TY - JOUR PY - 2019// TI - Quantitative risk assessment method for information security of SCADA systems JO - China safety science journal (CSSJ) A1 - Xiong, W. A1 - Jin, J. A1 - Tang, J. SP - 157 EP - 163 VL - 29 IS - 8 N2 - In order to effectively analyze and assess information security risk of SCADA systems and solve the problem of quantifying information security risk which is difficult for traditional methods. Firstly, three elements, threat, vulnerability and assets, were confirmed based on information safety risk evaluation model, and possible threats, vulnerability and assets were obtained through analyzing and deconstructing typical SCADA system structure. Secondly, AHP was used to determine the influence extent of different elements on SCADA systems. Then the judgment matrix and combination weight of the three elements to security risk were studied and threat-vulnerability-asset were combined and compared to obtain relatively quantifiable and comparable risk parameters. Finally, the method was applied to assess information security risk of a typical SCADA system.

RESULTS show that AHP has good operability in identifying weak points in system information security, and hierarchical construction can clearly show the internal relationship of a complex SCADA system, the finer the hierarchy is, the more accurate analysis would be, but overelaborate construction may lead to heavy dependence on experts' experience. © 2019 China Safety Science Journal

Language: zh

LA - zh SN - 1003-3033 UR - http://dx.doi.org/10.16265/j.cnki.issn1003-3033.2019.08.025 ID - ref1 ER -