作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2020, Vol. 46 ›› Issue (8): 132-138. doi: 10.19678/j.issn.1000-3428.0055631

• 网络空间安全 • 上一篇    下一篇

基于攻击防御树的CPS最小防御代价计算方法

钟志成, 徐丙凤, 顾久根   

  1. 南京林业大学 信息科学技术学院, 南京 210037
  • 收稿日期:2019-07-31 修回日期:2019-09-06 发布日期:2019-09-12
  • 作者简介:钟志成(1998-),男,本科生,主研方向为CPS系统安全;徐丙凤,讲师、博士;顾久根,本科生。
  • 基金资助:
    国家自然科学基金青年科学基金(61802192,61702282);江苏省高等学校自然科学研究项目(18KJB520024,17KJB520023);南京林业大学校青年创新基金(CX2016026);南京林业大学大学生创新训练计划项目(2018NFUSPITP475,2018NFUSPITP457)。

Minimum Defense Cost Calculation Method for CPS Based on Attack Defense Tree

ZHONG Zhicheng, XU Bingfeng, GU Jiugen   

  1. College of Information Science and Technology, Nanjing Forestry University, Nanjing 210037, China
  • Received:2019-07-31 Revised:2019-09-06 Published:2019-09-12

摘要: 为降低信息物理融合系统(CPS)的防御代价,提高防御措施的有效性,提出一种基于攻击防御树的CPS最小防御代价计算方法,并实现相应的计算工具。通过对攻击防御树增加约束,给出原子攻击防御树的概念。对攻击防御树进行预处理,将其转换为原子攻击防御树,采用代数方法进行最小防御代价计算。基于此,在Eclipse平台上利用Java语言实现一款最小防御代价计算软件。以某电力系统的经典案例进行实验验证,结果表明,该方法可以正确且高效地计算出攻击防御树的最小防御代价。

关键词: 信息物理融合系统, 攻击防御树, 防御代价, 割集, 网络攻击

Abstract: In order to reduce the defense cost of Cyber Physical System(CPS) and improve the effectiveness of defense measures,this paper proposes a method based on Attack Defense Tree(ADTree) to calculate the minimal defense cost of CPS and implements a calculation tool.Firstly,the concept of atom attack defense tree(A2DTree) is proposed by adding constraints to ADTree.Secondly,the ADTree is transformed into an A2DTree by preprocessing,and the minimum defense cost is calculated by using an algebraic method.On this basis,a tool for minimum defense cost calculation is designed and implemented by Java on the Eclipse platform.The effectiveness of the method is verified by an experiment based on a typical case study of a power system.Results show that the proposed method can correctly and efficiently calculate the minimum defense cost of ADTree.

Key words: Cyber Physical System(CPS), Attack Defense Tree(ADTree), defense cost, cut set, network attack

中图分类号: