Journal of Shanghai Jiaotong University ›› 2019, Vol. 53 ›› Issue (Sup.1): 68-73.doi: 10.16183/j.cnki.jsjtu.2019.S1.012

Previous Articles     Next Articles

Information Security Analysis of Digital Control System Based on Attack Tree Model

SUN Zhuo,LIU Dong,XIAO Anhong,MING Pingzhou,GUO Wen,ZHOU Junyi,CHEN Junjie   

  1. Science and Technology on Reactor System Design Technology Laboratory, Nuclear Power Institute of China, Chengdu 610213, China
  • Published:2020-04-08

Abstract: The nuclear reactor digital control system(DCS)has introduced more threat factors while improving the convenience of the control system. The engineering station has the vulnerability of the traditional IT system in information security because of using a wide range of interface and Windows system, leaving hidden dangers to the security of the digital control system. An information security analysis method based on attack tree model for digital control system is proposed. The attack tree model with combining the hardware and software characteristics of DCS and its location in the system is established. The DCS information security asset assessment quantitative method is proposed. The common vulnerability scoring system (CVSS) to calculate the probability of attack tree nodes and attack paths is used. Through the quantitative evaluation of the engineering station,the attack path that the attacker is most likely to take is obtained,providing technical reference for the developer and the verification and validation (V&V) activities.

Key words: nuclear science and engineering; digital control system (DCS); information security; attack tree model; engineering station

CLC Number: