曹翔, 姜敏. 基于业务关联模型的变电站网络安全风险评估方法[J]. 电力信息与通信技术, 2022, 20(11): 57-64. DOI: 10.16543/j.2095-641x.electric.power.ict.2022.11.007
引用本文: 曹翔, 姜敏. 基于业务关联模型的变电站网络安全风险评估方法[J]. 电力信息与通信技术, 2022, 20(11): 57-64. DOI: 10.16543/j.2095-641x.electric.power.ict.2022.11.007
CAO Xiang, JIANG Min. Substation Cyber Security Risk Assessment Method Based on Business Association Model[J]. Electric Power Information and Communication Technology, 2022, 20(11): 57-64. DOI: 10.16543/j.2095-641x.electric.power.ict.2022.11.007
Citation: CAO Xiang, JIANG Min. Substation Cyber Security Risk Assessment Method Based on Business Association Model[J]. Electric Power Information and Communication Technology, 2022, 20(11): 57-64. DOI: 10.16543/j.2095-641x.electric.power.ict.2022.11.007

基于业务关联模型的变电站网络安全风险评估方法

Substation Cyber Security Risk Assessment Method Based on Business Association Model

  • 摘要: 为了对变电站系统提供直观、量化的网络安全风险值,提高网络安全风险管控和运维能力,文章提出基于业务关联模型的变电站网络安全风险评估方法。在分析变电站网络特点的基础上,给出风险评估模型中的指标体系、系统框架和分析方法。然后采用基于业务关联模型的层次分析法,给出理论上的计算方法和具体实现方式。通过对变电站中网络设备的分类、各类设备业务的分类以及对各类业务威胁/脆弱点的分析,以逐层加权方法得到整个网络的风险值,并对实现中的多源融合问题进行讨论。通过对现有变电站数据的采集,实现网络安全风险的可视化和可追溯。最后通过工程应用验证理论的可行性和技术的实用性。

     

    Abstract: In order to provide intuitive and quantitative cyber security risk value for substation system and improve cyber security risk control and operation and maintenance ability, this paper proposes a substation cyber security risk assessment method based on business association model. Based on the analysis of the characteristics of substation network, the index system, system framework and analysis method in the risk assessment model are given. Then the analytic hierarchy process based on business association model is used to give the theoretical calculation method and specific implementation method. Through the classification of network equipment in substation, the classification of various equipment services and the analysis of various service threats/vulnerabilities, the risk value of the whole network is obtained by layer by layer weighting method, and the problem of multi-source fusion in implementation is discussed. Through the collection of existing substation data, the visualization and traceability of cyber security risk can be realized. Finally, the feasibility of the theory and the practicability of the technology are verified by engineering application.

     

/

返回文章
返回