2007 IEEE POWER ENGINEERING SOCIETY GENERAL MEETING, VOLS 1-10(2007)
Iowa State Univ Sci & Technol
被引用198|浏览8
摘要
By penetrating the SCADA system, an intruder may remotely operate a power system using supervisory control privileges. Hence, cybersecurity has been recognized as a major threat due to the potential intrusion to the online system. This paper proposes a methodology to evaluate the cybersecurity vulnerability using attack trees. The attack tree formulation based on power system control networks is used to evaluate the system, scenario, and leaf vulnerabilities. The measure of vulnerabilities in the power system control framework is determined based on existing cybersecurity conditions before the vulnerability indices are evaluated. After the indices are evaluated, an upper bound is imposed on each scenario vulnerability in order to determine the pivotal attack leaves that require countermeasure improvements. The proposed framework can be extended to security investment analysis.
更多
查看译文
关键词
attack tree,cybersecurity,defense systems,power system control,security vulnerability