Network Security Risk Assessment Framework Based on Tactical Correlation

Power system network is one of the important targets of cyber attack.In order to ensure the safe operation of power system,network managers need to evaluate the network security risk.Usually,existing network security risk assessment framework only aims at a single scenario,and can not find the strat...

Full description

Bibliographic Details
Main Author: LIU Jie-ling, LING Xiao-bo, ZHANG Lei, WANG Bo, WANG Zhi-liang, LI Zi-mu, ZHANG Hui, YANG Jia-hai, WU Cheng-nan
Format: Article
Language:zho
Published: Editorial office of Computer Science 2022-09-01
Series:Jisuanji kexue
Subjects:
Online Access:https://www.jsjkx.com/fileup/1002-137X/PDF/1002-137X-2022-49-9-306.pdf
_version_ 1827965472827506688
author LIU Jie-ling, LING Xiao-bo, ZHANG Lei, WANG Bo, WANG Zhi-liang, LI Zi-mu, ZHANG Hui, YANG Jia-hai, WU Cheng-nan
author_facet LIU Jie-ling, LING Xiao-bo, ZHANG Lei, WANG Bo, WANG Zhi-liang, LI Zi-mu, ZHANG Hui, YANG Jia-hai, WU Cheng-nan
author_sort LIU Jie-ling, LING Xiao-bo, ZHANG Lei, WANG Bo, WANG Zhi-liang, LI Zi-mu, ZHANG Hui, YANG Jia-hai, WU Cheng-nan
collection DOAJ
description Power system network is one of the important targets of cyber attack.In order to ensure the safe operation of power system,network managers need to evaluate the network security risk.Usually,existing network security risk assessment framework only aims at a single scenario,and can not find the strategic attackers who use a variety of low-risk methods to achieve high-risk threat targets from large quantities of network security alerts.In order to meet the above challenges,this paper proposes a network security risk assessment method based on tactical correlation.In this method,the warning information generated on va-rious network security detection devices when an attacker implements a multi-step attack is associated to form an attack chain,and the security risk of the organization intranet is evaluated by calculating the threat,vulnerability,impact score of each node in the attack chain and the risk score of the whole attack chain.In order to verify the effectiveness and robustness of the proposed method,this paper selects a representative example to illustrate the specific implementation process of the proposed method for network security risk assessment in the organizational intranet.The example shows that the network security risk assessment framework based on the tactical association can correctly assess the harm of multi-step attack caused by low-risk alarm association to achieve high-risk targets,and is more robust than the traditional single scenario analysis method,which can better provide decision-making basis for organization decision-makers in network security risk management.
first_indexed 2024-04-09T17:33:33Z
format Article
id doaj.art-5f2e5ef3f7d042a4988c706b32b88d82
institution Directory Open Access Journal
issn 1002-137X
language zho
last_indexed 2024-04-09T17:33:33Z
publishDate 2022-09-01
publisher Editorial office of Computer Science
record_format Article
series Jisuanji kexue
spelling doaj.art-5f2e5ef3f7d042a4988c706b32b88d822023-04-18T02:32:31ZzhoEditorial office of Computer ScienceJisuanji kexue1002-137X2022-09-0149930631110.11896/jsjkx.210600171Network Security Risk Assessment Framework Based on Tactical CorrelationLIU Jie-ling, LING Xiao-bo, ZHANG Lei, WANG Bo, WANG Zhi-liang, LI Zi-mu, ZHANG Hui, YANG Jia-hai, WU Cheng-nan01 Institute for Network Science and Cyberspace & BNRist,Tsinghua University,Beijing 100084,China ;2 State Grid Shanghai Electric Power Company,Shanghai 200122,China ;3 State Grid Shanghai Electric Power Research Institute,Shanghai 200437,China ;4 Songjiang Power Supply Company of State Grid Shanghai Municipal Electric Power Company,Shanghai 201699,ChinaPower system network is one of the important targets of cyber attack.In order to ensure the safe operation of power system,network managers need to evaluate the network security risk.Usually,existing network security risk assessment framework only aims at a single scenario,and can not find the strategic attackers who use a variety of low-risk methods to achieve high-risk threat targets from large quantities of network security alerts.In order to meet the above challenges,this paper proposes a network security risk assessment method based on tactical correlation.In this method,the warning information generated on va-rious network security detection devices when an attacker implements a multi-step attack is associated to form an attack chain,and the security risk of the organization intranet is evaluated by calculating the threat,vulnerability,impact score of each node in the attack chain and the risk score of the whole attack chain.In order to verify the effectiveness and robustness of the proposed method,this paper selects a representative example to illustrate the specific implementation process of the proposed method for network security risk assessment in the organizational intranet.The example shows that the network security risk assessment framework based on the tactical association can correctly assess the harm of multi-step attack caused by low-risk alarm association to achieve high-risk targets,and is more robust than the traditional single scenario analysis method,which can better provide decision-making basis for organization decision-makers in network security risk management.https://www.jsjkx.com/fileup/1002-137X/PDF/1002-137X-2022-49-9-306.pdfnetwork security|advanced persistent threat(apt)|risk assessment|tactical correlation|risk management
spellingShingle LIU Jie-ling, LING Xiao-bo, ZHANG Lei, WANG Bo, WANG Zhi-liang, LI Zi-mu, ZHANG Hui, YANG Jia-hai, WU Cheng-nan
Network Security Risk Assessment Framework Based on Tactical Correlation
Jisuanji kexue
network security|advanced persistent threat(apt)|risk assessment|tactical correlation|risk management
title Network Security Risk Assessment Framework Based on Tactical Correlation
title_full Network Security Risk Assessment Framework Based on Tactical Correlation
title_fullStr Network Security Risk Assessment Framework Based on Tactical Correlation
title_full_unstemmed Network Security Risk Assessment Framework Based on Tactical Correlation
title_short Network Security Risk Assessment Framework Based on Tactical Correlation
title_sort network security risk assessment framework based on tactical correlation
topic network security|advanced persistent threat(apt)|risk assessment|tactical correlation|risk management
url https://www.jsjkx.com/fileup/1002-137X/PDF/1002-137X-2022-49-9-306.pdf
work_keys_str_mv AT liujielinglingxiaobozhangleiwangbowangzhilianglizimuzhanghuiyangjiahaiwuchengnan networksecurityriskassessmentframeworkbasedontacticalcorrelation