A risk assessment model for similar attack scenarios in industrial control system


연구 분야: Infrastructure



학회: The Journal of Supercomputing


초록

Although the expansion of attack types against industrial control systems is limited, the available means that violate the same security strategy emerge endlessly. However, the high availability and real-time requirements of industrial control systems restrict the application of some countermeasures that require massive resources. To solve this problem, this paper proposes a low learning-cost risk assessment model for similar scenarios, which enables the formulation of defense strategies for system risks in advance. To lay the foundation for this method, we firstly aggregate the attack means into limited attack types according to word clustering to address the classification challenge caused by unknown attacks. Then, similarity and statistical methods are combined to predict the next attack type. Subsequently, the hidden Markov model is used to map attack types and security states to obtain the forecasting results of the next security state. Based on this, the risk value is calculated through these prediction and forecasting results, and the system relevance and alert timeliness are considered in the assessment stage. We break the scenario limitations and verify the advantages of our model in a known scenario and another similar scenario with unknown attacks. The experimental results show that our model can deal with unknown attacks in similar scenarios and has excellent scenario migration ability. Meanwhile, the changing trend of the risk value is in consistence with the actual data, which also confirms that the assessment model can forecast the future risk situation of the system accurately and comprehensively.


Author Profile
Yaofang Zhang

School of Computer Science and Technology Harbin Institute of Technology Weihai 264209 China

Andorra
Author Profile
Zibo Wang

School of Cyber Science and Technology Harbin Institute of Technology Harbin 150001 China

Andorra
Author Profile
Yingzhou Wang

School of Computer Science and Technology Harbin Institute of Technology Weihai 264209 China

Andorra

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Andorra, China
사이트 Springer
좋아요 수 0

연관 논문 목록 (199건)