compare these paths with the MDFC extracted through AcciMap reverse analysis (for example, comparing the degree of node sequence overlap, risk value differences, etc.). Based on the comparison results, the system can prompt the user to iteratively optimize the AcciMap model or MDFC risk parameters.
[0189] iii. Advanced Analysis Module: This module is used to perform deeper risk analysis to provide richer decision-making information. Specifically, it may include:
[0190] a. Interaction Effect Analysis Module: This module quantitatively evaluates the potential interaction effects between any two or more MDFCs. For example, it calculates the Jaccard similarity between their node sets and combines this with their average importance index to estimate their interaction effect index (IE). Chain combinations with high IE values may generate synergistic risk effects due to shared critical failure factors and therefore require special attention.
[0191] b. AcciMap model coverage evaluation module: used to quantitatively evaluate the degree to which the currently constructed multi-level security model and its extracted MDFC capture the overall potential risks of the system. For example, the importance weights W of each system level can be preset. l and the maximum potential failure impact factor M that may be generated at each level l , combining the importance index of all identified MDFCs Calculate AcciMap coverage C Accimap A low coverage rate may indicate that the model is insufficient and needs further improvement.
[0192] c. Sensitivity analysis module: allows users to select certain key input parameters (such as AHP weights, P, S, D scores of specific MDFCs) for perturbation and observe the impact of their changes on the final risk assessment results (such as I FC The degree of influence of the parameters (value sorting, key node identification) is determined to identify the parameters that are most sensitive to the results.
[0193] d. Time series analysis module: If the input data contains valid timestamp information, this module can analyze the temporal trends of indicators such as the frequency of MDFC occurrence and average IFC value, revealing the dynamic evolution of risks.
[0194] iv. Report and Recommendation Generation Module: This module is responsible for systematically integrating and summarizing the results of all the above analysis steps (including critical failure chains, critical nodes, critical paths, chain combinations with high IE values, AcciMap coverage assessment results, sensitivity analysis results, etc.), and automatically or semi-automatically generating a risk assessment report with a clear structure, detailed content, and both pictures and text. More importantly, based on these specific analysis findings and combined with the built-in risk control knowledge base or preset risk response rule templates (or through an interface with an expert system), the module can propose targeted, hierarchical and classified (for example, prioritizing based on risk level, control urgency, and cost-effectiveness), and actionable risk control and prevention measures.
[0195] 6. User interaction and result display unit 106 (usually embodied as a graphical user interface GUI):
[0196] This unit is the main entry point for users to interact with the entire multi-dimensional failure chain risk analysis and control system and the main exit point for information display. It is responsible for:
[0197] i. Provide a friendly graphical user interface (GUI) to guide users in inputting or importing basic data (such as AcciMap model data and historical accident information); select or configure various parameters required for system operation (for example, the scale value of the AHP judgment matrix, the criteria and entry method for expert scoring, the definition and hierarchical constraint rules of source / accident nodes for failure chain extraction, the selection rules for network edge weights, and the option settings for topological analysis and advanced analysis).
[0198] ii. Process monitoring and intermediate result display: During the system operation and analysis process, the current analysis progress can be fed back to the user, and some important intermediate results can be optionally displayed, such as the list of extracted MDFCs and their node sequences, the P, S, D scores of each MDFC, and I FC The calculation results, preliminary visualization of the constructed weighted failure network, preliminary calculated values of key network topology indicators, etc. are provided to enable users to have an intuitive understanding of the analysis process.
[0199] iii. Visual presentation and report output of final results: Comprehensively and clearly present the final risk assessment results and decision-making support information in a way that is easy for users to understand and accept. This usually includes:
[0200] a. Table format: For example, press I FC List of key failure chains sorted by value; list of key nodes sorted by centrality index; table of interaction effect index, etc.
[0201] b. Graphical form: For example, MDFC's I FCValue distribution histograms; statistical graphs of network topology indicators (such as degree distribution and intensity distribution); parameter impact curves for sensitivity analysis; trend graphs for time series analysis, etc. These graphs can be dynamically generated and embedded into the GUI using the system's internally integrated drawing engine (for example, Python-based libraries such as Matplotlib and Seaborn).
