An airborne system safety analysis method and system based on attack graph and fault tree
Patent Information
- Application Number
- CN202610871793.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-16
- Publication Date
- 2026-09-18
AI Technical Summary
例如,某航电系统的冗余通道在正常情况下可以容忍单通道故障,但如果攻击者已通过网络攻击劫持了一个冗余通道的数据,此时另一个通道又发生了随机硬件失效,该航电系统会将失去所有有效的航向数据来源,这种“攻击 + 失效”的混合场景,单独进行安全性分析或信息安全分析均无法识别,因为安全性分析不考虑攻击行为,信息安全分析不考虑随机失效
[0052] As described above, this invention provides a method and system for airborne system security analysis based on attack graphs and fault trees, which has the following beneficial effects: This invention can integrate security reports and information security reports into a unified extended fault tree, enabling the identification and quantification of mixed hazard scenarios of "attack events + random failures" at the model level, thereby achieving quantitative coupling of security analysis and information security analysis within the same formal model. Since the essential difference between attacks and random failures lies in the attacker's choice of path and the change in probability with defense, this invention addresses this difference through triplet parameterization and game theory models, allowing both types of events to be quantitatively calculated uniformly within the same fault tree. This solves the compatibility problem between attack behavior and random failures in a probabilistic sense through the probability transformation function of security threat event nodes. Furthermore, this invention provides a decision-making basis for defense resource allocation through game theory solutions. The Nash equilibrium solution not only provides the danger ranking of each cut set but also the optimal strategy for the defender, i.e., which defense measures should be prioritized for limited defense resources. In the analysis experiment, the resource allocation scheme given by the game theory model reduced the overall residual danger of the system by 42% compared to the uniform allocation scheme. Furthermore, since the two sets of requirements generated by independent analysis may conflict (security requires data availability while information security requires data isolation) or be incomplete (mixed scenarios not covered by either set of requirements), this invention eliminates the gap between security and information security requirements by unifying the requirement set. Therefore, the coupling requirement mechanism of this invention binds related security constraints and information security constraints into a set, reducing conflicts and omissions between requirements. Simultaneously, this invention can output reports that simultaneously comply with both DO-326A and ARP4761 formats, allowing security reviewers and information security reviewers to obtain their respective analysis results from the same report, reducing cross-domain communication costs.
Smart Images

Figure CN122778377A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a method and system for airborne system security analysis based on attack graphs and fault trees. Background Technology
[0002] Safety assessments of airborne systems have traditionally followed the ARP4761 standard, employing methods such as Fault Tree Analysis (FTA) and Failure Mode and Effects Analysis (FMEA). These methods model system failures as random events, quantifying the probability of each basic event using the failure rate (λ), and calculating the probability of the top event through logic gate combinations. This methodology has decades of engineering experience in handling random failure scenarios such as hardware aging and software defects, demonstrating high technological maturity.
[0003] With the increasing networking of airborne systems (AFDX (Avionics Full-Duplex Switched Ethernet) networks, wireless data links, electronic flight bags, and other external connections), information security threats have become a significant source of risk. DO-326A (Airworthiness Security Process Specification) explicitly requires that information security threats be included in the security assessment during the airworthiness certification process. However, fundamental methodological differences exist between existing security analysis methods and information security analysis methods, resulting in a disconnect between the two analytical activities.
[0004] Specifically, traditional fault tree analysis cannot express the characteristics of information security threats. The basic events in a fault tree assume that each event occurs independently with a constant probability. However, information security attacks are intentional; for example, attackers may actively choose the weakest intrusion path in a system, and the attack probability is not constant but varies with defensive measures. Attacks also have multi-step characteristics: a complete attack often requires breaching multiple security barriers sequentially, with dependencies between steps (success of a preceding step is required for subsequent steps), which contradicts the assumption of independence of basic events in traditional fault trees. Furthermore, attacks are adaptive: when an attack path is defended, attackers will switch to other paths; this adversarial behavior cannot be described by static failure probabilities.
[0005] Attack graph analysis in the field of information security lacks a correlation with security consequences. The cybersecurity field uses attack graphs to model attack paths faced by a system, analyzing all possible paths an attacker can take from an external intrusion point to a critical asset. Mature tools (such as MulVAL and TVA) support attack graphs for vulnerability assessment and penetration path analysis. However, the output of attack graph analysis is "which assets an attacker can reach" and "the attack difficulty of each path," without establishing a quantitative correlation with security consequences. In other words, an attack graph can answer "can an attacker compromise a navigation computer?" but it cannot answer "what level of security harm will ultimately result from compromising a navigation computer?" The latter requires functional hazard assessment within security analysis to answer.
[0006] Therefore, it is evident that the two independent analysis methods described above have evaluation blind spots. This leads to the current practice in engineering where security engineers and information security engineers conduct FTA and attack graph analyses separately, producing two independent analysis reports. This fragmented approach has blind spots: some hazardous scenarios require a combination of "attack event + random failure" to trigger. For example, a redundant channel in an avionics system can tolerate a single channel failure under normal circumstances. However, if an attacker has hijacked the data of one redundant channel through a network attack, and another channel experiences a random hardware failure, the avionics system will lose all valid heading data sources. This mixed scenario of "attack + failure" cannot be identified by either security analysis or information security analysis alone, because security analysis does not consider attack behavior, and information security analysis does not consider random failures. Summary of the Invention
[0007] In view of the shortcomings of the prior art described above, the purpose of this invention is to provide an airborne system security analysis method and system based on attack graphs and fault trees, so as to solve the technical problems existing in the prior art.
[0008] To achieve the above and other related objectives, this invention provides a method for airborne system security analysis based on attack graphs and fault trees, comprising the following steps:
[0009] A security threat event node type is added to the basic event node of the original fault tree to form a fusion model; the security threat event node is used to parameterize the triple consisting of attack feasibility, attack motivation and exposure window;
[0010] The triples are converted into probability values compatible with quantitative security analysis using a probability transformation function, and network topology and data flow information are extracted from the fusion model. An attack graph is then generated by combining the threat knowledge base.
[0011] Each complete attack path from the initial intrusion point to the target asset in the attack graph is mapped to a security threat event node in the fusion model, and an extended fault tree containing traditional basic event nodes and security threat event nodes is constructed.
[0012] A minimum attack failure cut set search is performed on the extended fault tree. During the cut set search, the cut sets are divided into two categories: random failure cut sets and mixed attack failure cut sets. The cut set probability is calculated for random failure cut sets, and the risk of the mixed attack failure cut sets is evaluated using a game theory model. The game theory model is used to model the optimal attack path chosen by the attacker as the attacker's strategy and the existing defense measures as the defender's strategy. The equilibrium risk of the mixed cut sets is obtained by solving the Nash equilibrium.
[0013] Based on the solution results of the fusion model, corresponding security requirements or information security requirements are generated for each cut set whose risk exceeds the threshold. These requirements are labeled as pure security requirements, pure information security requirements, or coupled requirements according to their source. Security constraints and information security constraints are associated with coupled requirements, and a unified set of requirements is formed by sorting them by risk level to output a joint analysis report that conforms to the target format.
[0014] Optionally, the process of converting triples into probability values compatible with quantitative security analysis via a probability transformation function includes:
[0015] The feasibility of an attack is assessed using a five-level quantitative scoring system. The scoring is based on four factors: the level of professional knowledge required for the attack, the difficulty of acquiring the required equipment, the length of the attack window, and whether internal personnel cooperation is required. Each factor is scored within a preset score range, and the weighted average is taken to obtain the normalized value of the attack feasibility.
[0016] The attack motivation is quantified into a three-level score based on the value level of the target asset and the type of attacker, resulting in an attack motivation score. The types of attackers include random attackers, targeted attackers, and targeted attackers.
[0017] The exposure window is calculated based on the proportion of time the interface is open to the outside world to the total running time. The value of the permanently exposed interface is set to 1. The value of the interface that is only open during ground maintenance is calculated based on the proportion of maintenance time.
[0018] Based on the attack feasibility normalized value, attack motivation score, and exposure window ratio, the triple is converted into a probability value compatible with quantitative security analysis using a probability transformation function: P_STE = 1 - (1 - AF_norm)^(AM_score * EW_ratio), where P_STE is the probability value obtained by the probability transformation function, AF_norm is the attack feasibility normalized value, AM_score is the attack motivation score, and EW_ratio is the exposure window ratio.
[0019] Optionally, the process of mapping each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model includes:
[0020] Extract all external interface nodes from the fusion model as the initial intrusion point set of the attack graph, and extract the components carrying security-critical functions as the target asset set;
[0021] Starting from each initial intrusion point, the attack path is expanded by breadth-first search in combination with the attack patterns in the threat knowledge base. After each expansion step, it is checked whether the current node can reach the adjacent node using at least one attack pattern in the knowledge base, until the target asset is reached or the expansion can no longer continue.
[0022] For each complete path from the intrusion point to the target asset in the generated attack graph, the feasibility of the path attack is calculated, and each complete attack path is mapped to a security threat event node. The feasibility of the path attack is used as the attack feasibility parameter of the corresponding security threat event node. Among them, the attack motivation is the motivation score of the target asset in each complete path, and the exposure window is the exposure window value of the intrusion point in each complete path.
