信息安全研究 ›› 2017, Vol. 3 ›› Issue (3): 270-276.

• 学术论文 • 上一篇    下一篇

基于工作流的舰艇系统脆弱性定量 评估方法研究

储忠涛   

  1. 华中科技大学自动化学院
  • 收稿日期:2017-03-20 出版日期:2017-03-15 发布日期:2017-03-21
  • 通讯作者: 储忠涛
  • 作者简介:硕士研究生,主要研究方向为工业控制系统信息安全.

Research on Quantitative Assessment Method of Vulnerability of Warship System Based on Workflow

  • Received:2017-03-20 Online:2017-03-15 Published:2017-03-21

摘要: 舰艇系统作为典型的信息物理融合系统,在对其进行信息安全脆弱性评估时需要充分考虑网络部分和物理部分融合的特性.在对舰艇系统信息安全问题进行深入分析的基础上,结合工作流基本原理,提出了基于工作流的舰艇系统信息安全脆弱性评估方法.该方法针对待评估的业务过程建立基于工作流的脆弱性评估模型,对执行工作流任务的设备进行解析,分析设备中存在的脆弱点,利用层次分析法对设备的信息安全脆弱性进行评估.根据工作流任务之间的逻辑关系以及执行工作流任务设备的脆弱性评估结果,对工作流任务的信息安全脆弱性进行评估,最终评估得到业务过程的信息安全脆弱性.

关键词: 信息物理融合系统, 舰艇系统, 脆弱性评估, 工作流模型, 层次分析法

Abstract: Warship system is a typical cyberphysical system. The characteristics of the fusion of cyber part and physical part of warship system needs to be fully considered during the security vulnerability assessment. In this paper, a workflow based vulnerability assessment method for security of the warship system is proposed after analyzing the security issues of the warship deeply and studying the principle of workflow. In detail, A workflow based vulnerability assessment model is established for the business process which is to be evaluated. Further, the composition of equipment that performs the workflow task and the vulnerability of the equipment are analyzed, respectively. And then, the security vulnerability of the equipment is evaluated by analytic hierarchy process (AHP) method. According to the logical relationship between workflow tasks and the results of vulnerability assessment of equipment, the security vulnerability of the workflow tasks is evaluated, and finally the security vulnerability of the business process is evaluated.

Key words: cyberphysical system, warship system, security vulnerability assessment, workflow model, analytic hierarchy process