System security assessment method and apparatus, and device, storage medium and program product

By acquiring security assessment indicators and calculating security assessment parameters at each level of the industrial control system, and combining the analytic hierarchy process (AHP) to determine the weights, the problem of low accuracy in security assessment of cloud-edge collaborative industrial control systems was solved. This enabled precise assessment and risk management of system security, and enhanced the system's security stability.

WO2025020790A9PCT designated stage expired Publication Date: 2026-02-12PURPLE MOUNTAIN LAB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/100427
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-07-26
Filing Date
2024-06-20
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing technologies have low accuracy in assessing the security of cloud-edge collaborative industrial control systems. They cannot effectively identify and quantify the security factors of the system, resulting in the inability to take timely preventive and remedial measures, which increases the risk of cyberattacks.

Method used

By acquiring the first security assessment index of each level of the industrial control system, calculating the security assessment parameters using the index assessment model, determining the weight parameters of each index using the analytic hierarchy process, and finally determining the security assessment result of the system based on the security assessment parameters, a precise security assessment of the cloud-edge collaborative industrial control system is achieved.

Benefits of technology

It improves the accuracy of security assessment for cloud-edge collaborative industrial control systems, provides an intuitive understanding of the system's security level, helps to correctly deploy prevention and control measures, reduces severe incidents caused by cyberattacks, and enhances the safe and stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024100427_12022026_PF_FP_ABST
    Figure CN2024100427_12022026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a system security assessment method and apparatus, and a device, a storage medium and a program product. The method comprises: acquiring first security assessment indicators corresponding to an industrial control system, wherein the industrial control system at least comprises an industrial cloud platform layer, an edge control platform layer and a terminal device layer; according to each first security assessment indicator and an indicator assessment model corresponding to each first security assessment indicator, determining a security assessment parameter corresponding to each first security assessment indicator, wherein each indicator assessment model is used for calculating the security assessment parameter for the corresponding first security assessment indicator; and according to the security assessment parameters, determining a security assessment result corresponding to the industrial control system. By means of the method, the accuracy of a security assessment result of a cloud-edge collaborative industrial control system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

System security evaluation method, device, equipment, storage medium and program product

[0001] Related applications

[0002] The present application claims priority to the Chinese patent application No. 2023109333428, filed on July 26, 2023, entitled "System security evaluation method, device, equipment, storage medium and program product", the contents of which are hereby incorporated by reference in their entirety. TECHNICAL FIELD

[0003] Field of information security technology BACKGROUND

[0004] With the gradual evolution of industrial control systems to cloud-edge collaborative open architecture, the physical isolation security boundary relied on by the industrial control system has collapsed. Once a network attack-based functional safety event occurs, it will cause power outages or water outages, traffic chaos, production paralysis and other major accidents that affect social safety. In addition, the time of initiating a network attack, the target of the attack and the attack method are uncertain and unpredictable, so these factors greatly affect the safety of the operation of the cloud-edge collaborative industrial control system. In order to protect the complex system of cloud-edge collaborative industrial control system, it is necessary to study the security evaluation method of cloud-edge collaborative industrial control system under network attack.

[0005] In some cases, when evaluating the security of a cloud-edge collaborative industrial control system under network attack, the security of the cloud-edge collaborative industrial control system is mainly evaluated based on the information level. Here, the evaluation based on the information level, for example, can be to set some network attacks to evaluate the security of the system under the network attack.

[0006] However, in the above case, there is a problem that the accuracy of the evaluation result obtained when evaluating the security of the cloud-edge collaborative industrial control system is not high.

[0007] SUMMARY

[0008] Therefore, it is necessary to provide a system security evaluation method, device, equipment, storage medium and program product capable of improving the accuracy of the security evaluation result of the cloud-edge collaborative industrial control system to solve the above technical problems.

[0009] In a first aspect, the present application provides a system security evaluation method, which comprises:

[0010] obtaining first security evaluation indexes corresponding to each level in an industrial control system; the industrial control system at least includes a cloud platform layer, an edge control platform layer and a terminal device layer;

[0011] According to each first safety evaluation index and the index evaluation model corresponding to each first safety evaluation index, a safety evaluation parameter corresponding to each first safety evaluation index is determined; each index evaluation model is used for safety evaluation parameter calculation on the corresponding first safety evaluation index.

[0012] According to each safety evaluation parameter, a safety evaluation result corresponding to the industrial control system is determined.

[0013] In one of the embodiments, before the above-mentioned determination of the safety evaluation parameter corresponding to each first safety evaluation index according to each first safety evaluation index and the index evaluation model corresponding to each first safety evaluation index, the method further comprises:

[0014] Each second safety evaluation index corresponding to each first safety evaluation index is obtained; each second safety evaluation index of each first safety evaluation index is an index of the same level and / or different levels;

[0015] According to a preset analytic hierarchy process and each first safety evaluation index, a first weight parameter corresponding to each first safety evaluation index is determined;

[0016] According to the analytic hierarchy process and each second safety evaluation index of the same level, a second weight parameter corresponding to each second safety evaluation index of the same level is determined.

[0017] In one of the embodiments, the above-mentioned determination of the safety evaluation parameter corresponding to each first safety evaluation index according to each first safety evaluation index and the index evaluation model corresponding to each first safety evaluation index comprises:

[0018] Each second safety evaluation index is respectively input into the corresponding index evaluation model to determine a sub-evaluation parameter corresponding to each second safety evaluation index;

[0019] Each second weight parameter is respectively input into the corresponding index evaluation model, and each sub-evaluation parameter and the corresponding second weight parameter are subjected to mathematical operation processing to determine the safety evaluation parameter corresponding to each first safety evaluation index.

[0020] In one of the embodiments, the above-mentioned determination of the first weight parameter corresponding to each first safety evaluation index according to the preset analytic hierarchy process and each first safety evaluation index comprises:

[0021] According to the relative importance degree of each first safety evaluation index obtained, a comparison matrix corresponding to each first safety evaluation index is determined;

[0022] According to the comparison matrix, the importance degree corresponding to each first safety evaluation index itself is determined;

[0023] According to the importance degree corresponding to each first security evaluation index and the preset optimal transfer matrix, a first weight parameter corresponding to each first security evaluation index is determined.

[0024] In one of the embodiments, the determining of the security evaluation result corresponding to the industrial control system according to each security evaluation parameter comprises:

[0025] According to the first weight parameter corresponding to each first security evaluation index, each security evaluation parameter is weighted and summed to determine the security evaluation result.

[0026] In one of the embodiments, the security evaluation result comprises a security evaluation value, and the method further comprises:

[0027] The security evaluation value is matched with a plurality of preset security evaluation ranges to determine a target security level corresponding to the security evaluation value.

[0028] Each security evaluation range corresponds to a different security level.