[0023] Optionally, the feasibility of the path attack is obtained through a chained calculation of the feasibility of the conditional attack, wherein the feasibility of each step of the attack in the path is conditional upon the success of the preceding steps. The calculation formula for the feasibility of the path attack is: AF_path = AF_1 * AF_2|1 * AF_3|1,2 * ... * AF_n|1,...,n-1, where AF_path is the result of the path attack feasibility calculation for the complete path, AF_1 represents the conditional attack feasibility of the first step, and AF_n|1,...,n-1 represents the conditional attack feasibility of the nth step under the condition that the preceding n-1 steps are all successful.
[0024] Optionally, the process of performing a minimum attack failure cutset search on the extended fault tree includes:
[0025] The extended fault tree is decomposed from top to bottom. The top event is decomposed layer by layer through logic gates to the basic event node and the security threat event node, generating all the smallest event combinations that cause the top event to occur, denoted as the cut set.
[0026] Each cut set is examined, and cut sets containing only basic event nodes are marked as random failure cut sets, cut sets containing only security threat event nodes are marked as pure attack cut sets, and cut sets containing both types of nodes are marked as attack failure hybrid cut sets.
[0027] For random failure cut sets, the probability of the cut set is calculated by multiplying the failure probabilities of each basic event by the independent assumption. For pure attack cut sets and mixed cut sets, they are included in the attacker's strategy space of the game theory model, and each cut set is regarded as an optional strategy of the attacker.
[0028] Remove cut sets whose probability or risk level is lower than a preset threshold from all cut sets, sort them by risk level from high to low, and output the list of cut sets with the least attack failure.
[0029] Optionally, the calculation process of the game theory model includes:
[0030] A zero-sum game model is constructed, which includes the attacker's strategy space and the defender's strategy space. The attacker's strategy space is a cut set of all nodes containing security threat events, and the defender's strategy space is a set of implementable defense measures. Each defense measure is defined as an operation that can reduce the probability of a specific security threat event node.
[0031] The benefit matrix is defined as follows: for the attacker choosing cut set i and the defender choosing defense combination j, the attacker's benefit is equal to the residual risk of the cut set under defense combination j. The residual risk is obtained by recalculating the probability of security threat event nodes affected by defense measures in the cut set after reducing the defense effectiveness coefficient.
[0032] Solve for the mixed-policy Nash equilibrium on the payoff matrix, where the attacker's equilibrium policy corresponds to the probability distribution of each cut set chosen by the rational attacker, and the defender's equilibrium policy corresponds to the optimal defense resource allocation scheme.
[0033] The equilibrium risk of each cut set is equal to the probability of that cut set being chosen under the attacker's equilibrium strategy multiplied by the residual risk of that cut set under the defender's equilibrium strategy.
[0034] Optionally, the generation rule for the unified requirement set is:
[0035] For random failure cut sets whose risk exceeds the threshold, safety requirements are generated based on the components involved in each basic event in the random failure cut set. The corresponding requirements include failure rate constraints, redundancy design requirements, or monitoring and detection requirements, and are marked as pure safety requirements.
[0036] For pure attack cut sets whose risk level exceeds the threshold, information security requirements are generated based on the attack paths corresponding to each security threat event node in the pure attack cut set. The corresponding requirements include access control measures, intrusion detection rules or network isolation requirements, and are marked as pure information security requirements.
[0037] For attacks whose risk level exceeds the threshold, a hybrid cut set is generated to fail. At the same time, security constraints and information security constraints are generated. The security constraints and information security constraints are related to each other to form a set of coupled requirements. The level of security consequences is marked if either of the two constraints is not met.
[0038] All requirements are sorted by hazard level, and requirements with the same hazard level are sorted by safety consequence level, forming a unified requirement set and outputting it.
[0039] This invention also provides an airborne system security analysis system based on attack graphs and fault trees, the system comprising:
[0040] The fusion model construction module is used to add security threat event node types to the basic event nodes of the original fault tree to form a fusion model; and to convert triples into probability values compatible with quantitative security analysis through a probability transformation function, extract network topology and data flow information from the fusion model, and generate an attack graph by combining it with a threat knowledge base; and to map each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model, constructing an extended fault tree containing traditional basic event nodes and security threat event nodes; wherein, the security threat event node is used to parameterize the triples composed of attack feasibility, attack motive, and exposure window;
[0041] The fusion model solving module is used to perform minimum attack failure cut set search on the extended fault tree. During the cut set search process, the cut sets are divided into two categories: random failure cut sets and attack failure mixed cut sets. The cut set probability is calculated for random failure cut sets, and the risk of attack failure mixed cut sets is evaluated by a game theory model. The game theory model is used to model the optimal attack path chosen by the attacker as the attacker's strategy and the existing defense measures as the defender's strategy. The equilibrium risk of the mixed cut sets is obtained by solving the Nash equilibrium.
[0042] The requirement generation and reporting module is used to generate corresponding security requirements or information security requirements for each cut set whose risk exceeds the threshold based on the solution results of the fusion model. The requirements are labeled as pure security requirements, pure information security requirements, or coupled requirements according to their source. The coupled requirements are associated with security constraints and information security constraints, and sorted by risk to form a unified requirement set, so as to output a joint analysis report that conforms to the target format.
[0043] Optionally, the process of converting triples into probability values compatible with quantitative security analysis via a probability transformation function includes:
[0044] The feasibility of an attack is assessed using a five-level quantitative scoring system. The scoring is based on four factors: the level of professional knowledge required for the attack, the difficulty of acquiring the required equipment, the length of the attack window, and whether internal personnel cooperation is required. Each factor is scored within a preset score range, and the weighted average is taken to obtain the normalized value of the attack feasibility.
[0045] The attack motivation is quantified into a three-level score based on the value level of the target asset and the type of attacker, resulting in an attack motivation score. The types of attackers include random attackers, targeted attackers, and targeted attackers.
[0046] The exposure window is calculated based on the proportion of time the interface is open to the outside world to the total running time. The value of the permanently exposed interface is set to 1. The value of the interface that is only open during ground maintenance is calculated based on the proportion of maintenance time.
[0047] Based on the attack feasibility normalized value, attack motivation score, and exposure window ratio, the triple is converted into a probability value compatible with quantitative security analysis using a probability transformation function: P_STE = 1 - (1 - AF_norm)^(AM_score * EW_ratio), where P_STE is the probability value obtained by the probability transformation function, AF_norm is the attack feasibility normalized value, AM_score is the attack motivation score, and EW_ratio is the exposure window ratio.
[0048] Optionally, the process of mapping each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model includes:
[0049] Extract all external interface nodes from the fusion model as the initial intrusion point set of the attack graph, and extract the components carrying security-critical functions as the target asset set;
[0050] Starting from each initial intrusion point, the attack path is expanded by breadth-first search in combination with the attack patterns in the threat knowledge base. After each expansion step, it is checked whether the current node can reach the adjacent node using at least one attack pattern in the knowledge base, until the target asset is reached or the expansion can no longer continue.
[0051] For each complete path from the intrusion point to the target asset in the generated attack graph, the feasibility of the path attack is calculated, and each complete attack path is mapped to a security threat event node. The feasibility of the path attack is used as the attack feasibility parameter of the corresponding security threat event node. The attack motivation is the motivation score of the target asset in each complete path, and the exposure window is the exposure window value of the intrusion point in each complete path. The feasibility of the path attack is obtained through a chained calculation of conditional attack feasibility. The feasibility of each step in the path is conditional upon the success of the preceding steps. The formula for calculating the feasibility of the path attack is: AF_path = AF_1 * AF_2|1 * AF_3|1,2 * ... * AF_n|1,...,n-1, where AF_path is the result of the path attack feasibility calculation for the complete path, AF_1 represents the conditional attack feasibility of the first step, and AF_n|1,...,n-1 represents the conditional attack feasibility of the nth step under the condition that the preceding n-1 steps are all successful.
[0052] As described above, this invention provides a method and system for airborne system security analysis based on attack graphs and fault trees, which has the following beneficial effects: This invention can integrate security reports and information security reports into a unified extended fault tree, enabling the identification and quantification of mixed hazard scenarios of "attack events + random failures" at the model level, thereby achieving quantitative coupling of security analysis and information security analysis within the same formal model. Since the essential difference between attacks and random failures lies in the attacker's choice of path and the change in probability with defense, this invention addresses this difference through triplet parameterization and game theory models, allowing both types of events to be quantitatively calculated uniformly within the same fault tree. This solves the compatibility problem between attack behavior and random failures in a probabilistic sense through the probability transformation function of security threat event nodes. Furthermore, this invention provides a decision-making basis for defense resource allocation through game theory solutions. The Nash equilibrium solution not only provides the danger ranking of each cut set but also the optimal strategy for the defender, i.e., which defense measures should be prioritized for limited defense resources. In the analysis experiment, the resource allocation scheme given by the game theory model reduced the overall residual danger of the system by 42% compared to the uniform allocation scheme. Furthermore, since the two sets of requirements generated by independent analysis may conflict (security requires data availability while information security requires data isolation) or be incomplete (mixed scenarios not covered by either set of requirements), this invention eliminates the gap between security and information security requirements by unifying the requirement set. Therefore, the coupling requirement mechanism of this invention binds related security constraints and information security constraints into a set, reducing conflicts and omissions between requirements. Simultaneously, this invention can output reports that simultaneously comply with both DO-326A and ARP4761 formats, allowing security reviewers and information security reviewers to obtain their respective analysis results from the same report, reducing cross-domain communication costs. Attached Figure Description
[0053] Figure 1 This is a schematic diagram of the overall structure of an attack graph and fault tree fusion analysis system provided in one embodiment of the present invention;
[0054] Figure 2 This is a schematic diagram of the extended fault tree and attack graph mapping process in the fusion model construction module provided in one embodiment of the present invention;
[0055] Figure 3 This is a schematic diagram of the game theory model construction and solution process in the fusion model solving module provided in one embodiment of the present invention;
[0056] Figure 4 This is a schematic diagram of cutset classification and risk assessment for a certain type of avionics system fusion analysis provided in an embodiment of the present invention.
