A Fuzzy Probability Bayesian Network Approach for Dynamic Cybersecurity Risk Assessment in Industrial Control Systems

被引:120
|
作者
Zhang, Qi [1 ]
Zhou, Chunjie [1 ]
Tian, Yu-Chu [2 ]
Xiong, Naixue [3 ]
Qin, Yuanqing [1 ]
Hu, Bowen [1 ]
机构
[1] Huazhong Univ Sci & Technol, Sch Automat, Wuhan 430074, Hubei, Peoples R China
[2] Queensland Univ Technol, Sch Elect Engn & Comp Sci, Brisbane, Qld 4001, Australia
[3] Northeastern State Univ, Dept Math & Comp Sci, Tahlequah, OK 74464 USA
基金
美国国家科学基金会; 澳大利亚研究理事会;
关键词
Bayesian network (BN); cybersecurity; fuzzy probability; industrial control systems (ICSs); risk assessment; METHODOLOGY;
D O I
10.1109/TII.2017.2768998
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the increasing deployment of data network technologies in industrial control systems (ICSs), cybersecurity becomes a challenging problem in ICSs. Dynamic cybersecurity risk assessment plays a vital role in ICS cybersecurity protection. However, it is difficult to build a risk propagation model for ICSs due to the lack of sufficient historical data. In this paper, a fuzzy probability Bayesian network (FPBN) approach is presented for dynamic risk assessment. First, an FPBN is established for analysis and prediction of the propagation of cybersecurity risks. To overcome the difficulty of limited historical data, the crisp probabilities used in standard Bayesian networks are replaced in our approach by fuzzy probabilities. Then, an approximate dynamic inference algorithm is developed for dynamic assessment of ICS cybersecurity risk. It is embedded with a noise evidence filter in order to reduce the impact from noise evidence caused by system faults. Experiments are conducted on a simplified chemical reactor control system to demonstrate the effectiveness of the presented approach.
引用
收藏
页码:2497 / 2506
页数:10
相关论文
共 50 条
  • [1] Cybersecurity Risk Assessment Strategies in Industrial Control Systems
    Gale, Tim
    [J]. CHEMICAL ENGINEERING PROGRESS, 2023, 119 (12) : 35 - 39
  • [2] A Bayesian network approach for cybersecurity risk assessment implementing and extending the FAIR model
    Wang, Jiali
    Neil, Martin
    Fenton, Norman
    [J]. COMPUTERS & SECURITY, 2020, 89
  • [3] Software project risk probability assessment based on dynamic Bayesian network
    Zhang Junguang
    Guo Lihong
    Xu Zhenchao
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL SYMPOSIUM ON COMPUTERS & INFORMATICS, 2015, 13 : 1128 - 1134
  • [4] Multimodel-Based Incident Prediction and Risk Assessment in Dynamic Cybersecurity Protection for Industrial Control Systems
    Zhang, Qi
    Zhou, Chunjie
    Xiong, Naixue
    Qin, Yuanqing
    Li, Xuan
    Huang, Shuang
    [J]. IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2016, 46 (10): : 1429 - 1444
  • [5] A Risk-Based Dynamic Decision-Making Approach for Cybersecurity Protection in Industrial Control Systems
    Qin, Yuanqing
    Zhang, Qi
    Zhou, Chunjie
    Xiong, Naixue
    [J]. IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2020, 50 (10): : 3863 - 3870
  • [6] A Systems Approach for Cybersecurity Risk Assessment
    Meshkat, Leila
    Miller, Robert L.
    [J]. 2022 68TH ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2022), 2022,
  • [7] A Fuzzy Dynamic Bayesian Network-Based Situation Assessment Approach
    Naderpour, Mohsen
    Lu, Jie
    Zhang, Guangquan
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS (FUZZ - IEEE 2013), 2013,
  • [8] Association Analysis-Based Cybersecurity Risk Assessment for Industrial Control Systems
    Qin, Yuanqing
    Peng, Yuan
    Huang, Kaixing
    Zhou, Chunjie
    Tian, Yu-Chu
    [J]. IEEE SYSTEMS JOURNAL, 2021, 15 (01): : 1423 - 1432
  • [9] Using Bayesian Network to develop a probability assessment approach for construction safety risk
    Wang, Tao
    Liao, Binchao
    Ma, Xin
    Fang, Dongping
    [J]. Tumu Gongcheng Xuebao/China Civil Engineering Journal, 2010, 43 (SUPPL. 2): : 384 - 391
  • [10] A mixed fuzzy probabilistic approach for risk assessment of dynamic systems
    Abdo, H.
    Flaus, J-M
    [J]. IFAC PAPERSONLINE, 2015, 48 (03): : 960 - 965