[0029] In a second aspect, the present application further provides a system security evaluation device, which comprises:

[0030] The acquisition module is configured to acquire first security evaluation indexes corresponding to each level in the industrial control system; the industrial control system at least comprises a cloud platform layer, an edge control platform layer and a terminal device layer;

[0031] The first determination module is configured to determine security evaluation parameters corresponding to each first security evaluation index according to each first security evaluation index and an index evaluation model corresponding to each first security evaluation index; each index evaluation model is configured to perform security evaluation parameter calculation on the corresponding first security evaluation index.

[0032] The second determination module is configured to determine a security evaluation result corresponding to the industrial control system according to each security evaluation parameter.

[0033] In a third aspect, the present application further provides a computer device, which comprises a memory and a processor; the memory stores a computer program; and the processor realizes the following steps when executing the computer program:

[0034] The acquisition module is configured to acquire first security evaluation indexes corresponding to each level in the industrial control system; the industrial control system at least comprises a cloud platform layer, an edge control platform layer and a terminal device layer;

[0035] The first determination module is configured to determine security evaluation parameters corresponding to each first security evaluation index according to each first security evaluation index and an index evaluation model corresponding to each first security evaluation index; each index evaluation model is configured to perform security evaluation parameter calculation on the corresponding first security evaluation index.

[0036] According to each security evaluation parameter, a security evaluation result corresponding to the industrial control system is determined.

[0037] In a fourth aspect, the present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the following steps:

[0038] Obtaining first security evaluation indexes corresponding to each level in the industrial control system; the industrial control system at least includes a cloud platform layer, an edge control platform layer and a terminal device layer;

[0039] According to each first security evaluation index and an index evaluation model corresponding to each first security evaluation index, a security evaluation parameter corresponding to each first security evaluation index is determined; each index evaluation model is used for security evaluation parameter calculation on the corresponding first security evaluation index;

[0040] According to each security evaluation parameter, a security evaluation result corresponding to the industrial control system is determined.

[0041] In a fifth aspect, the present application also provides a computer program product, which includes a computer program, and the computer program is executed by a processor to implement the following steps:

[0042] Obtaining first security evaluation indexes corresponding to each level in the industrial control system; the industrial control system at least includes a cloud platform layer, an edge control platform layer and a terminal device layer;

[0043] According to each first security evaluation index and an index evaluation model corresponding to each first security evaluation index, a security evaluation parameter corresponding to each first security evaluation index is determined; each index evaluation model is used for security evaluation parameter calculation on the corresponding first security evaluation index;

[0044] According to each security evaluation parameter, a security evaluation result corresponding to the industrial control system is determined.

[0045] The system security evaluation method, device, equipment, storage medium and program product can obtain the first security evaluation indexes corresponding to each level in the industrial control system, then determine the security evaluation parameters corresponding to each first security evaluation index according to the first security evaluation indexes and the index evaluation models corresponding to the first security evaluation indexes, and finally determine the security evaluation result corresponding to the industrial control system according to the security evaluation parameters. The industrial control system at least includes an industrial cloud platform layer, an edge control platform layer and a terminal device layer. In the method, the security of the industrial control system is evaluated in real time by obtaining the first security evaluation indexes corresponding to each level in the industrial control system, determining the security evaluation parameters corresponding to each first security evaluation index according to the first security evaluation indexes and the index evaluation models corresponding to the first security evaluation indexes, and finally determining the security evaluation result corresponding to the industrial control system according to the security evaluation parameters, so as to provide an intuitive understanding of the security level of the system, help to correctly deploy prevention and control measures, reduce the risk of adverse accidents caused by network attacks of the industrial control system, and enhance the safe and stable operation level of the system. In addition, the security evaluation result corresponding to the industrial control system is determined by using the security evaluation parameters corresponding to the first security evaluation indexes, the security risk of the industrial system is evaluated, so as to effectively handle the uncertainty problem in the security risk evaluation process, and thus improve the accuracy of the evaluation. BRIEF DESCRIPTION OF DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only embodiments of the present application, and other drawings can be obtained by the disclosed drawings without creative labor for those skilled in the art.

[0047] FIG. 1 is an internal structure diagram of a computer device in an embodiment;

[0048] FIG. 2 is a flow diagram of a system security evaluation method in an embodiment;

[0049] FIG. 3 is a traditional industrial control system topology architecture in an embodiment;

[0050] FIG. 4 is a connection relationship diagram of a management network MNet in an embodiment;

[0051] FIG. 5 is a connection relationship diagram of a system network SNet in an embodiment;

[0052] FIG. 6 is a connection relationship diagram of a control network CNet in an embodiment;

[0053] FIG. 7 is a cloud-edge collaborative industrial control system topology architecture in one embodiment;

[0054] FIG. 8 is a first security assessment indicator and a second security assessment indicator of an industrial control system in another embodiment;

[0055] FIG. 9 is a flowchart of a system security assessment method in another embodiment;

[0056] FIG. 10 is a second security assessment indicator of an industrial control system in another embodiment;

[0057] FIG. 11 is a flowchart of a system security assessment method in another embodiment;

[0058] FIG. 12 is a system inherent safety capability evaluation level diagram in another embodiment;

[0059] FIG. 13 is a flowchart of a system security assessment method in another embodiment;

[0060] FIG. 14 is a structural block diagram of a system security assessment device in one embodiment. DETAILED DESCRIPTION

[0061] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.

[0062] It has become an important real problem in the current global network security field that network attacks cause significant physical damage to industrial control systems. From the perspective of the internal industrial control system, modern industrial control systems are gradually shifting from closed and dedicated control communication protocols to general-purpose Internet protocols, from dedicated hardware and operating systems to general-purpose hardware and general-purpose operating systems, and increasingly interconnected with other information systems, resulting in an increasing attack surface. From the perspective of external threats to industrial control systems, the intention and technology of attacks on industrial control systems, the ability and intensity of vulnerability analysis, and the organization and ability of network attack personnel are constantly increasing. From the perspective of threats, in 2010, the network attack in the Stuxnet incident caused physical damage to thousands of uranium enrichment centrifuges in Iran, becoming a landmark event in the opening of cyber warfare. The problem of physical damage to industrial control systems by network attacks has become an important problem that endangers national security.

[0063] Under the background of accelerating the development of digital economy and promoting the integration of digital revolution, new demands have emerged in the field of industrial control, including unified management of large-scale data acquisition, storage and monitoring systems, heterogeneous data expansion and unified management of control objects, super-computing and storage resource requirements, and multi-device collaboration requirements brought by fine-grained management. Traditional industrial network architecture has many problems in terms of massive data acquisition, processing, device interconnection, and computing resource diversification, and cannot meet the urgent needs of networked control collaboration, business collaboration, and remote system management. To solve the above problems, the industrial field uses new-generation information technology-based distributed computing, virtualization, and interactive service technology to create cloud-edge collaborative industrial control systems.