[0057] Figure 5 This is a schematic diagram comparing the coverage of fusion analysis and traditional independent analysis in one embodiment of the present invention. Detailed Implementation
[0058] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, unless otherwise specified, the following embodiments and features described therein can be combined with each other.
[0059] It should be noted that the illustrations provided in this embodiment are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0060] In one exemplary embodiment, this embodiment provides an airborne system security analysis method based on attack graphs and fault trees, including the following steps:
[0061] A security threat event node type is added to the basic event node of the original fault tree to form a fusion model; the security threat event node is used to parameterize the triple consisting of attack feasibility, attack motivation and exposure window.
[0062] The triples are converted into probability values compatible with quantitative security analysis using a probability transformation function, and network topology and data flow information are extracted from the fusion model. An attack graph is then generated by combining the threat knowledge base. In some examples, the process of converting triples into probability values compatible with quantitative security analysis using a probability transformation function may include: quantifying attack feasibility using a five-level quantitative scoring system, based on four factors: the level of expertise required for the attack, the difficulty of acquiring the required equipment, the attack window duration, and whether internal personnel cooperation is needed. Each factor is scored within a preset score range, and a weighted average is taken to obtain a normalized attack feasibility value; quantifying attack motive into a three-level score based on the value level of the target asset and the attacker type, obtaining an attack motive score value, where attacker types include random attackers, targeted attackers, and targeted attackers; calculating the exposure window based on the proportion of interface open time to total runtime, assigning a value of 1 to permanently exposed interfaces, and calculating the exposure window based on the proportion of maintenance time for interfaces only open during ground maintenance; and converting the triples into probability values compatible with quantitative security analysis using a probability transformation function based on the normalized attack feasibility value, the attack motive score value, and the exposure window proportion, with: P_STE = 1 - (1 - AF_norm)^(AM_score * EW_ratio), where P_STE is the probability value obtained by the probability transformation function, AF_norm is the attack feasibility normalization value, AM_score is the attack motivation score value, and EW_ratio is the exposure window ratio.
[0063] Each complete attack path from the initial intrusion point to the target asset in the attack graph is mapped to a security threat event node in the fusion model, constructing an extended fault tree containing traditional basic event nodes and security threat event nodes. In some examples, the process of mapping each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model may include: extracting all external interface nodes from the fusion model as the initial intrusion point set of the attack graph, and extracting components carrying security-critical functions as the target asset set; starting from each initial intrusion point, combining attack patterns in the threat knowledge base, expanding the attack path in a breadth-first search, and after each expansion step, checking whether the current node can reach adjacent nodes using at least one attack pattern in the knowledge base, until the target asset is reached or further expansion is impossible; for each complete path from the intrusion point to the target asset in the generated attack graph, the path attack feasibility is calculated, and each complete attack path is mapped to a security threat event node, and the path attack feasibility is used as the attack feasibility parameter of the corresponding security threat event node; where the attack motivation is the motivation score of the target asset in each complete path, and the exposure window is the exposure window value of the intrusion point in each complete path. In some examples, the feasibility of a path attack is obtained through a chained calculation of the feasibility of a conditional attack. The feasibility of each step in the path is conditional upon the success of the preceding steps. The formula for calculating the feasibility of a path attack is: AF_path = AF_1 * AF_2|1 * AF_3|1,2 * ... * AF_n|1,...,n-1, where AF_path is the result of the path attack feasibility calculation for the complete path, AF_1 represents the conditional attack feasibility of the first step, and AF_n|1,...,n-1 represents the conditional attack feasibility of the nth step under the condition that the preceding n-1 steps are all successful.
[0064] A minimum attack failure cut set search is performed on the extended fault tree. During the cut set search, the cut sets are divided into two categories: random failure cut sets and mixed attack failure cut sets. The cut set probability is calculated for random failure cut sets, and the risk of the mixed attack failure cut sets is evaluated using a game theory model. The game theory model is used to model the optimal attack path chosen by the attacker as the attacker's strategy and the existing defense measures as the defender's strategy. The equilibrium risk of the mixed cut sets is obtained by solving the Nash equilibrium. In some examples, the process of performing a minimum attack failure cut set search on an extended fault tree may include: decomposing the extended fault tree from top to bottom, decomposing the top event layer by layer through logic gates to basic event nodes and security threat event nodes, generating all minimum event combinations that cause the top event to occur, denoted as cut sets; checking each cut set, marking cut sets containing only basic event nodes as random failure cut sets, cut sets containing only security threat event nodes as pure attack cut sets, and cut sets containing both types of nodes as mixed attack failure cut sets; calculating the cut set probability for random failure cut sets by multiplying the failure probabilities of each basic event by the independent assumption; for pure attack cut sets and mixed cut sets, incorporating them into the attacker's strategy space of the game theory model, with each cut set as an optional strategy for the attacker; removing cut sets whose cut set probability or danger level is lower than a preset threshold from all cut sets, sorting them from high to low danger, and outputting a list of minimum attack failure cut sets. In some examples, the computation process of the game theory model may include: constructing a zero-sum game model comprising the attacker's policy space and the defender's policy space, where the attacker's policy space is all cut sets containing security threat event nodes, and the defender's policy space is a set of implementable defensive measures, each defensive measure being defined as an operation that reduces the probability of a specific security threat event node; defining the payoff matrix, including: for the attacker choosing cut set i and the defender choosing defense combination j, the attacker's payoff is equal to the residual risk of that cut set under defense combination j, the residual risk being recalculated by reducing the probability of security threat event nodes affected by the defensive measures in the cut set by the defense effectiveness coefficient; solving for the mixed-policy Nash equilibrium on the payoff matrix, where the attacker's equilibrium strategy corresponds to the probability distribution of each cut set being chosen by a rational attacker, and the defender's equilibrium strategy corresponds to the optimal defense resource allocation scheme; the equilibrium risk of each cut set is equal to the probability of that cut set being chosen under the attacker's equilibrium strategy multiplied by the residual risk of that cut set under the defender's equilibrium strategy.
[0065] Based on the solution results of the fusion model, corresponding security requirements or information security requirements are generated for each cut set whose risk exceeds the threshold. These requirements are labeled as pure security requirements, pure information security requirements, or coupled requirements according to their source. Security constraints and information security constraints are associated with coupled requirements, and a unified set of requirements is formed by sorting them by risk level to output a joint analysis report that conforms to the target format. In some examples, the rules for generating a unified requirement set can be as follows: For random failure segments with a risk level exceeding a threshold, security requirements are generated based on the components involved in each basic event within the random failure segment. These requirements include failure rate constraints, redundancy design requirements, or monitoring and detection requirements, and are labeled as pure security requirements. For pure attack segments with a risk level exceeding a threshold, information security requirements are generated based on the attack paths corresponding to each security threat event node within the pure attack segment. These requirements include access control measures, intrusion detection rules, or network isolation requirements, and are labeled as pure information security requirements. For mixed attack and failure segments with a risk level exceeding a threshold, both security constraints and information security constraints are generated simultaneously. These security constraints and information security constraints are interconnected to form a set of coupled requirements, and it is noted that failure to meet either constraint will result in a security consequence level. All requirements are sorted by risk level, and requirements of the same risk level are sorted by security consequence level to form a unified requirement set, which is then output.
[0066] In summary, this invention provides an airborne system security analysis method based on attack graphs and fault trees. It integrates security and information security reports into a unified extended fault tree, enabling the identification and quantification of mixed hazard scenarios involving "attack events + random failures" at the model level. This achieves quantitative coupling of security and information security analysis within the same formal model. Since the fundamental difference between attacks and random failures lies in the attacker's path selection and the change in probability with defense, this method addresses this difference through triplet parameterization and game theory models. This allows for unified quantitative calculation of both types of events within the same fault tree, thus resolving the compatibility issue between attack behavior and random failures in a probabilistic sense through the probability transformation function of security threat event nodes. Furthermore, this method provides a decision-making basis for defense resource allocation through game theory solutions. The Nash equilibrium solution not only provides a ranking of the danger levels of each cut set but also the optimal strategy for the defender, i.e., which defense measures should be prioritized for limited defense resources. In the analysis experiments, the resource allocation scheme given by the game theory model reduced the overall residual danger of the system by 42% compared to the uniform allocation scheme. Furthermore, since the two sets of requirements generated by independent analysis may be contradictory (security requires data availability but information security requires data isolation) or incomplete (mixed scenarios not covered by either set of requirements), this method eliminates the gap between security and information security requirements by unifying the requirement set. Therefore, the coupling requirement mechanism of this method binds related security and information security constraints into a group, reducing contradictions and omissions between requirements. Simultaneously, this method can output reports that simultaneously meet the requirements of DO-326A and ARP4761 formats. Security and information security auditors can obtain the analysis results of their respective concerns from the same report, reducing cross-domain communication costs. Therefore, this method can establish a unified formal framework for security and information security analysis. By extending the traditional fault tree model, this method can accommodate information security threat events. A mapping mechanism from attack graphs to extended fault trees is designed to integrate the inputs of both types of analysis. A cut-set solving algorithm suitable for including attack behaviors is proposed, ultimately outputting unified analysis results that simultaneously cover both security and information security requirements. This method can add a fusion layer to existing FTA or attack graph analysis, enabling the two originally separate analysis sets to work together, thereby discovering mixed hazard scenarios that cannot be identified by individual analysis.
