期刊文献+

面向工控系统漏洞的多维属性评估 被引量:1

Multi-dimensional attribute analysis of industrial control system vulnerability
下载PDF
导出
摘要 针对工业控制系统漏洞风险评估角度较为单一且与工控环境联系不紧密问题,提出了面向工业控制系统漏洞的多维属性评估方法。首先,建立了漏洞有效性、风险类别属性判别模板,同时定义漏洞风险程度多维评价指标。其次,提出基于ernieCat的风险程度预测模型,使用漏洞文本描述及漏洞内在评价属性作为融合特征预测漏洞的严重性、危害性以及可利用性等级。结合工业控制系统设备层级关键信息与漏洞风险等级情况,建立多维度量化指标,对工业控制系统漏洞的危害程度进行量化评估。最后,通过实验验证ernieCat模型应用在漏洞风险程度预测方面的优越性。 In order to solve the problem that the industrial control system vulnerability risk assessment is simple and not closely related to the industrial control environment,a multi-dimensional attri-bute analysis method of industrial control system vulnerability is proposed.Firstly,a template for discriminating vulnerability attack effectiveness and risk category attributes is established,and multi-dimensional evaluation indicators for the degree of risk vulnerability are defined.Secondly,an automat-ed prediction model of risk level based on ernieCat is proposed,which uses the fusion features of vulnerability text descriptions and the intrinsic evaluation attributes of vulnerabilities to predict the seriousness level,hazard level and exploitability level of industrial vulnerabilities.Besides,this paper combines device-level critical information of industrial control system with vulnerability-level risk situations,and establishes multi-dimensional quantitative evaluation indicators to quantitatively assess the risk hazard level for industrial control system vulnerabilities.Experimental results show that the ernieCat model is superior for predicting vulnerability risk level.
作者 李彤彤 王诗蕊 张耀方 王佰玲 王子博 刘红日 LI Tong-tong;WANG Shi-rui;ZHANG Yao-fang;WANG Bai-ling;WANG Zi-bo;LIU Hong-ri(School of Computer Science and Technology,Harbin Institute of Technology(Weihai),Weihai 264209;China Industrial Control Systems Cyber Emergency Response Team,Beijing 100040;School of Cyberspace Science,Harbin Institute of Technology,Harbin 150001;Weihai Cyberguard Technologies Co.,Ltd.,Weihai 264209,China)
出处 《计算机工程与科学》 CSCD 北大核心 2023年第2期261-268,共8页 Computer Engineering & Science
基金 国防基础科研计划(JCKY2019608B001)。
关键词 工控系统漏洞 属性判别 ERNIE模型 风险评价指标 量化评估 industrial control system vulnerability discrimination of attribute ERNIE model risk assessment metrics quantitative assessment
  • 相关文献

参考文献8

二级参考文献76

  • 1刘奇旭,张翀斌,张玉清,张宝峰.安全漏洞等级划分关键技术研究[J].通信学报,2012,33(S1):79-87. 被引量:36
  • 2陈治纲,何丕廉,孙越恒,郑小慎.基于向量空间模型的文本分类系统的研究与实现[J].中文信息学报,2005,19(1):36-41. 被引量:43
  • 3陆余良,夏阳.主机安全量化融合模型研究[J].计算机学报,2005,28(5):914-920. 被引量:28
  • 4龚俭,梅海彬,丁勇,魏德昊.多特征关联的入侵事件冗余消除[J].东南大学学报(自然科学版),2005,35(3):366-371. 被引量:13
  • 5Abbott R,Chin J,Donnelley J,et al.Security Analysis andEnhancements of Computer Operating Systems[R].Washington DC,USA:US Department of Commerce,1976.
  • 6Bisbey II R,Hollingworth D.Protection Analysis:FinalReport[R].Marina Del Rey,USA:University of SouthernCalifornia,1978.
  • 7Bishop M,Bailey D.A Critical Analysis of VulnerabilityTaxonomies[R].Davis,USA:University of California atDavis,1996.
  • 8Christey S.The Preliminary List of Vulnerability Examplesfor Researchers[R].Bedford,USA:Mitre,2006.
  • 9Landwehr C,Bull A,Mcdemott J,et al.A taxonomy ofcomputer program security flaws[J].ACM ComputingSurveys,1994,26(3):211-254.
  • 10Aslam T,Krsul I,Spafford E.Use of a Taxonomy ofSecurity Faults[R].West Lafayette,USA:PurdureUniversity.1996.

共引文献198

同被引文献17

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部