[0064] With the gradual evolution of industrial control systems to cloud-edge collaborative open architecture, the physical isolation security boundary on which the industrial control system relies has collapsed. Once a network attack-based functional safety event occurs, it will cause power outages, water outages, traffic chaos, production paralysis, and other major accidents that affect social safety. The time of network attack initiation, attack target, and attack method are uncertain and unpredictable, which greatly affects the security of cloud-edge collaborative industrial control system operation. In order to protect the complex industrial control system, it is necessary to study the security evaluation method of cloud-edge collaborative industrial control system under network attack, accurately identify and reasonably quantify the security factors of industrial control system, and it is particularly important to take preventive, remedial, and mitigation measures in a timely and accurate manner before and after the attack. Security evaluation assesses the security of the industrial control system in real time in a quantitative or qualitative manner, provides an intuitive understanding of the security level of the system, helps to correctly deploy prevention and control measures, reduces the risk of adverse accidents caused by network attacks in industrial control systems, and enhances the security and stability of the system.

[0065] Currently, the security evaluation method of industrial control system mainly evaluates the security of industrial control system at the information level, but there is less research on the role of attacks at the physical function level. The information and physics of industrial control systems are closely coupled and cannot be evaluated from a single information or physical layer. The overall security of the industrial control system should be evaluated. Therefore, the above-mentioned technologies have the problem of low accuracy of the evaluation results when evaluating the security of cloud-edge collaborative industrial control systems. Based on this, the present application provides a system security evaluation method, device, equipment, storage medium and program product, which can solve the above technical problems.

[0066] The system security evaluation method provided by the embodiments of the present application can be applied to a computer device, which can be a terminal or a server. Taking the server as an example, its internal structure diagram can be as shown in FIG. 1. The computer device includes a processor, a memory and a network interface connected through a system bus. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store data in a system security evaluation process. The network interface of the computer device is configured to communicate with an external terminal through a network connection. The computer program is executed by the processor to implement a system security evaluation method.

[0067] Those skilled in the art can understand that the structure shown in FIG. 1 is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. A specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.

[0068] In one embodiment, as shown in FIG. 2, a system security evaluation method is provided. Taking the computer device in FIG. 1 as an example, the method includes the following steps:

[0069] In S202, first security evaluation indexes corresponding to each level in the industrial control system are obtained. The industrial control system at least includes an industrial cloud platform layer, an edge control platform layer and a terminal device layer.

[0070] The industrial control system mainly refers to a cloud-edge collaborative industrial control system. A topology architecture of the cloud-edge collaborative industrial control system is evolved from a topology architecture of a traditional industrial control system. Specifically, as shown in FIG. 3, the topology architecture of the traditional industrial control system includes, from top to bottom, a management layer, an engineer station (or operator station) layer, and a field control layer (the field control layer includes a programmable logic controller (PLC) and a distributed control system (DCS)). The management layer and the engineer station (or operator station) layer are connected through an industrial switch, and the management layer, the engineer station (or operator station) layer, and the field control layer are connected through an industrial switch. The management layer and the engineer station layer are connected through a management network, the engineer station layer and the field control layer are connected through a system network, and the field control layer can be connected through a control network. As shown in FIG. 4, the management network (MNet) can realize data communication, coordinated control, and scheduling management among an engineer station, a data server, a production process (including quality management, production planning, and sales business), and a production workshop. As shown in FIG. 5, the system network (SNet) can realize data transmission among a field control station, an operator station, an engineer station, and each other, and maintain data consistency. As shown in FIG. 6, the control network (CNet) can realize interconnection and information transmission between I / O modules and control modules in the control station.

[0071] As shown in FIG. 7, the topology architecture of the cloud-edge collaborative industrial control system includes, from top to bottom, an industrial cloud platform layer, an edge control platform layer, and a terminal device layer. The evolution process of the topology architecture of the industrial control system from the topology architecture of the traditional industrial control system to the cloud-edge collaborative architecture is as follows: the management layer of the traditional industrial control system can be evolved into the industrial cloud platform layer. The cloud end of the cloud platform has strong computing power, and the cloud platform can complete functions such as design, optimization scheduling, virtual production, and virtual testing. The functions of the cloud platform mainly include service management, production management, intelligent application, and data management. The engineer station (or operator station) layer of the traditional industrial control system is evolved into the edge control platform layer. The main functions of the edge control platform layer include production management (quality, process, etc.), intelligent application (fault diagnosis, predictive maintenance, edge simulation process production, etc.), data management (data acquisition, preprocessing, storage, analysis), and perception control (protocol conversion, device interconnection, intelligent monitoring, and precise control). The field control layer of the traditional industrial control system is evolved into the terminal device layer. The terminal device layer mainly performs field control and data acquisition.

[0072] In some embodiments, the first security indicators can be system availability, system trustworthiness, and system inherent safety capability. The system availability refers to the ability of the industrial control system to perform a specified function or recover from a failure under specified conditions and at specified time or time interval, with the required external resources guaranteed. The system availability mainly focuses on the impact of the failure on the industrial control system. The system trustworthiness refers to the ability of the industrial control system to complete a specified function under specified conditions and at specified time. The system trustworthiness aims to maintain the normal execution of the function of the industrial control system. The system inherent safety capability refers to the characteristics of the industrial control system to eliminate unacceptable risk impact. The system inherent safety capability aims to prevent human casualties and property losses.

[0073] In this step, the server can obtain the first security indicators corresponding to the industrial control system, which at least includes an industrial cloud platform layer, an edge control platform layer, and a terminal device layer.

[0074] S204, according to each first security evaluation indicator and the index evaluation model corresponding to each first security evaluation indicator, determine the security evaluation parameter corresponding to each first security evaluation indicator; each index evaluation model is used for security evaluation parameter calculation on the corresponding first security evaluation indicator.

[0075] In this step, after obtaining the first security evaluation indicators corresponding to each level of the industrial control system, the server determines the security evaluation parameter corresponding to each first security evaluation indicator according to each first security evaluation indicator and the index evaluation model corresponding to each first security evaluation indicator. The index evaluation model corresponding to the first security evaluation indicator mainly refers to the model for processing and calculating the security evaluation parameter of the first security evaluation indicator of the industrial control system. The first security indicator of the industrial control system is shown in FIG. 8. Since the first evaluation indicator mainly includes system availability, system trustworthiness, and system inherent safety capability, the index evaluation model corresponding to different first evaluation indicators is also different. Specifically, the index evaluation model corresponding to the system availability is the system availability evaluation model, the index evaluation model corresponding to the system trustworthiness is the system trustworthiness evaluation model, and the index evaluation model corresponding to the system inherent safety capability is the system inherent safety capability evaluation model. In addition, since the index evaluation model mainly includes the system availability evaluation model, the system trustworthiness evaluation model, and the system inherent safety capability evaluation model, the security evaluation parameter corresponding to different index evaluation models is also different. Specifically, the security evaluation parameter corresponding to the system availability evaluation model can be the system availability evaluation parameter, the security evaluation parameter corresponding to the system trustworthiness evaluation model can be the system trustworthiness evaluation parameter, and the security evaluation parameter corresponding to the system inherent safety capability evaluation model can be the system inherent safety capability evaluation parameter.

[0076] S206, determine the security evaluation result corresponding to the industrial control system according to the security evaluation parameters.

[0077] In this step, after determining the security evaluation parameters corresponding to the first security evaluation indicators, the server determines the security evaluation result corresponding to the industrial control system according to the obtained security evaluation parameters. The security evaluation result is a result of evaluating the security of the industrial control system. The result can be a numerical value or a numerical range. Through the numerical value or numerical range, the security of the industrial control system can be reflected.

[0078] In the above system security evaluation method, the first security evaluation indicators corresponding to each level in the industrial control system are obtained. Then, the security evaluation parameters corresponding to each first security evaluation indicator can be determined according to each first security evaluation indicator and the index evaluation model corresponding to each first security evaluation indicator. Finally, the security evaluation result corresponding to the industrial control system is determined according to each security evaluation parameter. Each index evaluation model is used to calculate the security evaluation parameters of the corresponding first security evaluation indicator. The industrial control system at least includes an industrial cloud platform layer, an edge control platform layer and a terminal device layer. In this method, by obtaining the first security evaluation indicators corresponding to each level in the industrial control system, and then determining the security evaluation parameters corresponding to each first security evaluation indicator according to each first security evaluation indicator and the index evaluation model corresponding to each first security evaluation indicator, and finally determining the security evaluation result corresponding to the industrial control system according to each security evaluation parameter, the security of the industrial control system can be evaluated in real time. This provides a direct understanding of the security level of the system, which helps to correctly deploy prevention and control measures, reduces the risk of adverse accidents caused by network attacks on the industrial control system, and enhances the security and stability of the system. In addition, the security evaluation result corresponding to the industrial control system is determined by using the security evaluation parameters corresponding to the first security evaluation indicators. The security risk of the industrial system can be evaluated, thereby effectively dealing with the uncertainty problem in the security risk evaluation process, and improving the accuracy of the evaluation.

[0079] In the above embodiment, it is mentioned that the server can obtain the first security evaluation indicators corresponding to each level in the industrial control system. The following embodiment will describe in detail the specific process of the server obtaining the second security evaluation indicators corresponding to each first security evaluation indicator before obtaining the first security evaluation indicators corresponding to each level in the industrial control system, and determining the first weight parameters corresponding to the first security evaluation indicators and the second weight parameters corresponding to each second security evaluation indicator of the same level according to the predetermined analytic hierarchy process.

[0080] In another embodiment, another system security evaluation method is provided, which, based on the above-mentioned embodiment, as shown in FIG. 9, can further include the following steps before S204:

[0081] S302, obtaining each second security evaluation index of each first security evaluation index; each second security evaluation index of each first security evaluation index is an index of the same level and / or different levels.

[0082] Continuing to refer to FIG. 8, wherein the second security evaluation index includes the mean time between failures and the mean time to repair corresponding to the system availability, can also be the device credibility, the operating system credibility, the software credibility and the data credibility corresponding to the system credibility, and can also be the security of the industrial cloud platform layer, the security of the edge control platform layer and the security of the terminal device layer corresponding to the system inherent security capability. Among them, the mean time between failures and the mean time to repair are used to evaluate the system availability. The device credibility, the operating system credibility, the software credibility and the data credibility are used to evaluate the system credibility. The security of the industrial cloud platform layer, the security of the edge control platform layer and the security of the terminal device layer are used to evaluate the system inherent security capability.

[0083] Alternatively, as shown in FIG. 10, the second security evaluation index can also be the injection attack, the distributed denial of service (DDOS) attack, the vulnerability / backdoor attack and the password attack corresponding to the security of the industrial cloud platform layer, can also be the security of the historical / real-time database, the security of the resource management system and the security of the industrial gateway corresponding to the security of the edge control platform layer, and can also be the interference attack, the configuration attack and the firmware attack corresponding to the security of the terminal device layer. Among them, the injection attack, the distributed denial of service (DDOS) attack, the vulnerability / backdoor attack and the password attack are used to evaluate the security of the industrial cloud platform layer. The security of the historical / real-time database, the security of the resource management system and the security of the industrial gateway are used to evaluate the security of the edge control platform layer. The interference attack, the configuration attack and the firmware attack are used to evaluate the security of the terminal device layer.

[0084] In this step, the server can obtain each second security evaluation index of each first security evaluation index of each lower level. And each second security evaluation index of each first security evaluation index is an index of the same level and / or different levels.

[0085] S304, determining a first weight parameter corresponding to each first security evaluation index according to a preset analytic hierarchy process and each first security evaluation index.

[0086] Among them, the preset analytic hierarchy process is an improved analytic hierarchy process of optimal transfer matrix, and the weight parameters of each index can be directly obtained by the improved analytic hierarchy process of optimal transfer matrix.

[0087] In this step, the server can determine the first weight parameter corresponding to each first security evaluation index according to the preset analytic hierarchy process and each first security evaluation index. The preset analytic hierarchy process can calculate the first weight parameter corresponding to the first security evaluation index. The first weight parameter corresponding to the first security evaluation index refers to the relative importance of the first security evaluation index, i.e., system availability, system trustworthiness, and system inherent safety capability, in the overall evaluation of the security of the industrial control system. For example, the first weight parameter corresponding to the first security evaluation index can be ω1, ω2, ω3, which represent the first weight parameters of the system availability, system trustworthiness, and system inherent safety capability indexes, respectively.

[0088] S306, according to the analytic hierarchy process and each second security evaluation index of the same level, determine the second weight parameter corresponding to each second security evaluation index of the same level.

[0089] In this step, the server determines the second weight parameter corresponding to each second security evaluation index of the same level according to the analytic hierarchy process and each second security evaluation index of the same level. The analytic hierarchy process can calculate the second weight parameter corresponding to each second security evaluation index. The second weight parameter corresponding to each second security evaluation index refers to the relative importance of each second security evaluation index of the same level in the evaluation of the first security evaluation index. Taking the first security index of system trustworthiness as an example, the second weight parameter is the relative importance of the device trustworthiness, operating system trustworthiness, software trustworthiness, and data trustworthiness in evaluating the system trustworthiness. For example, the second weight parameter corresponding to the second security evaluation index can be ω 21 ,ω 22 ,ω 23 ,ω 24 ,ω 21 ,ω 22 ,ω 23 ,ω 24 , which represent the second weight parameters of the system trustworthiness sub-indexes of device trustworthiness, system trustworthiness, software trustworthiness, and data trustworthiness, respectively. The second weight parameter corresponding to the second security evaluation index can also be ω 31 ,ω 32 ,ω 33 ,ω 31 ,ω 32 ,ω 33 , which represent the second weight parameters of the system inherent safety capability sub-indexes of the security of the industrial cloud platform layer, the security of the edge control platform layer, and the security of the terminal device layer, respectively. The second weight parameter corresponding to the second security evaluation index can also be ω 311 ,ω 312 ,ω313 314 311 312 313 314 The second weight parameters corresponding to the second security evaluation indexes of the security of the cloud platform layer are ω 321 322 323 321 322 323 The second weight parameters corresponding to the second security evaluation indexes of the security of the edge control platform layer are ω 331 332 333 331 332 333 The second weight parameters corresponding to the second security evaluation indexes of the security of the terminal device layer are ω