[0202] c. Network visualization: Provide an interactive or static visualization interface for the constructed weighted failure network (may be directly integrated or implemented by calling external tools such as Gephi), allowing users to view the network structure, node attributes, edge weights, and may support interactive operations such as node highlighting and path finding.
[0203] d. Structured report output: All important analysis results, charts and recommendations are integrated into a structured risk assessment report, which can be exported to common document formats (such as PDF, HTML, Word, etc.).
[0204] 7. Sensitivity and Time Series Analysis Unit 107:
[0205] This unit is an extension of the system's advanced analysis function and is integrated into the risk assessment and decision support unit 105 or exists as an independent module.
[0206] i. Sensitivity analysis module: This module allows the user to select one or more key input parameters (e.g., a comparison value in the AHP judgment matrix, the P, S, D score of a specific MDFC, or a dimension weight ω calculated by AHP). P 、ω S 、ω D As the object of sensitivity analysis. Users can set the range of change and the change step (or change percentage) of these parameters. The system will automatically adjust the values of these parameters iteratively within the set range and re-execute risk quantification (at least I FC calculation) and identification of key risk factors (e.g. FC Finally, the module will record and display the effect of changes in input parameters on output results (such as I of a specific MDFC) in the form of diagrams (such as spider diagrams, tornado diagrams, or parameter-result curves) or tables. FC The impact degree and change trend of the risk assessment results (such as the value of the key failure chain, the sorting stability of the key failure chain, the centrality index value of the key node, etc.) can be analyzed to help users identify the key assumptions or input data that are most sensitive to the overall risk assessment results.
[0207] ii. Time Series Analysis Module: If the user-provided input data (e.g., historical accident data, failure event records, or regularly updated risk score data) contains valid timestamp information, this module can be activated to perform dynamic risk trend analysis. Specific functions may include:
[0208] a. Aggregate statistics on the number of MDFCs or the frequency of occurrence of specific types of MDFCs according to a preset time window (such as monthly, quarterly, or annual), and draw a trend chart (such as a line chart or bar chart) showing their changes over time to reveal the cyclical or trend patterns of risk events.
[0209] b. If I FC The scoring data also has corresponding timestamp information (for example, the score is updated after each security review or assessment), so the I of a specific key MDFC can be analyzed. FC value or the average I of all MDFCs FC The changing trend of the value over time can be used to monitor the dynamic evolution of the overall risk level of the system.
[0210] c. Going further, if the node or edge attributes of the network also have timestamps (for example, the implementation time of a certain security measure, the aging degree of a certain device, etc.), network snapshots at different time points can be constructed and the topological structure changes between these snapshots can be compared to analyze the dynamic evolution of network risks.
[0211] Through the description of the above embodiments, the present invention provides a systematic, quantitative and innovative verification mechanism combined with a multi-dimensional failure chain risk analysis method and its implementation system, which can be effectively applied to the accident prevention and risk management of complex and high-risk social and technical systems, thereby improving their overall safety performance.
[0212] The present invention has been described through the above specific embodiments, but these descriptions are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A failure chain quantitative analysis and risk assessment method and system based on a multi-level safety model, applied to industrial or socio-technical systems with multi-level control structures and complex causal interactions that can be deconstructed using the AcciMap model. The method is characterized by: The following steps are involved: a. Systematic hierarchical causal model construction and multi-dimensional failure chain (MDFC) identification steps, including: i. Construct a hierarchical AcciMap model of the socio-technical system based on historical accident data, expert interviews, and system structure analysis. The AcciMap model deconstructs the socio-technical system into multiple system layers with inherent logical relationships and identifies failure events and their causal relationships within and between layers. ii. Formalize the AcciMap model as a directed acyclic graph (DAG) G = (V, E), where V is the set of nodes representing the failure events, E is the set of directed edges representing the causal relationships, and each node v∈V belongs to one of the specific levels l∈L of the AcciMap model; iii. In the directed acyclic graph G, according to the preset node attributes and hierarchical standards, determine the source node set representing the system high-level root cause failure And the set of accident nodes representing the final accident consequences of the underlying system iv. From the directed acyclic graph G, extract all nodes starting from any source node v through a path search algorithm. s ∈s, finally at any accident node v t ∈t, and the hierarchical evolution between nodes in the path conforms to the path of the preset system failure propagation logic, thus obtaining the multi-dimensional failure chain (MDFC) set {FC k Each multi-dimensional failure chain represents a complete sequence of failure propagation from high-level causes to low-level accidents; b. Multi-dimensional failure chain risk quantification steps, including: i. For each of the multi-dimensional failure chains FC extracted in step a k Based on a preset risk assessment dimension set, a quantitative score value corresponding to each dimension is obtained. The risk assessment dimension set includes at least: a failure propagation probability (P) dimension for evaluating the possibility of failure chain propagation, an accident consequence severity (S) dimension for evaluating the severity of the final accident consequence caused by the failure chain, and a defense penetration (D) dimension for evaluating whether the existing safety barrier fails to effectively prevent or mitigate the development of the failure chain. By organizing experts in the field and using an improved Delphi method, and referring to a predefined 1-5 level Likert scale scoring criterion, a quantitative score value P corresponding to each dimension is obtained. k 、S k 、D k ; ii. Using the preset weight determination method, calculate the normalized weight coefficient ω of the three risk assessment dimension elements P, S, and D P 、ω S 、ω D , and satisfies ω P +ω S +ω D =1, and perform logical consistency verification on the weight determination process; iii. Based on the weighted sum model, calculate each multi-dimensional failure chain FC k The comprehensive failure chain importance index I FCk ; c. Failure propagation network construction and topology feature analysis steps include: i. Integrate all multi-dimensional failure chains FC extracted in step a k , take all non-repeated failure event nodes appearing in these multi-dimensional failure chains as the network node set V′, and map the causal relationship between any two directly connected failure event nodes in the multi-dimensional failure chain into directed edges in the network, forming a directed failure propagation network G′=(V′,E′); ii. Importance index of each multi-dimensional failure chain calculated in step b For each edge (v i ,v j )∈E′ assigns at least one edge weight ω calculated by a preset rule ij , forming a directed weighted failure network G′=(V′,E′,W); iii. calculating and analyzing the network topology characteristics of the constructed directed weighted failure propagation network G′, wherein the characteristics include at least indicators reflecting node centrality, connectivity, and the overall network structure; d. Risk assessment and control decision support steps, including: i. Based on the failure chain importance index Combined with the network topology characteristic indicators, the AcciMap model and MDFC set obtained in step a are used to perform reverse cause tracing to identify the key failure chains that significantly contribute to the overall system risk, the key failure event nodes that constitute the system vulnerability, and the main risk propagation paths; ii. Verify and deepen the identification results of step d(i) using forward risk propagation path analysis: select nodes with high-level or high-risk output characteristics from the network G′ as potential risk sources, use a weighted path search algorithm to calculate the risk propagation paths from these risk sources to the accident node, and compare these forward-identified paths with the reverse-extracted MDFCs to analyze their consistency and differences, so as to iteratively verify and optimize the AcciMap model, MDFC set, and risk assessment results; iii. Calculate the Interaction Effect Index (IE) between any two or more multi-dimensional failure chains to identify failure chain combinations with synergistically enhanced risk effects; iv. Based on the preset importance weights of each system level and the maximum potential impact factor of each level, combined with the importance index of all multi-dimensional failure chains, evaluate the coverage of the multi-level safety model for the critical failure propagation path (C Accimap ); v. Based on the above analysis results, generate a risk assessment report for the socio-technical system and propose targeted risk control and prevention measures.
2. The method according to claim 1, characterized in that In step a, the multi-level security model is specifically the AcciMap model, whose preset system layers include at least the government policy and budget layer, the regulatory agency and association layer, the company management layer, the technology and operation management layer, the physical process and personnel activity layer, and the equipment and environment layer. The preset system failure propagation logic preferably follows the principle of layer reduction or preservation, that is, for any directly connected node pair (v i ,v i+1 ), whose level satisfies l(v i )≤l(v i+1 ).
3. The method according to claim 1, characterized in that In step b, the preset weight determination method is the analytic hierarchy process (AHP), and the logical consistency verification is to perform a consistency ratio (CR) test on the AHP judgment matrix, and the CR is required to be less than or equal to 0.
10. According to the weighted sum model, the calculation formula of the comprehensive failure chain importance index is: Among them, P k 、S k 、D k is the quantitative score value, ω P 、ω S 、ω D is the normalized weight coefficient calculated by AHP.
