基于不完全信息静态博弈的工控系统风险评估方法

RISK ASSESSMENT METHOD OF INDUSTRIAL CONTROL SYSTEM BASED ON INCOMPLETE INFORMATION STATIC GAME

  • 摘要: 针对目前大多数工业控制系统风险评估方法未思考防御者策略以及攻防两者之间的对抗问题,提出一种基于博弈模型的风险评估方法。通过攻击防御图模型,计算攻击收益和防御收益;建立静态贝叶斯攻防博弈模型,计算混合策略贝叶斯纳什均衡,获得攻防两者最优策略概率分布。根据信息安全风险评估的计算方法,以防御者收益和攻击者最优策略选择概率分布为基础进行风险评估计算。通过一个实例证明了该方法的可行性和有用性。

     

    Abstract: At present, most industrial control system risk assessment methods do not consider the defender strategy and the confrontation between attack and defense. Therefore, this paper proposes a risk assessment method based on game model. The attack defense graph was used to calculate attack gain and defense gain. The static Bayesian attack and defense game model was established to calculate the mixed strategy Bayesian Nash equilibrium, and the optimal probability distribution of attack and defense strategies was obtained. According to the calculation method of information security risk assessment, the risk assessment analysis method was calculated based on the probability distribution of the defender's benefit and the attacker's optimal strategy selection. An example was used to illustrate the feasibility and usefulness of the proposed method.

     

/

返回文章
返回