Suppr超能文献

针对SCADA和DCS网络的网络安全风险评估

Cyber security risk assessment for SCADA and DCS networks.

作者信息

Ralston P A S, Graham J H, Hieb J L

机构信息

University of Louisville, JB Speed School of Engineering, 40292 Louisville, KY, United States.

出版信息

ISA Trans. 2007 Oct;46(4):583-94. doi: 10.1016/j.isatra.2007.04.003. Epub 2007 Jul 10.

Abstract

The growing dependence of critical infrastructures and industrial automation on interconnected physical and cyber-based control systems has resulted in a growing and previously unforeseen cyber security threat to supervisory control and data acquisition (SCADA) and distributed control systems (DCSs). It is critical that engineers and managers understand these issues and know how to locate the information they need. This paper provides a broad overview of cyber security and risk assessment for SCADA and DCS, introduces the main industry organizations and government groups working in this area, and gives a comprehensive review of the literature to date. Major concepts related to the risk assessment methods are introduced with references cited for more detail. Included are risk assessment methods such as HHM, IIM, and RFRM which have been applied successfully to SCADA systems with many interdependencies and have highlighted the need for quantifiable metrics. Presented in broad terms is probability risk analysis (PRA) which includes methods such as FTA, ETA, and FEMA. The paper concludes with a general discussion of two recent methods (one based on compromise graphs and one on augmented vulnerability trees) that quantitatively determine the probability of an attack, the impact of the attack, and the reduction in risk associated with a particular countermeasure.

摘要

关键基础设施和工业自动化对基于物理和网络的互联控制系统的依赖日益增加,这给监控与数据采集(SCADA)系统和分布式控制系统(DCS)带来了前所未有的网络安全威胁,且这种威胁还在不断加剧。工程师和管理人员了解这些问题并知道如何获取所需信息至关重要。本文全面概述了SCADA和DCS的网络安全与风险评估,介绍了该领域的主要行业组织和政府团体,并对迄今为止的相关文献进行了全面综述。文中介绍了与风险评估方法相关的主要概念,并引用参考文献以供更详细了解。其中包括诸如HHM、IIM和RFRM等风险评估方法,这些方法已成功应用于具有许多相互依存关系的SCADA系统,并凸显了对可量化指标的需求。文中大致介绍了概率风险分析(PRA),其中包括故障树分析(FTA)、事件树分析(ETA)和故障模式与影响分析(FEMA)等方法。本文最后对两种最新方法进行了一般性讨论(一种基于折衷图,另一种基于增强漏洞树),这两种方法可定量确定攻击概率、攻击影响以及与特定对策相关的风险降低情况。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验