[0090] In the embodiment, the second security evaluation indexes corresponding to each first security evaluation index are obtained, wherein the second security evaluation indexes of each first security evaluation index are indexes of the same level and / or different levels, then the first weight parameters corresponding to each first security evaluation index can be determined according to the preset AHP and each first security evaluation index, and the second weight parameters corresponding to the second security evaluation indexes of the same level can be determined according to the AHP and the second security evaluation indexes of the same level. In the method, the analysis of the first security evaluation index is more comprehensive by obtaining the second security evaluation indexes corresponding to each first security evaluation index, so that the evaluation of the security of the industrial system is more accurate. In addition, the first weight parameters corresponding to each first security evaluation index and the second weight parameters corresponding to the second security evaluation indexes of the same level are determined by the preset AHP, so that the weight parameters corresponding to the indexes of each level can be calculated, the relative importance of each index can be determined, a data basis for determining the security evaluation result corresponding to the industrial control system is provided, and the weight of each index can be directly obtained by using the AHP, so that the consistency check problem caused by the consistency check can be avoided, and the evaluation efficiency is improved.

[0091] ​​​​​​​​​​​​​​​The above embodiment mentioned that the security evaluation parameter corresponding to each first security evaluation index can be determined according to each first security evaluation index and the index evaluation model corresponding to each first security evaluation index. The following embodiment will describe in detail the specific process of determining the security evaluation parameter corresponding to each first security evaluation index according to each first security evaluation index and the index evaluation model corresponding to each first security evaluation index.

[0092] In another embodiment, another system security evaluation method is provided. Based on the above embodiment, as shown in FIG. 11, the S204 can include the following steps:

[0093] S402, input each second security evaluation index into the index evaluation model corresponding to each first security evaluation index respectively, and determine the sub-evaluation parameter corresponding to each second security evaluation index.

[0094] In this step, the server can input each second security evaluation index into the corresponding index evaluation model respectively, so as to determine the sub-evaluation parameter corresponding to each second security evaluation index. The sub-evaluation parameter corresponding to the second security evaluation index is the evaluation value calculated by the second security evaluation index. For example, when the index evaluation model is a system availability evaluation model, the second evaluation index is the mean time between failures and the mean time to repair, and the sub-evaluation parameter corresponding to the second security evaluation index can be the availability evaluation value of the system. For another example, when the index evaluation model is a system trustworthiness evaluation model, the second evaluation index is the device trustworthiness, the operating system trustworthiness, the software trustworthiness and the data trustworthiness, and the sub-evaluation parameter corresponding to the second security evaluation index can be the trustworthiness evaluation value of the system. For another example, when the index evaluation model is a system inherent security capability evaluation model, the second evaluation index is the security of the industrial cloud platform layer, the security of the edge control platform layer and the security of the terminal device layer, and the sub-evaluation parameter corresponding to the second security evaluation index can be the inherent security capability evaluation value of the system.

[0095] S404, input each second weight parameter into the corresponding index evaluation model respectively, and perform mathematical operation processing on each sub-evaluation parameter and the corresponding second weight parameter to determine the security evaluation parameter corresponding to each first security evaluation index.

[0096] In this step, after the server inputs each second security evaluation index into the corresponding index evaluation model respectively and determines the sub-evaluation parameter corresponding to each second security evaluation index, the server inputs each second weight parameter into the corresponding index evaluation model respectively, so as to perform mathematical operation processing on each sub-evaluation parameter and the corresponding second weight parameter, and finally determine the security evaluation parameter corresponding to each first security evaluation index. Specifically, taking the index evaluation model as the system availability evaluation model as an example,

[0097] First, the probability R of all states that the system can be in can be listed, and the set of all possible states can be represented as: R = [r1, r2,..., rn] n ]

[0098] In the formula, r i is the probability of the system being in the i-th state, with a value range of [0, 1]; n is the number of states that the system can be in, and the n possible states constitute the sample space, so we know that:

[0099] Here, only the working states of the system are considered to be normal working and failure, and let MTBF be the average failure interval time of the system, and MTTR be the average failure repair time of the system, then the availability r1 of the system and the unavailability r2 of the system can be represented as: r2 = (1 - r1)

[0100] Then the safety evaluation parameter corresponding to the system availability can be represented as:

[0101] Next, the evidence reasoning method based on fuzzy synthesis can be used to evaluate the system credibility of the industrial control system. Specifically, there are four indicators to be evaluated for the credibility of the industrial control system, namely, device credibility, system credibility, software credibility, and data credibility, so that

[0102] The index set of the system credibility to be evaluated can be represented as: u = {u1, u2, u3, u3}

[0103] The expert set can be represented as: DM L (L = 1, 2,..., r)

[0104] The relative weight of the expert can be set as: w = {w1, w2,..., w r}

[0105] The fuzzy evaluation level of the index can be: H = {H k |k = 1, 2, 3, 4, 5, 6, 7, 8, 9}

[0106] The fuzzy evaluation level of the index represents, in turn, the evaluation of the extreme, very poor, poor, slightly poor, general, slightly high, high, very high, and extremely high, and here we can take: P(H) = {P(H1), P(H2), P(H3), P(H4), P(H5), P(H6), P(H7), P(H8), P(H9)} = {0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9}

[0107] For each indicator, a confidence level at rating level H is given. The expression for this confidence level can be:

[0108] The degree of uncertainty in the evaluation of each indicator is: H Θ (U ik )

[0109] Where Θ represents the identification framework; based on the confidence levels of the indicators provided by experts, a basic confidence allocation function for the indicators is established, namely the Mass function, where the indicator with the largest weight is the key indicator u. ia The others are non-critical indicators. The Mass function for critical indicators is: m L (H k |u ia ) = TU ik

[0110] Non-key indicator u if The Mass function is: m L (H k |u if )=(w if / w ia )TU ik

[0111] Among them, w if For non-critical metric weights, w ia , where T is the weight of the key indicator and T is the discount factor.

[0112] The composition rule in evidence reasoning theory: m(O) = 0

[0113] In the formula, k is the evidence conflict factor, and m(A) reflects m1, m2, ..., m r The degree of joint support for proposition A from the corresponding r basic pieces of evidence.