[0067] In an exemplary embodiment of the present invention, an airborne system security analysis system based on attack graphs and fault trees is provided, comprising:
[0068] The fusion model construction module is used to add security threat event node types to the basic event nodes of the original fault tree to form a fusion model; and to convert triples into probability values compatible with quantitative security analysis through a probability transformation function, extract network topology and data flow information from the fusion model, and generate an attack graph by combining it with a threat knowledge base; and to map each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model, constructing an extended fault tree containing traditional basic event nodes and security threat event nodes; wherein, the security threat event node is used to parameterize the triples composed of attack feasibility, attack motivation and exposure window. In some examples, the process of converting triples into probability values compatible with quantitative security analysis using a probability transformation function may include: quantifying attack feasibility using a five-level quantitative scoring system, based on four factors: the level of expertise required for the attack, the difficulty of acquiring the required equipment, the attack window duration, and whether internal personnel cooperation is needed. Each factor is scored within a preset score range, and a weighted average is taken to obtain a normalized attack feasibility value; quantifying attack motive into a three-level score based on the value level of the target asset and the attacker type, obtaining an attack motive score value, where attacker types include random attackers, targeted attackers, and targeted attackers; calculating the exposure window based on the proportion of interface open time to total runtime, assigning a value of 1 to permanently exposed interfaces, and calculating the exposure window based on the proportion of maintenance time for interfaces only open during ground maintenance; and converting the triples into probability values compatible with quantitative security analysis using a probability transformation function based on the normalized attack feasibility value, the attack motive score value, and the exposure window proportion, with: P_STE = 1 - (1 - AF_norm)^(AM_score * EW_ratio), where P_STE is the probability value obtained by the probability transformation function, AF_norm is the attack feasibility normalization value, AM_score is the attack motivation score value, and EW_ratio is the exposure window ratio.In some examples, the process of mapping each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model may include: extracting all external interface nodes from the fusion model as the initial intrusion point set of the attack graph, and extracting components carrying security-critical functions as the target asset set; starting from each initial intrusion point, expanding the attack path in a breadth-first search based on attack patterns in the threat knowledge base, and checking whether the current node can reach adjacent nodes using at least one attack pattern in the knowledge base after each expansion step, until the target asset is reached or expansion can no longer continue; calculating the path attack feasibility for each complete path from the intrusion point to the target asset in the generated attack graph, mapping each complete attack path to a security threat event node, and using the path attack feasibility as the attack feasibility parameter of the corresponding security threat event node; wherein, the attack motivation is the motivation score of the target asset in each complete path, and the exposure window is the exposure window value of the intrusion point in each complete path. In some examples, the feasibility of a path attack is obtained through a chained calculation of the feasibility of a conditional attack. The feasibility of each step in the path is conditional upon the success of the preceding steps. The formula for calculating the feasibility of a path attack is: AF_path = AF_1 * AF_2|1 * AF_3|1,2 * ... * AF_n|1,...,n-1, where AF_path is the result of the path attack feasibility calculation for the complete path, AF_1 represents the conditional attack feasibility of the first step, and AF_n|1,...,n-1 represents the conditional attack feasibility of the nth step under the condition that the preceding n-1 steps are all successful.
[0069] The fusion model solving module is used to perform minimum attack failure cut set search on the extended fault tree. During the cut set search process, the cut sets are divided into two categories: random failure cut sets and attack failure mixed cut sets. The cut set probability is calculated for random failure cut sets, and the risk of attack failure mixed cut sets is evaluated by a game theory model. The game theory model is used to model the optimal attack path chosen by the attacker as the attacker's strategy and the existing defense measures as the defender's strategy. The equilibrium risk of the mixed cut sets is obtained by solving the Nash equilibrium. In some examples, the process of performing a minimum attack failure cut set search on an extended fault tree may include: decomposing the extended fault tree from top to bottom, decomposing the top event layer by layer through logic gates to basic event nodes and security threat event nodes, generating all minimum event combinations that cause the top event to occur, denoted as cut sets; checking each cut set, marking cut sets containing only basic event nodes as random failure cut sets, cut sets containing only security threat event nodes as pure attack cut sets, and cut sets containing both types of nodes as mixed attack failure cut sets; calculating the cut set probability for random failure cut sets by multiplying the failure probabilities of each basic event by the independent assumption; for pure attack cut sets and mixed cut sets, incorporating them into the attacker's strategy space of the game theory model, with each cut set as an optional strategy for the attacker; removing cut sets whose cut set probability or danger level is lower than a preset threshold from all cut sets, sorting them from high to low danger, and outputting a list of minimum attack failure cut sets. In some examples, the computation process of the game theory model may include: constructing a zero-sum game model comprising the attacker's policy space and the defender's policy space, where the attacker's policy space is all cut sets containing security threat event nodes, and the defender's policy space is a set of implementable defensive measures, each defensive measure being defined as an operation that reduces the probability of a specific security threat event node; defining the payoff matrix, including: for the attacker choosing cut set i and the defender choosing defense combination j, the attacker's payoff is equal to the residual risk of that cut set under defense combination j, the residual risk being recalculated by reducing the probability of security threat event nodes affected by the defensive measures in the cut set by the defense effectiveness coefficient; solving for the mixed-policy Nash equilibrium on the payoff matrix, where the attacker's equilibrium strategy corresponds to the probability distribution of each cut set being chosen by a rational attacker, and the defender's equilibrium strategy corresponds to the optimal defense resource allocation scheme; the equilibrium risk of each cut set is equal to the probability of that cut set being chosen under the attacker's equilibrium strategy multiplied by the residual risk of that cut set under the defender's equilibrium strategy.
[0070] The requirement generation and reporting module is used to generate corresponding security requirements or information security requirements for each cut set whose risk exceeds the threshold based on the solution results of the fusion model. The requirements are labeled as pure security requirements, pure information security requirements, or coupled requirements according to their source. The coupled requirements are associated with security constraints and information security constraints, and sorted by risk to form a unified requirement set, so as to output a joint analysis report that conforms to the target format. In some examples, the rules for generating a unified requirement set can be as follows: For random failure segments with a risk level exceeding a threshold, security requirements are generated based on the components involved in each basic event within the random failure segment. These requirements include failure rate constraints, redundancy design requirements, or monitoring and detection requirements, and are labeled as pure security requirements. For pure attack segments with a risk level exceeding a threshold, information security requirements are generated based on the attack paths corresponding to each security threat event node within the pure attack segment. These requirements include access control measures, intrusion detection rules, or network isolation requirements, and are labeled as pure information security requirements. For mixed attack and failure segments with a risk level exceeding a threshold, both security constraints and information security constraints are generated simultaneously. These security constraints and information security constraints are interconnected to form a set of coupled requirements, and it is noted that failure to meet either constraint will result in a security consequence level. All requirements are sorted by risk level, and requirements of the same risk level are sorted by security consequence level to form a unified requirement set, which is then output.
[0071] In another exemplary embodiment of the present invention, such as Figure 1 As shown, an airborne system security analysis system based on attack graphs and fault trees is provided, which includes three core modules: a fusion model construction module, a fusion model solving module, and a requirement generation and reporting module.
[0072] The fusion model building module is responsible for integrating traditional fault trees and attack graphs into a unified extended fault tree. First, the module constructs a traditional fault tree according to the ARP4761 standard method, obtaining the top event (e.g., loss of navigation function) from the functional hazard assessment results, and decomposing it layer by layer to basic events (e.g., navigation computer hardware failure, sensor data interruption) through logic gates (AND / OR). Then, a Security Threat Event (STE) node type is added to the fault tree. Each STE node is described by a triple (Attack Feasibility AF, Attack Motivation AM, Exposure Window EW), distinguishing it from the failure rate description method of traditional basic events. The fusion model building module converts the triples into probability values using the probability transformation function P_STE = 1 - (1 - AF_norm)^(AM_score *EW_ratio). Simultaneously, the fusion model building module extracts network topology and data flow information from the system architecture model. Taking all external interfaces as the intrusion starting point and security-critical components as the targets, it uses a breadth-first search to generate an attack graph in conjunction with a threat knowledge base. After each complete attack path is calculated for feasibility through a conditional feasibility chain, it is mapped to a STE node in an extended fault tree. Ultimately, a unified model is formed that includes both traditional basic events and security threat events.
