正在加载图片...
第17卷第5期 智能系统学报 Vol.17 No.5 2022年9月 CAAI Transactions on Intelligent Systems Sep.2022 D0:10.11992/tis.202107005 网络出版地址:https:/kns.cnki.net/kcms/detail/23.1538.TP.20220518.2144.012.html 基于云模型和组合权重的SCADA 系统安全风险评估研究 杨力,秦红梅,苏华文 (西南石油大学计算机科学学院,四川成都610500) 摘要:当前数据采集与监控系统(supervisory control and data acquisition,.SCADA)系统面临着巨大的安全威胁, 对其风险状况进行监测和评估是一项有效的应对措施。为有效处理评估过程中存在的模糊性和随机性问题, 将云模型理论引入SCADA系统安全风险评估中,提出了一种基于云模型和组合权重的安全风险评估模型。该 模型从SCADA系统的资产、威胁、脆弱性、安全措施4方面构建安全风险评估指标体系,采用最小二乘法求出 评估指标的最优组合权重,借助云发生器得到评估指标的云模型数字特征和SCADA系统的综合评估云,然后 基于黄金分割率构建标准评估云,同时结合改进的云相似度计算方法得出最终评估结果,最后通过实验验证了 模型的有效性和可行性。研究结果表明,该模型能够得到准确的评估结果,与模糊综合评价等方法相比,该评 估方法具备更高的可信性,评价效果更好。该方法不仅有助识别SCADA系统的安全风险威胁,而且为其他领 域的安全风险评估提供了一定的参考。 关键词:SCADA系统:安全风险评估;云模型;组合权重;云相似度;模糊性;随机性;云数字特征 中图分类号:TP399文献标志码:A文章编号:1673-4785(2022)05-0969-11 中文引用格式:杨力,秦红梅,苏华文.基于云模型和组合权重的SCADA系统安全风险评估研究.智能系统学报,2022, 17(5):969-979. 英文引用格式:YANG Li,QIN Hongmei,,SU Huawen.Research on security risk assessment of SCADA system based on the cloud model and combination weighting[J.CAAl transactions on intelligent systems,2022,17(5):969-979. Research on security risk assessment of SCADA system based on the cloud model and combination weighting YANG Li,QIN Hongmei,SU Huawen (School of Computer Science,Southwest Petroleum University,Chengdu 610500.China) Abstract:The current(supervisory control and data acquisition,SCADA)system faces a huge security threat,and mon- itoring and evaluating its risk status is an effective countermeasure.In this paper,a cloud model theory is introduced to the security risk assessment of the SCADA system,and a security risk assessment model is proposed based on the cloud model and combination weighting to effectively deal with the problem of ambiguity and randomness in the assessment process.Firstly,a security risk assessment index system is constructed from assets,threats,vulnerabilities,and security measures of a SCADA system,Then the least squares estimate is used to obtain optimal combination weighting,and the cloud digital characteristics are calculated with the help of cloud generator,to get comprehensive security risk assess- ment cloud.Next,according to the golden ratio,the standard evaluation cloud is constructed and combined with the im- proved cloud similarity calculation method to obtain the final evaluation result.Finally,the effectiveness and feasibility of the model are verified through experiments.The research results show that the model can obtain accurate evaluation results,and compared with the fuzzy comprehensive evaluation method,it shows that this method has higher credibility and better evaluation effect.This method not only helps in identifying security risk threats in the SCADA system but also provides a certain reference for security risk assessment in other fields. Keywords:SCADA system;security risk assessment;cloud model;combination weighting;cloud similarity;ambiguity; randomness;cloud digital characteristics 收稿日期:2021-07-05.网络出版日期:2022-05-19 数据采集与监控系统(supervisory control and 基金项目:国家自然科学基金项目(61175122):四川省科技计 划资助项目(2022 NSFSC0555). data acquisition,SCADA)系统是一个综合利用计 通信作者:杨力.E-mail:sexdyl@126.com 算机技术、控制技术和通信网络技术的数据采集DOI: 10.11992/tis.202107005 网络出版地址: https://kns.cnki.net/kcms/detail/23.1538.TP.20220518.2144.012.html 基于云模型和组合权重的 SCADA 系统安全风险评估研究 杨力,秦红梅,苏华文 (西南石油大学 计算机科学学院,四川 成都 610500) 摘 要:当前数据采集与监控系统 (supervisory control and data acquisition, SCADA) 系统面临着巨大的安全威胁, 对其风险状况进行监测和评估是一项有效的应对措施。