4. The method according to claim 1, wherein In step c, the edge weight definition rule includes at least one selected from the maximum risk contribution weight and / or cumulative risk flux weights The maximum risk contribution weight is defined as the maximum value of all multi-dimensional failure chains containing this edge, which is used to represent the highest potential risk level propagated through this connection. Its calculation formula is: The cumulative risk flux weight is defined as the sum of all multi-dimensional failure chains containing the edge, which is used to characterize the importance of the cumulative risk flowing through the connection. Its calculation formula is: The calculated network topology characteristic indicators include: the in-degree, out-degree, and total degree of the node, the in-strength, out-strength, and total strength of the node, the average weighted path length of the network, the network diameter, the weighted clustering coefficient of the node, the weighted betweenness centrality of the node, the effective scale of the node, the network constraint of the node, the global efficiency of the network, the local efficiency of the node, the rich club coefficient of the network, and the factional structure in the network.
5. The method according to claim 1, wherein In step d, the weighted path search algorithm uses the inverse of the edge weight as the path cost; The calculation formula of the interaction effect index (IE) is: Among them JS(FC i ,FC j ) is a multi-dimensional failure chain FC i and FC j Jaccard similarity, and They are multi-dimensional failure chains FC i and FC j The importance index, C(FC i ,FC j ) is a multi-dimensional failure chain FC i and FC j Time series correlation coefficient or preset constant; The multi-level security model coverage C Accimap The calculation formula is: Among them, ω i is the weight of the failure chain, W l is the default weight of system level l, M l The maximum potential impact factor at system level l.
6. The method according to claim 1, characterized in that The method further comprises a sensitivity analysis step, which comprises: a. Select at least one input parameter to be perturbed; b. adjusting the value of the selected input parameter within a preset parameter variation range; c. Re-perform at least step b(iii) and step d(i), record and analyze the effect of the input parameter changes on the I FCk The value or key failure chain ranking, and the degree of impact on the key node identification results; d. If the failure event node or multi-dimensional failure chain data contains valid timestamp information, the method should also include time series analysis.
7. A multi-dimensional failure chain risk analysis and control system, characterized in that: include: a data interface and model building unit, configured to receive relevant data of the socio-technical system and construct or formalize the multi-level security model and directed graph; b. A multi-dimensional failure chain identification and extraction unit configured to extract the multi-dimensional failure chain set from the directed graph according to a preset source / accident node definition and system failure propagation logic; c. Risk quantification unit, configured to obtain the three-factor risk scores, perform weight determination and logical consistency verification, and calculate the comprehensive failure chain importance index for each multi-dimensional failure chain; d. a network modeling and analysis unit configured to construct the directed weighted failure network based on the multi-dimensional failure chain and its importance index, and calculate various topological characteristic indicators of the network; e. Risk assessment, verification and decision support unit, configured to integrate analysis results, perform comparative verification of reverse cause tracing and forward risk propagation path analysis, conduct interaction effect analysis and model coverage assessment, and generate risk control measure recommendations.
8. The system according to claim 7, characterized in that The risk quantification unit is further configured to obtain a quantitative score value through expert evaluation and a modified Delphi method, and to determine a weight coefficient through a hierarchy analysis method and perform a consistency ratio test; The network modeling and analysis unit is further configured to calculate and assign edge weights to the network according to a maximum risk contribution weight rule or a cumulative risk flux rule, and use the inverse of the edge weight as the path cost when calculating the weighted betweenness centrality; The risk assessment, verification and decision support unit is further configured to calculate the interaction effect index and coverage of the model; The system further comprises a sensitivity analysis unit configured to perform the sensitivity analysis step and the time series analysis function described in claim 6.
9. A computer-readable storage medium storing computer-executable instructions, wherein when the computer-executable instructions are executed by a processor, the processor executes the failure chain quantitative analysis and risk assessment method based on a multi-level security model according to any one of claims 1 to 6.
Citation Information
Cited By
Intelligent situation analysis and arrangement method and system
CN121029126A
Common cause failure risk analysis method and system based on software structure coupling network
CN121233455A
Common cause failure risk analysis method and system based on software structure coupling network
CN121233455B
Industrial chain risk monitoring method, system and equipment based on causal analysis and medium
CN121352519A
Data low-code processing method and system based on dynamic binding and template technology
CN121387700A