摘要
针对工业控制系统漏洞风险评估角度较为单一且与工控环境联系不紧密问题,提出了面向工业控制系统漏洞的多维属性评估方法。首先,建立了漏洞有效性、风险类别属性判别模板,同时定义漏洞风险程度多维评价指标。其次,提出基于ernieCat的风险程度预测模型,使用漏洞文本描述及漏洞内在评价属性作为融合特征预测漏洞的严重性、危害性以及可利用性等级。结合工业控制系统设备层级关键信息与漏洞风险等级情况,建立多维度量化指标,对工业控制系统漏洞的危害程度进行量化评估。最后,通过实验验证ernieCat模型应用在漏洞风险程度预测方面的优越性。
In order to solve the problem that the industrial control system vulnerability risk assessment is simple and not closely related to the industrial control environment,a multi-dimensional attri-bute analysis method of industrial control system vulnerability is proposed.Firstly,a template for discriminating vulnerability attack effectiveness and risk category attributes is established,and multi-dimensional evaluation indicators for the degree of risk vulnerability are defined.Secondly,an automat-ed prediction model of risk level based on ernieCat is proposed,which uses the fusion features of vulnerability text descriptions and the intrinsic evaluation attributes of vulnerabilities to predict the seriousness level,hazard level and exploitability level of industrial vulnerabilities.Besides,this paper combines device-level critical information of industrial control system with vulnerability-level risk situations,and establishes multi-dimensional quantitative evaluation indicators to quantitatively assess the risk hazard level for industrial control system vulnerabilities.Experimental results show that the ernieCat model is superior for predicting vulnerability risk level.
作者
李彤彤
王诗蕊
张耀方
王佰玲
王子博
刘红日
LI Tong-tong;WANG Shi-rui;ZHANG Yao-fang;WANG Bai-ling;WANG Zi-bo;LIU Hong-ri(School of Computer Science and Technology,Harbin Institute of Technology(Weihai),Weihai 264209;China Industrial Control Systems Cyber Emergency Response Team,Beijing 100040;School of Cyberspace Science,Harbin Institute of Technology,Harbin 150001;Weihai Cyberguard Technologies Co.,Ltd.,Weihai 264209,China)
出处
《计算机工程与科学》
CSCD
北大核心
2023年第2期261-268,共8页
Computer Engineering & Science
基金
国防基础科研计划(JCKY2019608B001)。
关键词
工控系统漏洞
属性判别
ERNIE模型
风险评价指标
量化评估
industrial control system vulnerability
discrimination of attribute
ERNIE model
risk assessment metrics
quantitative assessment