[0073] The fusion model solving module performs cutset analysis on the extended fault tree. Since the probabilistic semantics of STE nodes differ from traditional basic events, attackers will adaptively choose paths rather than randomly, rendering traditional minimum cutset algorithms inapplicable. The module first searches for all minimum cutsets through top-down decomposition, then classifies the cutsets: those containing only basic events are random failure cutsets, and those containing STE nodes are attack-related cutsets. Random failure cutsets are calculated based on the traditional probability independence assumption. For attack-related cutsets, the fusion model solving module constructs a two-player zero-sum game model: the attacker's policy space is all attack-related cutsets, and the defender's policy space is the set of defensive measures the system can implement. Each entry in the payoff matrix represents the residual risk when the attacker chooses a certain cutset and the defender chooses a certain defensive combination. By solving the mixed-policy Nash equilibrium, the probability distribution of a rational attacker's choice of each cutset and the optimal allocation of defensive resources are obtained, and then the equilibrium risk of each cutset is calculated.
[0074] The requirements generation and reporting module transforms the solution results into a set of requirements usable in the engineering process. For cut sets whose hazard exceeds a threshold, corresponding requirements are generated based on their composition: random failure cut sets generate security requirements (failure rate constraints, redundancy design, monitoring and detection); pure attack cut sets generate information security requirements (access control, intrusion detection, network isolation); and mixed cut sets simultaneously generate a set of coupled requirements (security constraints and information security constraints are interrelated, and failure to meet any constraint may lead to harm). All requirements are labeled with their source category and sorted by hazard, outputting a joint analysis report conforming to DO-326A and ARP4761 formats.
[0075] In one embodiment, such as Figure 2 As shown in the example, this embodiment uses the "loss of navigation function" top event of a certain type of avionics system as an example to demonstrate the construction of the extended fault tree and the attack graph mapping process. The avionics system architecture includes two redundant navigation computers (NAV-A and NAV-B), which receive data from the inertial navigation unit (IRS) and GPS receiver through the AFDX network. The AFDX network is connected to the ground maintenance terminal through a maintenance port. The traditional fault tree construction is shown in Table 1, the attack graph generation results (starting from the maintenance port) are shown in Table 2, and the STE node generation is shown in Table 3.
[0076] Table 1
[0077]
[0078] Table 2
[0079]
[0080] Table 3
[0081]
[0082] In the extended fault tree, the sub-events of G1 (simultaneous failure of NAV-A and NAV-B) are {BE1AND BE2} in the traditional FTA. After the extension, the hybrid cut sets {STE1 AND BE2} (attacker hijacks NAV-A + NAV-B random hardware failure) and {BE1 AND STE2} (NAV-A random hardware failure + attacker hijacks NAV-B) are added.
[0083] / * Conditional Attack Feasibility Chain Calculation * / / / This code snippet calculates the feasibility of each attack path in the attack graph, which is used to map multi-step attack paths to a single STE node.
[0084] typedef struct { / / Defines the attack steps structure, describing the attack feasibility parameters for each step in the attack path.
[0085] double af; / / Single-step attack feasibility, representing the feasibility score of an attacker successfully executing this attack step without considering previous steps, with a value ranging from 0 to 1.
[0086] double cond_af; / / Feasibility of conditional attack, indicating the feasibility of executing this attack step under the condition that all preceding steps are successful, taking into account the privilege escalation effect obtained by the attacker after the success of the preceding steps.
[0087] } AttackStep; / / This structure is the basic unit for chained computation of attack paths. Each attack path consists of an ordered sequence of multiple AttackSteps.
[0088] double calc_path_af(AttackStep steps[], int n) { / / Function definition: Calculates the feasibility of a complete attack path AF_path. The first parameter steps is an array of attack steps, and the second parameter n is the total number of steps in the path.
[0089] double path_af = steps[0].af; / / Initialize the path attack feasibility to the single-step attack feasibility AF_1 of the first step. The first step has no preconditions, so the original feasibility value is taken directly.
[0090] for (int i = 1; i < n; i++) { / / Starting from the second step (index 1), iterate through each subsequent attack step in the path, calculate the feasibility of the conditions step by step, and multiply them together.
[0091] / * Feasibility of conditions: After the success of the preceding steps, the attacker has gained / / The following comments explain the calculation logic of feasibility of conditions: The success of the preceding steps means that the attacker has broken through the previous security barriers. * /
[0092] The corresponding permissions may make subsequent steps easier or harder. * / / / The permissions obtained may make subsequent steps easier (e.g., easier lateral movement after gaining intranet access), so the feasibility value needs to be adjusted.
[0093] steps[i].cond_af = steps[i].af * (1.0 + 0.1 * i); / / Calculate the feasibility of the conditional attack at step i: the original feasibility is multiplied by the privilege escalation factor (1 + 0.1 * i). The feasibility increases moderately as the attacker accumulates more privileges in later steps.
[0094] if (steps[i].cond_af > 1.0) / / Boundary protection: The feasibility of the condition may exceed 1.0 (probability cap) after the privilege escalation adjustment, and needs to be truncated.
[0095] steps[i].cond_af = 1.0; / / Truncate conditions with a probability greater than 1.0 to 1.0 to ensure that the probability value remains within the effective probability range [0,1].
[0096] path_af *= steps[i].cond_af; / / Multiply the conditional feasibility of the current step into the path attack feasibility, to achieve chained computation of AF_path = AF_1 * AF_2|1 * AF_3|1,2 * ...
[0097] / / The loop ends, and the feasibility of all steps has been accumulated into path_af through chained multiplication.
[0098] return path_af; / / Returns the path attack feasibility AF_path of the complete attack path, which will be used as the attack feasibility parameter for the corresponding STE node.
[0099] } / / Once the function finishes executing, the return value is used to map the attack path to the STE node in the fusion model building module.
[0100] / * STE Probability Conversion Function * / / / The following function converts the triples of security threat event nodes into probability values, enabling attack events to be quantitatively calculated in the same fault tree as random failures.
[0101] double calc_p_ste(double af_norm, / / Function definition: The first parameter af_norm is the attack feasibility normalization value, which is obtained by normalizing the path attack feasibility of the attack path, and the value ranges from 0 to 1.
[0102] double am_score, / / The second parameter am_score is the attack motivation score, which is a three-level score quantified based on the value level of the target asset and the type of attacker.
[0103] double ew_ratio) { / / The third parameter ew_ratio is the exposure window ratio, which represents the proportion of the system's external interface open time to the total running time. The value of permanently exposed interfaces is 1.
[0104] / * P_STE = 1 - (1 - AF_norm)^(AM_score * EW_ratio) * / / / Probability conversion formula explanation: Converts the triple (AF, AM, EW) into a probability value P_STE that is compatible with quantitative safety analysis.
[0105] double exponent = am_score * ew_ratio; / / Calculate the exponent, which is equal to the product of the attack motivation score and the exposure window ratio. The stronger the motivation and the longer the exposure, the larger the exponent and the higher the final probability.
[0106] return 1.0 - pow(1.0 - af_norm, exponent); / / Returns the STE probability value: 1 minus (1-AF_norm) raised to the power of exponent. The higher the AF_norm, the larger the AM_score, and the larger the EW_ratio, the closer P_STE is to 1.
[0107] } / / After the function finishes execution, the returned P_STE value is attached to the STE node of the extended fault tree and participates in the cut set probability calculation under the same dimension as the failure probability of traditional basic events.
[0108] In one embodiment, such as Figure 3 As shown in the figure, this embodiment demonstrates the process of performing a minimum attack failure cut set search and game theory solution on the above-mentioned extended fault tree. The cut set search results are shown in Table 4, the implementable defense measures are shown in Table 5, and the game theory payoff matrix (attacker's payoff = residual risk) is shown in Table 6.
[0109] Table 4
[0110]
[0111] Table 5
[0112]
[0113] Table 6
[0114]
[0115] Nash equilibrium result:
[0116] - Attacker's balanced strategy: CS6 probability 0.55, CS2 probability 0.25, CS3 probability 0.15, CS4 probability 0.05
[0117] - Optimal strategy for the defender: D1+D3 combination (maintain port authentication + IRS data authentication).
[0118] - Risk of equilibrium for each cut set: CS6=0.0009, CS2=0.0004, CS3=0.0002, CS4=0.00003.
[0119] / * Game Theory Payoff Matrix Construction * / / / This code segment implements the construction of the payoff matrix of the game theory model and the calculation of the residual risk of the hybrid cut set in the fusion model solving module.
[0120] typedef struct { / / Defines the payoff matrix entry structure, describing the payoff value corresponding to each (attack strategy, defense strategy) combination in the game matrix.
[0121] int cutset_id; / / Attacker's strategy number, i.e., the cutset number chosen by the attacker, corresponding to the index in the attack-related cutset list.
[0122] int defense_id; / / Defense strategy number, i.e., the combination number of defense measures selected by the defender, corresponding to the index in the list of defense measure combinations.
[0123] double residual_risk; / / Residual risk level, representing the residual risk value faced by the system under the condition that the attacker chooses this cut set and the defender chooses this defense combination.
[0124] } PayoffEntry; / / This structure constitutes a cell of the payoff matrix, and all entries form the complete payoff matrix for a two-player zero-sum game.
[0125] / * Reduction of STE probability by defensive measures * / / / The following function calculates the reduction of the probability of a security threat event by a single defensive measure.
[0126] double apply_defense(double p_ste, / / Function definition: The first parameter p_ste is the current probability value of the security threat event node before the defense measure is applied.
[0127] double defense_eff) { / / The second parameter defense_eff is the effectiveness coefficient of the defense measure for the STE node, ranging from 0 to 1, which indicates the proportion by which the defense measure can reduce the probability of STE.
[0128] return p_ste * (1.0 - defense_eff); / / Returns the STE probability value after defense measures are reduced: the original probability multiplied by (1 - defense effectiveness). The higher the effectiveness, the lower the residual probability.
[0129] } / / After the function finishes execution, the return value represents the residual probability of the STE node under the protection of specific defense measures.
[0130] / * Calculate the residual risk of the hybrid cut set * / / / The following function calculates the residual risk of the attack-failure hybrid cut set under a specific defense combination, which is the core of the calculation of each entry in the payoff matrix.
[0131] double calc_residual_risk(int cutset[], / / Function definition: The first parameter cutset is an array of event numbers in the cutset, containing the numbers of all the constituent events of the cutset.
[0132] int cs_size, / / The second parameter cs_size is the size of the cutset, that is, the number of events in the cutset array.
[0133] int defenses[], / / The third parameter defenses is an array of defense measure numbers selected by the defender, containing all active defense measure numbers in the current defense combination.
[0134] int def_size, / / The fourth parameter def_size is the number of defense measures in the current defense combination, that is, the length of the defenses array.
[0135] double p_be[], / / The fifth parameter p_be is an array of basic event failure probabilities, storing the failure rate of each basic event in a traditional fault tree.
[0136] double p_ste[], / / The sixth parameter p_ste is a security threat event probability array, which stores the initial probability value of each STE node calculated by the probability transformation function.
[0137] double def_eff[][MAX_STE]) { / / The seventh parameter def_eff is a two-dimensional array of defense effectiveness, def_eff[j][k] represents the effectiveness coefficient of the j-th defense measure against the k-th STE node.
[0138] double risk = 1.0; / / Initialize the residual risk to 1.0, and then calculate the overall probability of the cut set by multiplying the probabilities of each event (the events in the cut set are in an AND relationship, and the probabilities are multiplied).
[0139] for (int i = 0; i < cs_size; i++) { / / Iterate through each event in the cut set, calculate the effective probability of the event under the current defense combination, and multiply them together.
[0140] if (is_basic_event(cutset[i])) { / / Determine if the current event is a traditional basic event (random hardware failure, etc.). Basic events are not affected by defense measures.
[0141] risk *= p_be[cutset[i]]; / / If it is a basic event, directly multiply its failure probability into the residual risk. The probability of a basic event is constant and is not reduced by defensive measures.
[0142] } else { / / If the current event is not a basic event, it is a Security Threat Event Node (STE), and the reduction effect of defense measures needs to be considered.
[0143] double p = p_ste[cutset[i]]; / / Get the initial probability value P_STE of the STE node as the starting value for defense reduction calculation.
[0144] for (int j = 0; j < def_size; j++) { / / The inner loop iterates through each defense measure in the current defense combination, reducing the probability of the STE node one by one.
[0145] p = apply_defense(p, / / Call the defense reduction function to reduce the current STE probability p according to the effectiveness of the j-th defense measure).
[0146] def_eff[defenses[j]][cutset[i]]); / / Find the effectiveness coefficient of the j-th defense measure for the current STE node from the defense effectiveness matrix, and use it as a reduction parameter.
[0147] / / The inner loop ends, and p is now the residual probability of the STE node after being reduced one by one by all activated defense measures.
[0148] risk *= p; / / Multiply the reduced STE residual probability into the cut set residual risk.
[0149] / / The current event has been processed. Continue processing the next event in the cut set.
[0150] / / The outer loop ends, and the probabilities of all events have been multiplied. Risk is the residual risk of this cut set under the current defense combination.
[0151] return risk; / / Returns the residual risk value of the cut set, which serves as the attacker's payoff for the corresponding entry in the game theory payoff matrix.
[0152] } / / After the function finishes executing, the return value is filled into the residual_risk field of the PayoffEntry structure, forming a cell of the profit matrix.
[0153] In one embodiment, such as Figure 4 As shown in the figure, this embodiment demonstrates the process of automatically generating a unified requirement set based on the solution results of the fusion model. Taking the cutset analysis results of a certain embodiment above as input, requirements are generated according to the following rules. The corresponding mapping results from cutsets to requirements are shown in Table 7, and the requirement priority ranking (by risk level + consequence level) is shown in Table 8.
[0154] Table 7
[0155]
[0156] Table 8
[0157]
[0158] / * Requirements generation rules * / / / This code segment implements the core logic of the requirements generation and reporting module, including cut set classification, requirements structure definition, and automatic generation of unified requirements sets.
[0159] typedef enum { / / Defines a requirement category enumeration type, used to mark the source category of each requirement, distinguishing between pure security requirements, pure information security requirements, and coupled requirements.
[0160] REQ_SAFETY, / / Pure security requirement identifier, corresponding to the requirements generated from cut sets containing only basic events (random failures), including failure rate constraints, redundant design, or monitoring and detection requirements.
[0161] REQ_SECURITY, / / Pure information security requirement identifier, corresponding to the requirements generated by a cut set containing only security threat event nodes (pure attack), the content of which is access control, intrusion detection or network isolation requirements.
[0162] REQ_COUPLED / / Coupling requirement identifier, corresponding to the requirement generated by a cut set that simultaneously contains basic event and security threat event nodes (attack-failure hybrid), and includes both security constraints and information security constraints.
[0163] } ReqCategory; / / The three values of this enumeration correspond to the three requirement categories defined in steps (a), (b), and (c) of claim 6.
[0164] typedef struct { / / Defines the requirement structure, describing the complete information of each requirement in the joint analysis report.
[0165] char id
[16] ; / / Requirement number string, formatted as "REQ-S-001" (pure security) or "REQ-C-001" (pure information security or coupling), used for requirement tracking and referencing.
[0166] int source_cutset; / / Source cutset number, which records which cutset's analysis result triggered the generation of the requirement, supporting forward tracing from requirement to cutset.
[0167] ReqCategory category; / / Requirement category identifier, which can be one of REQ_SAFETY, REQ_SECURITY, or REQ_COUPLED, indicating which category the requirement belongs to.
[0168] char safety_constraint
[256] ; / / Safety constraint content string, storing the description of the security requirements corresponding to the requirement (such as the upper limit of failure rate, redundancy design requirements, etc.). This field is empty for pure information security requirements.
[0169] char security_constraint
[256] ; / / Information security constraint content string, storing the description of the information security requirements corresponding to the requirement (such as access control rules, intrusion detection configuration, etc.). This field is empty for pure security requirements.
[0170] int consequence_level; / / Safety consequence level, 1 represents catastrophic (CAT), 2 represents hazardous (HAZ), and 3 represents major (MAJ), used for prioritizing requirements.
[0171] double risk_score; / / Risk score, derived from the balanced risk of cut sets (attack-related cut sets) or the probability of cut sets (random failure cut sets), used for prioritizing requirements.
[0172] } Requirement; / / This structure is the complete data carrier of each requirement in the unified requirement set. All requirements are summarized to form the requirement part of the joint analysis report.
[0173] ReqCategory classify_cutset(CutSet *cs) { / / Function definition: Classifies a single cutset into categories. The parameter cs is a pointer to the cutset structure to be classified. Returns the required category corresponding to the cutset.
[0174] int has_be = 0, has_ste = 0; / / Initialize two flag variables: has_be marks whether the cut set contains basic event nodes, and has_ste marks whether it contains security threat event nodes.
[0175] for (int i = 0; i < cs->size; i++) { / / Loop through each event in the cut set and check its event type.
[0176] if (cs->events[i].type == BASIC_EVENT) / / Determine if the current event is a basic event type (a random failure event in a traditional fault tree, such as hardware failure, software defect, etc.).
[0177] has_be = 1; / / If it is a basic event, set the has_be flag to 1 to record that the cut set contains at least one random failure event.
[0178] else if (cs->events[i].type == SECURITY_THREAT) / / Determine if the current event is a security threat event type (a newly added STE node in the extended fault tree, corresponding to the attack path in the attack graph).
[0179] has_ste = 1; / / If it is a security threat event, set the has_ste flag to 1 to record that the cut set contains at least one attack event.
[0180] / / The loop ends, and has_be and has_ste record the existence of the two event types in the cut set, respectively.
[0181] if (has_be && !has_ste) return REQ_SAFETY; / / If the cut set contains only basic events and not security threat events, it is classified as a pure security requirement category (random failure cut set).
[0182] if (!has_be && has_ste) return REQ_SECURITY; / / If the cut set only contains security threat events and not basic events, it is classified as a pure information security requirement category (pure attack cut set).
[0183] return REQ_COUPLED; / / If the cut set contains both basic events and security threat events, it is classified as a coupled requirement category (attack-failure hybrid cut set).
[0184] } / / After the function finishes executing, the returned requirement category is used to fill in the requirement content and label the requirement attributes according to the category.
