• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

Cyber security assessment for SCADA systems
based on attackdefense game model

HUANG Hui-ping,XIAO Shi-de,MENG Xiang-yin   

  1. (College of Mechanical Engineering,Southwest Jiaotong University,Chengdu 610031,China)
  • Received:2015-08-27 Revised:2016-03-21 Online:2017-05-25 Published:2017-05-25

Abstract:

SCADA system cyber security assessment is an important basic work to ensure the reliable work of the system. Existing evaluation methods do not take the mutual influence between the attacker and the defender and the economic effect into account. In order to solve this problem, we propose an assessment method based on attack defense tree and game theory. Based on the attack defense tree, this method calculates the expected payoff function of the attacker and the defender, and establishes the system's attack and defense game model. The mixed strategy Nash equilibrium of the complete information static game model is solved, and the probability distribution of the attack and defense strategy is obtained. We describe the application of the method in a case study. The evaluation results show that the method is reasonable and feasible, which can help risk managers to evaluate the investment benefit of the existing system information security and defense measures. So they can deploy the defensive measures focusing on some particular attack events to achieve maximum return of investment.

Key words: SCADA system, cyber security, attack defense tree, game theory, payoffs function