Active defense technology is an effective method to address multiple attack threats in industrial control systems, which affects the evolution of offensive and defensive confrontation through various mechanisms. However, how to comprehensively measure its security effectiveness under unified security indicators remains an urgent problem to be solved. This paper proposes a security evaluation method based on the attack-defense graph method to conduct the formal analysis and security risk evaluation of the role of both attack and defense in complex industrial control system scenarios. Different from the previous method of calculating attack risk, we propose an accumulated approach for attack success rates under different attack frequencies, simulating the trend of system attack risk changing over time. According to the characteristics of active defense techniques like honeypots, simulate and analyze the impact of different deployment positions on attack risk. The experimental results show that the deployment of three honeypots in different hierarchies extended the time-to-compromise by 24.4% compared to the deployment in the same hierarchy.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Active Defense Simulation Evaluation of Industrial Control Systems Based on Attack-Defense Graph

  • Qun Xiao,
  • Shouguo Yang,
  • Jiaqian Peng,
  • Jingfei Bian,
  • Shichao Lv,
  • Limin Sun,
  • Zhiqiang Shi

摘要

Active defense technology is an effective method to address multiple attack threats in industrial control systems, which affects the evolution of offensive and defensive confrontation through various mechanisms. However, how to comprehensively measure its security effectiveness under unified security indicators remains an urgent problem to be solved. This paper proposes a security evaluation method based on the attack-defense graph method to conduct the formal analysis and security risk evaluation of the role of both attack and defense in complex industrial control system scenarios. Different from the previous method of calculating attack risk, we propose an accumulated approach for attack success rates under different attack frequencies, simulating the trend of system attack risk changing over time. According to the characteristics of active defense techniques like honeypots, simulate and analyze the impact of different deployment positions on attack risk. The experimental results show that the deployment of three honeypots in different hierarchies extended the time-to-compromise by 24.4% compared to the deployment in the same hierarchy.