[0185] void generate_requirements(CutSet cutsets[], / / Function definition: Automatically generates a unified set of requirements. The first parameter, cutsets, is an array of all cutsets (including randomly invalid cutsets and attack-related cutsets).
[0186] int n, / / The second parameter n is the length of the cut set array, i.e., the total number of cut sets.
[0187] Requirement reqs[], / / The third parameter reqs is an array of output requirements used to store all generated requirements.
[0188] int *req_count) { / / The fourth parameter, req_count, is a pointer to the demand counter, which outputs the total number of demands actually generated.
[0189] *req_count = 0; / / Initialize the demand counter to 0, and increment the counter by 1 for each subsequent demand generated.
[0190] for (int i = 0; i < n; i++) { / / Iterate through all cut sets and determine for each cut set whether a requirement needs to be generated.
[0191] if (cutsets[i].risk < RISK_THRESHOLD) / / Determine if the risk of the current cutset is lower than the preset threshold RISK_THRESHOLD. Cutsets with a risk lower than the threshold are acceptable and do not need to generate requirements.
[0192] continue; / / Skip cut sets with a danger level below the threshold, do not generate requirements for them, and continue processing the next cut set.
[0193] Requirement r; / / Declare a local variable r of a requirement structure to temporarily store the requirement information corresponding to the current cut set.
[0194] r.source_cutset = cutsets[i].id; / / Set the source cutset number of the requirement to the number of the current cutset to establish a traceability association from the requirement to the cutset.
[0195] r.category = classify_cutset(&cutsets[i]); / / Call the cutset classification function to determine the category of the current cutset, and return REQ_SAFETY, REQ_SECURITY or REQ_COUPLED.
[0196] r.risk_score = cutsets[i].risk; / / Sets the risk score of a demand to the risk value of the current cutset, which will be used for subsequent demand priority sorting.
[0197] r.consequence_level = cutsets[i].consequence; / / Sets the safety consequence level of the requirement to the hazard consequence level (CAT / HAZ / MAJ) associated with the current cutset for sorting and reporting annotation.
[0198] / * Fill in constraint content by category (specific business logic omitted) * / / / Here, different constraint content generation logic is called according to the requirement category: pure security fills in safety_constraint, pure information security fills in security_constraint, and coupled requirements fill in both.
[0199] reqs[(*req_count)++] = r; / / Copy the completed demand structure to the current position of the output demand array, and increment the demand counter to point to the next available position.
[0200] / / The loop ends, and all cut sets exceeding the danger threshold have generated corresponding requirements and stored in the reqs array.
[0201] / * Sort by hazard level + consequence level * / / / The following code sorts the generated requirement set by priority, ensuring that high-priority requirements are listed first in the output requirement set.
[0202] qsort(reqs, *req_count, sizeof(Requirement), cmp_priority); / / Sorts the requirement array by calling the standard library quicksort function. The cmp_priority comparison function implements the sorting logic of first sorting by hazard level in descending order, and then sorting by consequence level in ascending order for the same hazard level (CAT>HAZ>MAJ).
[0203] } / / After the function finishes execution, the reqs array stores the complete unified requirements set sorted by priority, req_count points to the total number of requirements, and the output is used to generate a joint analysis report conforming to DO-326A and ARP4761 formats.
[0204] In one embodiment, such as Figure 5 As shown, this embodiment takes a certain type of avionics system containing 3 security domains (flight critical domain, aviation operation domain, and passenger information domain), 12 main components, and 8 external interfaces as an example to compare the hazard scenario coverage of fusion analysis and traditional independent analysis (FTA + attack graph analysis respectively). The corresponding analysis configuration is shown in Table 9, the results of traditional independent analysis are shown in Table 10, the results of fusion analysis are shown in Table 11, the specific analysis of 7 super-threshold hybrid cut sets is shown in Table 12, and the coverage comparison is shown in Table 13.
[0205] Table 9
[0206]
[0207] Table 10
[0208]
[0209] Table 11
[0210]
[0211] Table 12
[0212]
[0213] Table 13
[0214]
[0215] In summary, this invention provides an airborne system security analysis system based on attack graphs and fault trees. It integrates security and information security reports into a unified extended fault tree, enabling the identification and quantification of mixed hazard scenarios involving "attack events + random failures" at the model level. This achieves quantitative coupling of security and information security analysis within the same formal model. Since the fundamental difference between attacks and random failures lies in the attacker's path selection and the change in probability with defense, this system addresses this difference through triplet parameterization and game theory models. This allows for unified quantitative calculation of both types of events within the same fault tree, thus resolving the compatibility issue between attack behavior and random failures in a probabilistic sense through the probability transformation function of security threat event nodes. Furthermore, this system provides a decision-making basis for defense resource allocation through game theory solutions. The Nash equilibrium solution not only provides a ranking of the danger levels of each cut set but also the optimal strategy for the defender, i.e., which defense measures should be prioritized for limited defense resources. In the analysis experiments, the resource allocation scheme given by the game theory model reduced the overall residual danger of the system by 42% compared to the uniform allocation scheme. Furthermore, since the two sets of requirements generated by independent analysis may conflict (security requires data availability while information security requires data isolation) or be incomplete (mixed scenarios not covered by either set of requirements), this system eliminates the gap between security and information security requirements by unifying the requirement set. Therefore, the coupling requirement mechanism of this system binds related security and information security constraints into a group, reducing conflicts and omissions between requirements. Simultaneously, this system can output reports that simultaneously meet the requirements of DO-326A and ARP4761 formats. Security auditors and information security auditors can obtain the analysis results of their respective concerns from the same report, reducing cross-domain communication costs. Therefore, this system can establish a unified formal framework for security analysis and information security analysis. By extending the traditional fault tree model, this system can accommodate information security threat events. A mapping mechanism from attack graphs to extended fault trees is designed to integrate the inputs of both types of analysis. A cut-set solving algorithm suitable for including attack behaviors is proposed, ultimately outputting unified analysis results that simultaneously cover both security and information security requirements. This system can add a fusion layer to the existing FTA or attack graph analysis, enabling the two originally separate analysis systems to work together and discover mixed hazard scenarios that could not be identified by individual analysis.
[0216] It should be noted that the airborne system security analysis system based on attack graphs and fault trees provided in the above embodiments and the airborne system security analysis method based on attack graphs and fault trees provided in the above embodiments belong to the same concept. The specific operation methods of each module and unit have been described in detail in the method embodiments and will not be repeated here. In practical applications, the airborne system security analysis system based on attack graphs and fault trees provided in the above embodiments can be assigned to different functional modules as needed, that is, the internal structure of the system can be divided into different functional modules to complete all or part of the functions described above. No limitation is imposed here. Therefore, the present invention effectively overcomes the various shortcomings of the prior art and has high industrial application value.
[0217] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.
Claims
1. A method for airborne system security analysis based on attack graphs and fault trees, characterized in that, The method includes the following steps: A security threat event node type is added to the basic event node of the original fault tree to form a fusion model; the security threat event node is used to parameterize the triple consisting of attack feasibility, attack motivation and exposure window; The triples are converted into probability values compatible with quantitative security analysis using a probability transformation function, and network topology and data flow information are extracted from the fusion model. An attack graph is then generated by combining the threat knowledge base. Each complete attack path from the initial intrusion point to the target asset in the attack graph is mapped to a security threat event node in the fusion model, and an extended fault tree containing traditional basic event nodes and security threat event nodes is constructed. A minimum attack failure cut set search is performed on the extended fault tree. During the cut set search, the cut sets are divided into two categories: random failure cut sets and mixed attack failure cut sets. The cut set probability is calculated for random failure cut sets, and the risk of the mixed attack failure cut sets is evaluated using a game theory model. The game theory model is used to model the optimal attack path chosen by the attacker as the attacker's strategy and the existing defense measures as the defender's strategy. The equilibrium risk of the mixed cut sets is obtained by solving the Nash equilibrium. Based on the solution results of the fusion model, corresponding security requirements or information security requirements are generated for each cut set whose risk exceeds the threshold. These requirements are labeled as pure security requirements, pure information security requirements, or coupled requirements according to their source. Security constraints and information security constraints are associated with coupled requirements, and a unified set of requirements is formed by sorting them by risk level to output a joint analysis report that conforms to the target format.
2. The airborne system security analysis method based on attack graphs and fault trees according to claim 1, characterized in that, The process of converting triples into probability values compatible with quantitative security analysis using probability transformation functions includes: The feasibility of an attack is assessed using a five-level quantitative scoring system. The scoring is based on four factors: the level of professional knowledge required for the attack, the difficulty of acquiring the required equipment, the length of the attack window, and whether internal personnel cooperation is required. Each factor is scored within a preset score range, and the weighted average is taken to obtain the normalized value of the attack feasibility. The attack motivation is quantified into a three-level score based on the value level of the target asset and the type of attacker, resulting in an attack motivation score. The types of attackers include random attackers, targeted attackers, and targeted attackers. The exposure window is calculated based on the proportion of time the interface is open to the outside world to the total running time. The value of the permanently exposed interface is set to 1. The value of the interface that is only open during ground maintenance is calculated based on the proportion of maintenance time. Based on the attack feasibility normalized value, attack motivation score, and exposure window ratio, the triple is converted into a probability value compatible with quantitative security analysis through a probability transformation function: P_STE = 1 - (1 - AF_norm)^(AM_score* EW_ratio), where P_STE is the probability value obtained by the probability transformation function, AF_norm is the attack feasibility normalized value, AM_score is the attack motivation score, and EW_ratio is the exposure window ratio.