为有效处理评估过程中存在的模糊性和随机性问题, 将云模型理论引入 SCADA 系统安全风险评估中,提出了一种基于云模型和组合权重的安全风险评估模型。该 模型从 SCADA 系统的资产、威胁、脆弱性、安全措施 4 方面构建安全风险评估指标体系,采用最小二乘法求出 评估指标的最优组合权重,借助云发生器得到评估指标的云模型数字特征和 SCADA 系统的综合评估云,然后 基于黄金分割率构建标准评估云,同时结合改进的云相似度计算方法得出最终评估结果,最后通过实验验证了 模型的有效性和可行性。研究结果表明,该模型能够得到准确的评估结果,与模糊综合评价等方法相比,该评 估方法具备更高的可信性,评价效果更好。该方法不仅有助识别 SCADA 系统的安全风险威胁,而且为其他领 域的安全风险评估提供了一定的参考。 关键词:SCADA 系统;安全风险评估;云模型;组合权重;云相似度;模糊性;随机性;云数字特征 中图分类号:TP399 文献标志码:A 文章编号:1673−4785(2022)05−0969−11 中文引用格式:杨力, 秦红梅, 苏华文. 基于云模型和组合权重的 SCADA 系统安全风险评估研究 [J]. 智能系统学报, 2022, 17(5): 969–979. 英文引用格式:YANG Li, QIN Hongmei, SU Huawen. Research on security risk assessment of SCADA system based on the cloud model and combination weighting[J]. CAAI transactions on intelligent systems, 2022, 17(5): 969–979. Research on security risk assessment of SCADA system based on the cloud model and combination weighting YANG Li,QIN Hongmei,SU Huawen (School of Computer Science, Southwest Petroleum University, Chengdu 610500, China) Abstract: The current (supervisory control and data acquisition, SCADA) system faces a huge security threat, and mon￾itoring and evaluating its risk status is an effective countermeasure. In this paper, a cloud model theory is introduced to the security risk assessment of the SCADA system, and a security risk assessment model is proposed based on the cloud model and combination weighting to effectively deal with the problem of ambiguity and randomness in the assessment process. Firstly, a security risk assessment index system is constructed from assets, threats, vulnerabilities, and security measures of a SCADA system, Then the least squares estimate is used to obtain optimal combination weighting, and the cloud digital characteristics are calculated with the help of cloud generator, to get comprehensive security risk assess￾ment cloud. Next, according to the golden ratio, the standard evaluation cloud is constructed and combined with the im￾proved cloud similarity calculation method to obtain the final evaluation result. Finally, the effectiveness and feasibility of the model are verified through experiments. The research results show that the model can obtain accurate evaluation results, and compared with the fuzzy comprehensive evaluation method, it shows that this method has higher credibility and better evaluation effect. This method not only helps in identifying security risk threats in the SCADA system but also provides a certain reference for security risk assessment in other fields. Keywords: SCADA system; security risk assessment; cloud model; combination weighting; cloud similarity; ambiguity; randomness; cloud digital characteristics 数据采集与监控系统 (supervisory control and data acquisition, SCADA) 系统是一个综合利用计 算机技术、控制技术和通信网络技术的数据采集 收稿日期:2021−07−05. 网络出版日期:2022−05−19. 基金项目:国家自然科学基金项目 (61175122);四川省科技计 划资助项目 (2022NSFSC0555). 通信作者:杨力. E-mail: scxdy1@126.com. 第 17 卷第 5 期 智 能 系 统 学 报 Vol.17 No.5 2022 年 9 月 CAAI Transactions on Intelligent Systems Sep. 2022
向下翻页>>
©2008-现在 cucdc.com 高等教育资讯网 版权所有