Active Defense Simulation Evaluation of Industrial Control Systems Based on Attack-Defense Graph
摘要
Active defense technology is an effective method to address multiple attack threats in industrial control systems, which affects the evolution of offensive and defensive confrontation through various mechanisms. However, how to comprehensively measure its security effectiveness under unified security indicators remains an urgent problem to be solved. This paper proposes a security evaluation method based on the attack-defense graph method to conduct the formal analysis and security risk evaluation of the role of both attack and defense in complex industrial control system scenarios. Different from the previous method of calculating attack risk, we propose an accumulated approach for attack success rates under different attack frequencies, simulating the trend of system attack risk changing over time. According to the characteristics of active defense techniques like honeypots, simulate and analyze the impact of different deployment positions on attack risk. The experimental results show that the deployment of three honeypots in different hierarchies extended the time-to-compromise by 24.4% compared to the deployment in the same hierarchy.