SCADA系统信息安全风险评估的研究与应用
2021-02-19李丹

摘 要:在对风险评估理论研究的基础上,提出了基于改进层次分析法的SCADA系统信息安全风险评估方法。首先建立了ACADA系統信息安全风险评估层次结构模型,分为管理和技术两大类。然后针对传统层次分析法中通过两两比较法构造判断矩阵难以符合一致性要求的问题,进行了一定的改进,提出通过排序赋值法构造判断矩阵,通过改进层次分析法和熵权法计算出各评价指标权值。最后将以上方法用于对自来水厂SCADA系统信息安全风险评估。
关键词:SCADA系统;信息安全风险评估;层次分析法
中图分类号:TP309 文献标识码:A文章编号:2096-4706(2021)13-0133-03
Research and Application of SCADA System Information Security Risk Assessment
LI Dan
(Hubei University of Technology, Wuhan 430068, China)
Abstract: Based on the research of risk assessment theory, an information security risk assessment method of SCADA system based on improved analytic hierarchy process is proposed. Firstly, the hierarchical structure model of information security risk assessment of ACADA system is established, which is divided into two categories of management and technology. Then, aimming at the problem that the judgment matrix constructed by paired comparison method in the traditional analytic hierarchy process is difficult to meet the consistency requirements, some improvements are made. The construction of judgment matrix by sorting assignment method is proposed, and the weight of each evaluation index is calculated by improved analytic hierarchy process and the entropy weight method. Finally, the above methods are used to evaluate the information security risk of SCADA system in waterworks.
Keywords: SCADA system; information security risk assessment; analytic hierarchy process
0 引 言
数据采集与监控系统(Supervisory Control And Data Acquisition, SCADA)是众多大型工业生产与各国基础设施的控制系统,主要应用于石油、化工、天然气、电力、先进制造、铁路、城市供水供热等行业,这些领域与民生国计都息息相关,是我们衡量一个国家工业化程度的重要标志。
近年来,工业SCADA系统受到攻击的频率越来越多,发生了很多重大信息安全事件[1],例如:2001年澳大利亚昆士兰州的污水处理厂遭受黑客攻击,造成污水横流,给自然环境造成极大的负担;2008年南美洲某国的电网控制系统遭到黑客控制,导致电网停止工作,给国民经济造成损失;2013年美国天然气管道公司被黑客入侵,盗取重要的系统数据资料,给燃气公司造成极大威胁。
信息安全风险评估的方法主要围绕着解决四类问题,即量化、不确定性、实时性和关联性[2]。层次分析法是解决风险评估的量化问题,他能够全面系统的对信息系统存在的问题进行评估,但层次分析法在评估指标过多时,采用两两比较法构造的判断矩阵难以符合一致性要求。……