[0114] Evidence is synthesized according to the above synthesis rules to obtain the Mass function for the higher-level indicator, m(H). k |u), calculate the deterministic evaluation value S of the second safety assessment index u, which is the sub-assessment parameter corresponding to the second safety assessment index:

[0115] Based on the second weight parameters and sub-evaluation parameters of each second security indicator, the security evaluation parameters for system reliability can be obtained as follows:

[0116] Taking the index evaluation model as an example, the evaluation parameters of the inherent safety capability of the cloud-edge collaborative industrial control system are calculated by using the fuzzy comprehensive evidence reasoning method. Without loss of generality, taking the security of the industrial cloud platform layer as an example, the next level index includes four types of attacks: injection attack, DDoS attack, vulnerability / backdoor attack, and password attack. The security evaluation of the injection attack (including attack frequency and damage degree) can be performed by the following steps: setting the injection attack evaluation index set as The expert set is represented as DM L (L = 1, 2,..., r), and the relative weight of the expert is set as w = {w1, w2,..., w r}, and the fuzzy evaluation level of the index is H = {H k | k = 1, 2, 3, 4, 5}, and the evaluation level of the system inherent safety capability is shown in FIG. 12. The evaluation value can be [0, 0.2), [0.2, 0.4), [0.4, 0.6), [0.6, 0.8), [0.8, 1), and here P(H) = {P(H1), P(H2), P(H3), P(H4), P(H5)} = {0.1, 0.3, 0.5, 0.7, 0.9}

[0117] The subsequent calculation process refers to the system credibility evaluation process. The fuzzy comprehensive evidence reasoning method is used to calculate the sub-evaluation parameters of the indexes: injection attack, DDoS attack, vulnerability / backdoor attack, password attack, historical / real-time database, asset management system, industrial gateway, interference attack, configuration attack, and firmware attack, which are represented as e 311 ,e 312 ,e 313 ,e 314 、e 321 ,e 322 ,e 323 、e 331 ,e 332 ,e 333 ; and the sub-evaluation parameters corresponding to the security of the industrial cloud platform layer are The sub-evaluation parameters corresponding to the security of the edge control platform layer are The sub-evaluation parameters corresponding to the terminal device layer are

[0118] According to the second weight parameters and the sub-evaluation parameters of the second security indexes, the security evaluation parameter of the system inherent safety capability can be calculated as: T G = ω 31 σ1+ ω 32 σ2+ ω 33 σ3;

[0119] wherein ω 31 , ω32 ωi,ω 33 ωi,ω

[0120] In the embodiment, each second security evaluation index is input into the corresponding index evaluation model to determine the corresponding sub-evaluation parameter of each second security evaluation index, and then each second weight parameter is input into the corresponding index evaluation model, and the index evaluation model performs mathematical operation processing on each sub-evaluation parameter and the corresponding second weight parameter, so as to determine the security evaluation parameter corresponding to each first security evaluation index. In the method, the security evaluation parameter corresponding to each first security evaluation index is determined by performing mathematical operation processing on each sub-evaluation parameter and the corresponding second weight parameter, so that the security evaluation result corresponding to each industrial system can be determined according to each security evaluation parameter, and the security risk of the industrial system can be evaluated, the uncertainty problem in the security risk evaluation process can be effectively handled, and the accuracy of the evaluation is improved.

[0121] The above embodiment mentions that the first weight parameter corresponding to each first security evaluation index can be determined according to the preset analytic hierarchy process and each first security evaluation index, and the following embodiment will be described in detail.

[0122] In another embodiment, another system security evaluation method is provided, which is based on the above-mentioned embodiment, as shown in FIG. 13, the above-mentioned S304 can include the following steps:

[0123] S502, determining the comparison matrix corresponding to each first security evaluation index according to the relative importance of each first security evaluation index.

[0124] S504, determining the importance of each first security evaluation index itself according to the comparison matrix.

[0125] S506, determining the first weight parameter corresponding to each first security evaluation index according to the importance of each first security evaluation index itself and the preset optimal transfer matrix.

[0126] In the above steps, the server can determine the comparison matrix corresponding to each first security evaluation index according to the relative importance of each first security evaluation index, then determine the importance of each first security evaluation index itself according to the comparison matrix corresponding to each first security evaluation index, and finally determine the first weight parameter corresponding to each first security evaluation index according to the importance of each first security evaluation index itself and the preset optimal transfer matrix. Specifically, the index weight obtained by the analytic hierarchy process improved by the optimal transfer matrix can include the following steps:

[0127] (1) Still referring to FIG. 8, according to the established first security evaluation index and second security evaluation index system of the industrial control system, a judgment matrix A=(a ij ) n×n , wherein,

[0128] wherein, i and j both represent the first security evaluation index or the second security evaluation index, and n represents n first security evaluation indexes or n second security evaluation indexes.

[0129] (2) According to the comparison matrix A, define φ i as the importance of the i-th index, and use to calculate the importance of the first security evaluation index, and set φ max , φ min represent the maximum value and the minimum value of the importance, i.e. φ max = max{φ i}, φ min = min{φi}, on this basis, a new importance judgment matrix B=(b ij n×n

[0130] wherein, φ i is the importance of the i-th index, φ j is the importance of the j-th index, φ max represents the maximum value of the importance, and φ min represents the minimum value of the importance.

[0131] (3) According to the importance judgment matrix B=(b ij ) n×n design an optimal transfer matrix C=(c ij ) n×n , wherein

[0132] wherein, b il represents the i-th row and the l-th column element of the importance judgment matrix B, and b jl ​denotes the element in the jth row and the lth column of the importance judgment matrix B, and n denotes that there are n first security evaluation indexes.

[0133] The corresponding first weight parameter ω of the ith first security index i The first weight parameter ω of the ith first security index can be calculated by the following formula:

[0134] wherein n denotes that there are n first security evaluation indexes, and ω i denotes the corresponding first weight parameter of the first security evaluation index.

[0135] Thus, the corresponding first weight parameter ω of the first security index can be obtained, and ω1, ω2, and ω3 represent the first weight parameters of the system usability, the system trustworthiness, and the system inherent safety capability index, respectively.

[0136] It should be noted that when calculating the second weight parameter, the server can determine the comparison matrix corresponding to each second security evaluation index according to the relative importance of each second security evaluation index, then determine the importance corresponding to each second security evaluation index itself according to the comparison matrix corresponding to each second security evaluation index, and finally determine the second weight parameter corresponding to each second security evaluation index according to the importance corresponding to each second security evaluation index itself and the preset optimal transfer matrix. The specific calculation process is the same as that of the first weight parameter determination, which will not be described here.

[0137] In this embodiment, the comparison matrix corresponding to each first security evaluation index is first determined according to the relative importance of each first security evaluation index, then the importance corresponding to each first security evaluation index itself is determined according to the comparison matrix, and finally the first weight parameter corresponding to each first security evaluation index is determined according to the importance corresponding to each first security evaluation index itself and the preset optimal transfer matrix. In this method, the weight of each index can be obtained through the optimal transfer matrix, thereby avoiding the consistency checking problem caused by consistency checking, and further improving the evaluation efficiency.

[0138] The above embodiment mentions that the safety evaluation result corresponding to the industrial control system can be determined according to each security evaluation parameter, and the following embodiment will describe the specific process of determining the safety evaluation result corresponding to the industrial control system according to each security evaluation parameter.

[0139] In another embodiment, another system security evaluation method is provided, and on the basis of the above-mentioned embodiment, the above-mentioned S206 can include the following steps:

[0140] Step A, performing weighted sum processing on each security evaluation parameter according to the first weight parameter corresponding to each first security evaluation index, to determine the safety evaluation result.