3. The airborne system security analysis method based on attack graphs and fault trees according to claim 1, characterized in that, The process of mapping each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model includes: Extract all external interface nodes from the fusion model as the initial intrusion point set of the attack graph, and extract the components carrying security-critical functions as the target asset set; Starting from each initial intrusion point, the attack path is expanded by breadth-first search in combination with the attack patterns in the threat knowledge base. After each expansion step, it is checked whether the current node can reach the adjacent node using at least one attack pattern in the knowledge base, until the target asset is reached or the expansion can no longer continue. For each complete path from the intrusion point to the target asset in the generated attack graph, the feasibility of the path attack is calculated, and each complete attack path is mapped to a security threat event node. The feasibility of the path attack is used as the attack feasibility parameter of the corresponding security threat event node. Among them, the attack motivation is the motivation score of the target asset in each complete path, and the exposure window is the exposure window value of the intrusion point in each complete path.
4. The airborne system security analysis method based on attack graphs and fault trees according to claim 3, characterized in that, The feasibility of the path attack is obtained through a chain-like calculation of the feasibility of conditional attacks. The feasibility of each step in the path is conditional upon the success of the preceding steps. The calculation formula for the feasibility of the path attack is: AF_path = AF_1 * AF_2|1 * AF_3|1,2 * ... * AF_n|1,...,n-1, where AF_path is the result of the path attack feasibility calculation for the complete path, AF_1 represents the feasibility of the conditional attack in step 1, and AF_n|1,...,n-1 represents the feasibility of the conditional attack in step n under the condition that the preceding n-1 steps are all successful.
5. The airborne system security analysis method based on attack graphs and fault trees according to claim 1, characterized in that, The process of performing a minimum attack failure cutset search on the extended fault tree includes: The extended fault tree is decomposed from top to bottom. The top event is decomposed layer by layer through logic gates to the basic event node and the security threat event node, generating all the smallest event combinations that cause the top event to occur, denoted as the cut set. Each cut set is examined, and cut sets containing only basic event nodes are marked as random failure cut sets, cut sets containing only security threat event nodes are marked as pure attack cut sets, and cut sets containing both types of nodes are marked as attack failure hybrid cut sets. For random failure cut sets, the probability of the cut set is calculated by multiplying the failure probabilities of each basic event by the independent assumption. For pure attack cut sets and mixed cut sets, they are included in the attacker's strategy space of the game theory model, and each cut set is regarded as an optional strategy of the attacker. Remove cut sets whose probability or risk level is lower than a preset threshold from all cut sets, sort them by risk level from high to low, and output a list of cut sets with the least attack failure.
6. The airborne system security analysis method based on attack graphs and fault trees according to claim 1, characterized in that, The calculation process of the game theory model includes: A zero-sum game model is constructed, which includes the attacker's strategy space and the defender's strategy space. The attacker's strategy space is a cut set of all nodes containing security threat events, and the defender's strategy space is a set of implementable defense measures. Each defense measure is defined as an operation that can reduce the probability of a specific security threat event node. The benefit matrix is defined as follows: for the attacker choosing cut set i and the defender choosing defense combination j, the attacker's benefit is equal to the residual risk of the cut set under defense combination j. The residual risk is obtained by recalculating the probability of security threat event nodes affected by defense measures in the cut set after reducing the defense effectiveness coefficient. Solve for the mixed-policy Nash equilibrium on the payoff matrix, where the attacker's equilibrium policy corresponds to the probability distribution of each cut set chosen by the rational attacker, and the defender's equilibrium policy corresponds to the optimal defense resource allocation scheme. The equilibrium risk of each cut set is equal to the probability of that cut set being chosen under the attacker's equilibrium strategy multiplied by the residual risk of that cut set under the defender's equilibrium strategy.
7. The airborne system security analysis method based on attack graphs and fault trees according to claim 1, characterized in that, The generation rules for the unified requirement set are as follows: For random failure cut sets whose risk exceeds the threshold, safety requirements are generated based on the components involved in each basic event in the random failure cut set. The corresponding requirements include failure rate constraints, redundancy design requirements, or monitoring and detection requirements, and are marked as pure safety requirements. For pure attack cut sets whose risk level exceeds the threshold, information security requirements are generated based on the attack paths corresponding to each security threat event node in the pure attack cut set. The corresponding requirements include access control measures, intrusion detection rules or network isolation requirements, and are marked as pure information security requirements. For attacks whose risk level exceeds the threshold, a hybrid cut set is generated to fail. At the same time, security constraints and information security constraints are generated. The security constraints and information security constraints are related to each other to form a set of coupled requirements. The level of security consequences is marked if either of the two constraints is not met. All requirements are sorted by hazard level, and requirements with the same hazard level are sorted by safety consequence level, forming a unified requirement set and outputting it.
8. An airborne system security analysis system based on attack graphs and fault trees, characterized in that, The system includes: The fusion model construction module is used to add security threat event node types to the basic event nodes of the original fault tree to form a fusion model; and to convert triples into probability values compatible with quantitative security analysis through a probability transformation function, extract network topology and data flow information from the fusion model, and generate an attack graph by combining it with a threat knowledge base; and to map each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model, constructing an extended fault tree containing traditional basic event nodes and security threat event nodes; wherein, the security threat event node is used to parameterize the triples composed of attack feasibility, attack motive, and exposure window; The fusion model solving module is used to perform minimum attack failure cut set search on the extended fault tree. During the cut set search process, the cut sets are divided into two categories: random failure cut sets and attack failure mixed cut sets. The cut set probability is calculated for random failure cut sets, and the risk of attack failure mixed cut sets is evaluated by a game theory model. The game theory model is used to model the optimal attack path chosen by the attacker as the attacker's strategy and the existing defense measures as the defender's strategy. The equilibrium risk of the mixed cut sets is obtained by solving the Nash equilibrium. The requirement generation and reporting module is used to generate corresponding security requirements or information security requirements for each cut set whose risk exceeds the threshold based on the solution results of the fusion model. The requirements are labeled as pure security requirements, pure information security requirements, or coupled requirements according to their source. The coupled requirements are associated with security constraints and information security constraints, and sorted by risk to form a unified requirement set, so as to output a joint analysis report that conforms to the target format.
9. The airborne system security analysis system based on attack graphs and fault trees according to claim 8, characterized in that, The process of converting triples into probability values compatible with quantitative security analysis using probability transformation functions includes: The feasibility of an attack is assessed using a five-level quantitative scoring system. The scoring is based on four factors: the level of professional knowledge required for the attack, the difficulty of acquiring the required equipment, the length of the attack window, and whether internal personnel cooperation is required. Each factor is scored within a preset score range, and the weighted average is taken to obtain the normalized value of the attack feasibility. The attack motivation is quantified into a three-level score based on the value level of the target asset and the type of attacker, resulting in an attack motivation score. The types of attackers include random attackers, targeted attackers, and targeted attackers. The exposure window is calculated based on the proportion of time the interface is open to the outside world to the total running time. The value of the permanently exposed interface is set to 1. The value of the interface that is only open during ground maintenance is calculated based on the proportion of maintenance time. Based on the attack feasibility normalized value, attack motivation score, and exposure window ratio, the triple is converted into a probability value compatible with quantitative security analysis through a probability transformation function: P_STE = 1 - (1 - AF_norm)^(AM_score* EW_ratio), where P_STE is the probability value obtained by the probability transformation function, AF_norm is the attack feasibility normalized value, AM_score is the attack motivation score, and EW_ratio is the exposure window ratio.
10. The airborne system security analysis system based on attack graphs and fault trees according to claim 8, characterized in that, The process of mapping each complete attack path from the initial intrusion point to the target asset in the attack graph to a security threat event node in the fusion model includes: Extract all external interface nodes from the fusion model as the initial intrusion point set of the attack graph, and extract the components carrying security-critical functions as the target asset set; Starting from each initial intrusion point, the attack path is expanded by breadth-first search in combination with the attack patterns in the threat knowledge base. After each expansion step, it is checked whether the current node can reach the adjacent node using at least one attack pattern in the knowledge base, until the target asset is reached or the expansion can no longer continue. For each complete path from the intrusion point to the target asset in the generated attack graph, the feasibility of the path attack is calculated, and each complete attack path is mapped to a security threat event node. The feasibility of the path attack is used as the attack feasibility parameter of the corresponding security threat event node. The attack motivation is the motivation score of the target asset in each complete path, and the exposure window is the exposure window value of the intrusion point in each complete path. The feasibility of the path attack is obtained through a chained calculation of conditional attack feasibility. The feasibility of each step in the path is conditional upon the success of the preceding steps. The formula for calculating the feasibility of the path attack is: AF_path = AF_1 * AF_2|1 * AF_3|1,2 * ... * AF_n|1,...,n-1, where AF_path is the result of the path attack feasibility calculation for the complete path, AF_1 represents the conditional attack feasibility of the first step, and AF_n|1,...,n-1 represents the conditional attack feasibility of the nth step under the condition that the preceding n-1 steps are all successful.