[0141] In this step, the server can weight and sum each security evaluation parameter calculated in the above embodiment according to the first weight parameter corresponding to each first security evaluation indicator, so as to determine the security evaluation result. The calculation formula of the security evaluation result can be expressed as: E = T a ω1+T s ω2+T G ω3

[0142] Wherein, E represents the security evaluation result, ω1, ω2, ω3 represent the first weight parameters of the system availability, the system trustworthiness and the system inherent security capability indicator in turn, T a ,T s ,T G represent the security evaluation parameters corresponding to the system availability, the security evaluation parameters of the system trustworthiness and the security evaluation parameters of the system inherent security capability in turn.

[0143] In this embodiment, the security evaluation result of the industrial control system can be determined by weighting and summing each security evaluation parameter through the first weight parameter corresponding to each first security evaluation indicator. The security of the industrial control system can be evaluated in real time through the security evaluation result, which provides an intuitive understanding of the security level of the system, helps to correctly deploy prevention and control measures, reduces the risk of adverse accidents caused by network attacks of the industrial control system, and can enhance the safe and stable operation level of the system.

[0144] In another embodiment, another system security evaluation method is provided. On the basis of the above embodiment, the method can further include the following steps:

[0145] Step B, matching the security evaluation value with a plurality of preset security evaluation ranges to determine the target security level corresponding to the security evaluation value. Each security evaluation range corresponds to a different security level.

[0146] The safety evaluation value ranges from 0 to 1, and the closer to 0, the lower the safety level of the industrial system, and the closer to 1, the higher the safety level of the industrial system. The preset multiple safety evaluation ranges refer to the range of safety evaluation values obtained in advance by the staff. The range of the safety evaluation value can be [0, 1), and the range of the safety evaluation value can be, for example, [0, 0.2), [0.2, 0.4), [0.4, 0.6), [0.6, 0.8), [0.8, 1). The target safety level corresponding to [0, 0.2) can be safety level extremely low, the target safety level corresponding to [0.2, 0.4) can be safety level low, the target safety level corresponding to [0.4, 0.6) can be safety level slightly high, the target safety level corresponding to [0.6, 0.8) can be safety level high, and the target safety level corresponding to [0.8, 1) can be safety level very high.

[0147] In this step, the server can match the safety evaluation value with the preset multiple safety evaluation ranges, so as to determine the target safety level corresponding to the safety evaluation value. Each safety evaluation range corresponds to a different safety level. For example, when the calculated safety evaluation value is 0.1, it indicates that the target safety level of the industrial system is extremely low.

[0148] In this step, by matching the safety evaluation value with the preset multiple safety evaluation ranges, the target safety level corresponding to the safety evaluation value can be determined, so as to evaluate the safety of the industrial control system in real time, provide an intuitive understanding of the safety level of the system, help to correctly deploy prevention and control measures, reduce the risk of adverse accidents caused by network attacks of the industrial control system, and enhance the safety and stability of the system.

[0149] The following gives a detailed embodiment to explain the process of the system safety evaluation method in the application. Based on the above embodiment, the implementation process of the method can include the following contents:

[0150] S1, obtaining a first safety evaluation index corresponding to an industrial control system; the industrial control system at least includes an industrial cloud platform layer, an edge control platform layer and a terminal device layer;

[0151] S2, obtaining each second safety evaluation index corresponding to each first safety evaluation index of the lower level; each second safety evaluation index of each first safety evaluation index is an index of the same level and / or different level;

[0152] S3, determining a comparison matrix corresponding to each first safety evaluation index according to the relative importance of each first safety evaluation index;

[0153] S4, determining the importance degree of each first safety evaluation index according to the comparison matrix;

[0154] S5, determining the first weight parameter corresponding to each first safety evaluation index according to the importance degree of each first safety evaluation index and the preset optimal transfer matrix; wherein, the first safety evaluation index includes system availability, system credibility and system inherent safety capability; the index evaluation model corresponding to the first safety evaluation index includes system availability evaluation model, system credibility evaluation model and system inherent safety capability evaluation model;

[0155] S6, determining the second weight parameter corresponding to each second safety evaluation index at the same level according to the analytic hierarchy process and each second safety evaluation index at the same level;

[0156] S7, the index evaluation model is used for safety evaluation parameter calculation of the corresponding second safety evaluation index, each second safety evaluation index is input into the corresponding index evaluation model, and the sub-evaluation parameter corresponding to each second safety evaluation index is determined;

[0157] S8, the index evaluation model is also used for safety evaluation parameter calculation of the corresponding first safety evaluation index, each second weight parameter is input into the corresponding index evaluation model, and the safety evaluation parameter corresponding to each first safety evaluation index is determined by performing mathematical operation processing on each sub-evaluation parameter and the corresponding second weight parameter;

[0158] S9, performing weighted summation processing on each safety evaluation parameter according to the first weight parameter corresponding to each first safety evaluation index, and determining the safety evaluation result, wherein the safety evaluation result includes a safety evaluation value;

[0159] S10, matching the safety evaluation value with the preset plurality of safety evaluation ranges to determine the target safety level corresponding to the safety evaluation value; wherein, each safety evaluation range corresponds to a different safety level.

[0160] It should be understood that, although each step in the flowchart involved in the above embodiments is displayed in sequence according to the arrow, these steps are not necessarily executed in the order indicated by the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other orders. Moreover, at least part of the steps in the flowchart involved in the above embodiments can include multiple steps or stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.

[0161] Based on the same inventive concept, the embodiment of the present application also provides a system security evaluation device for implementing the system security evaluation method described above. The implementation scheme of the device for solving the problem is similar to the implementation scheme described in the above method, so the specific limitations in one or more system security evaluation device embodiments provided below can refer to the limitations of the system security evaluation method described above, which will not be repeated here.

[0162] In one embodiment, as shown in FIG. 14, a system security evaluation device is provided, comprising: an acquisition module 11, a first determination module 12 and a second determination module 13, wherein:

[0163] The acquisition module 11 is configured to acquire first security evaluation indexes corresponding to the industrial control system; the industrial control system at least includes an industrial cloud platform layer, an edge control platform layer and a terminal device layer;

[0164] The first determination module 12 is configured to determine security evaluation parameters corresponding to each first security evaluation index according to each first security evaluation index and an index evaluation model corresponding to each first security evaluation index; each index evaluation model performs security evaluation parameter calculation on the corresponding first security evaluation index; wherein the first security evaluation index includes system availability, system credibility and system inherent safety capability; the index evaluation model corresponding to the first security evaluation index includes a system availability evaluation model, a system credibility evaluation model and a system inherent safety capability evaluation model;

[0165] The second determination module 13 is configured to determine a security evaluation result corresponding to the industrial control system according to each security evaluation parameter.

[0166] In another embodiment, another system security evaluation device is provided, which can further include:

[0167] The second security index acquisition module is configured to acquire each second security evaluation index corresponding to each first security evaluation index; each second security evaluation index of each first security evaluation index is an index of the same level and / or different levels.

[0168] The first weight parameter determination module is configured to determine a first weight parameter corresponding to each first security evaluation index according to a preset analytic hierarchy process and each first security evaluation index;

[0169] The second weight parameter determination module is configured to determine a second weight parameter corresponding to each second security evaluation index of the same level according to the analytic hierarchy process and each second security evaluation index of the same level.

[0170] In another embodiment, another system security evaluation device is provided, and on the basis of the above-mentioned embodiment, the first determining module 12 can further include:

[0171] A sub-evaluation parameter determining unit is configured to input each second security evaluation index into a corresponding index evaluation model to determine a sub-evaluation parameter corresponding to each second security evaluation index.

[0172] A security evaluation parameter determining unit is configured to input each second weight parameter into a corresponding index evaluation model, perform mathematical operation processing on each sub-evaluation parameter and the corresponding second weight parameter, and determine a security evaluation parameter corresponding to each first security evaluation index.

[0173] In another embodiment, another system security evaluation device is provided, and on the basis of the above-mentioned embodiment, the first weight parameter determining module can further include:

[0174] A comparison matrix determining unit is configured to determine a comparison matrix corresponding to each first security evaluation index according to the relative importance of each first security evaluation index obtained.

[0175] An importance determining unit is configured to determine the importance of each first security evaluation index itself according to the comparison matrix.

[0176] A first weight parameter determining unit is configured to determine a first weight parameter corresponding to each first security evaluation index according to the importance of each first security evaluation index itself and a preset optimal transfer matrix.

[0177] In another embodiment, another system security evaluation device is provided, and on the basis of the above-mentioned embodiment, the second determining module 13 can further include:

[0178] A security evaluation result determining unit is configured to perform weighted summation processing on each security evaluation parameter according to the first weight parameter corresponding to each first security evaluation index to determine a security evaluation result.

[0179] In another embodiment, another system security evaluation device is provided, and on the basis of the above-mentioned embodiment, the system security evaluation device can further include:

[0180] A target security level determining module is configured to match the security evaluation value with a plurality of preset security evaluation ranges to determine a target security level corresponding to the security evaluation value, wherein each security evaluation range corresponds to a different security level.

[0181] The modules in the system security evaluation device can be implemented by software, hardware, or a combination thereof, in whole or in part. The modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in a computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the modules.

[0182] In an embodiment, a computer device is also provided, including a memory and a processor, the memory storing a computer program, and the processor implementing the steps in the above method embodiments when executing the computer program.

[0183] In an embodiment, a computer readable storage medium is provided, storing a computer program, and the computer program implementing the steps in the above method embodiments when executed by a processor.

[0184] In an embodiment, a computer program product is provided, including a computer program, and the computer program implementing the steps in the above method embodiments when executed by a processor.

[0185] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0186] Any combination of the technical features of the above-mentioned embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above-mentioned embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.

[0187] The above-mentioned embodiments only express several embodiments of the present application, and the description is more specific and detailed, but it should not be understood as limiting the scope of the patent application. It should be noted that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of the present application. Therefore, the scope of the patent protection of the present application should be subject to the appended claims.

Claims

1. A method of system security evaluation, wherein, The method comprises: obtaining first security evaluation indexes corresponding to an industrial control system; the industrial control system at least comprises a cloud platform layer, an edge control platform layer and a terminal equipment layer; determining security evaluation parameters corresponding to each of the first security evaluation indexes according to each of the first security evaluation indexes and an index evaluation model corresponding to each of the first security evaluation indexes; each of the index evaluation models is used for security evaluation parameter calculation of a corresponding first security evaluation index; wherein the first security evaluation indexes comprise system availability, system trustworthiness and system inherent safety capability; the index evaluation model corresponding to the first security evaluation index comprises a system availability evaluation model, a system trustworthiness evaluation model and a system inherent safety capability evaluation model; determining a security evaluation result corresponding to the industrial control system according to each of the security evaluation parameters.

2. The method of claim 1, wherein, Before the determining of the security evaluation parameters corresponding to each of the first security evaluation indexes according to each of the first security evaluation indexes and the index evaluation model corresponding to each of the first security evaluation indexes, the method further comprises: obtaining each of second security evaluation indexes corresponding to each of the first security evaluation indexes; each of the second security evaluation indexes of each of the first security evaluation indexes is an index of the same level and / or different levels; determining first weight parameters corresponding to each of the first security evaluation indexes according to a preset analytic hierarchy process and each of the first security evaluation indexes; determining second weight parameters corresponding to each of the second security evaluation indexes of the same level according to the analytic hierarchy process and each of the second security evaluation indexes of the same level.

3. The method of claim 2, wherein, The determining of the security evaluation parameters corresponding to each of the first security evaluation indexes according to each of the first security evaluation indexes and the index evaluation model corresponding to each of the first security evaluation indexes comprises: inputting each of the second security evaluation indexes into the index evaluation model corresponding to each of the first security evaluation indexes respectively to determine sub-evaluation parameters corresponding to each of the second security evaluation indexes; inputting each of the second weight parameters into the corresponding index evaluation model respectively to perform mathematical operation processing on each of the sub-evaluation parameters and the corresponding second weight parameters to determine the security evaluation parameters corresponding to each of the first security evaluation indexes.

4. The method of claim 2, wherein, The determining of the first weight parameters corresponding to each of the first security evaluation indexes according to the preset analytic hierarchy process and each of the first security evaluation indexes comprises: determining a comparison matrix corresponding to each of the first security evaluation indexes according to the relative importance of each of the first security evaluation indexes obtained; determining the importance of each of the first security evaluation indexes according to the comparison matrix; determining the first weight parameters corresponding to each of the first security evaluation indexes according to the importance of each of the first security evaluation indexes and a preset optimal transmission matrix.

5. The method according to any one of claims 2-4, wherein, The determining of the security evaluation result corresponding to the industrial control system according to each of the security evaluation parameters comprises: performing weighted summation processing on each of the security evaluation parameters according to the first weight parameters corresponding to each of the first security evaluation indexes to determine the security evaluation result.

6. The method according to any one of claims 1 to 4, wherein, The security evaluation result includes a security evaluation value, and the method further includes: matching the security evaluation value with a plurality of preset security evaluation ranges to determine a target security level corresponding to the security evaluation value; each of the security evaluation ranges corresponds to a different security level.

7. A system security evaluation apparatus, wherein, The device includes: an acquisition module configured to acquire first security evaluation indexes corresponding to each level in an industrial control system; the industrial control system includes at least a cloud platform layer, an edge control platform layer, and a terminal device layer; a first determination module configured to determine security evaluation parameters corresponding to each of the first security evaluation indexes according to each of the first security evaluation indexes and an index evaluation model corresponding to each of the first security evaluation indexes; each of the index evaluation models is used to calculate security evaluation parameters for a corresponding first security evaluation index; a second determination module configured to determine a security evaluation result corresponding to the industrial control system according to each of the security evaluation parameters.

8. A computer device comprising a memory and a processor, the memory storing a computer program, wherein, The processor executes the computer program to implement the steps of the method of any one of claims 1 to 6.

9. A computer readable storage medium having stored thereon a computer program, wherein, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.

10. A computer program product comprising a computer program, wherein, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.