چارچوب ارزیابی دینامیک ریسک امنیت سایبری برای سیستمهای کنترل صنعتی مبتنی بر SCADA
سیدمهدی حسینی
1
(
دانشجوی دکتری، گروه مهندسی برق، واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران
)
محمدعلی پورمینا
2
(
استاد گروه الکترونیک و مخابرات، واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران
)
احمد فخاریان
3
(
گروه مهندسی برق، واحد قزوین، دانشگاه آزاد اسلامی، قزوین، ایران
)
مهدی خطیر
4
(
استاد گروه الکترونیک و مخابرات، واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران.
)
کلید واژه: ارزیابی ریسک امنیت سایبری, امنیت SCADA سیستمهای کنترل صنعتی, حفاظت زیرساخت حیاتی, یادگیری ماشین, شبکههای بیزین,
چکیده مقاله :
سیستمهای کنترل صنعتی، بهخصوص سیستمهای کنترل نظارتی و اکتساب داده(SCADA) ، نقش محوری در مدیریت زیرساختهای حیاتی دارند. همگرایی روزافزون فناوریهای عملیاتی با شبکههای فناوری اطلاعات، چالشهای امنیتی پیچیدهای را به وجود آورده که در حملاتی چون استاکسنت، حادثه شبکه برق اوکراین و باجافزار کلونیال پایپلاین نمود یافته است. این سیستمها باید قابلیت اطمینان فوقالعادهای با در دسترسبودن بالای ۹۹.۹۹۹٪ و تأخیر کمتر از ۱۰ میلیثانیه برای کنترلرهای منطقی قابل برنامهریزی(PLC)ها داشته باشند. روشهای سنتی ارزیابی ریسک به دلیل ماهیت ایستای خود، قادر به مدلسازی تهدیدات دینامیک، وابستگیهای میان داراییها و تغییرات زمانی در شرایط عملیاتی نیستند. در این پژوهش، چارچوبی پیشرفته برای ارزیابی دینامیک ریسک امنیت سایبری ارائه شده که مخصوص سیستمهای SCADA در محیطهای صنعتی حساس طراحی شده است. این چارچوب هفت مؤلفه یکپارچه دارد، ارزشگذاری مبتنی بر لایهبندی داراییها با ضرایب وزنی تأثیر خسارت، شبکههای بیزین چندلایه و دینامیک برای مدلسازی احتمالاتی تهدیدها، امتیازدهی آفلاین سیستم امتیازدهی آسیبپذیری مشترک (CVSS) و ISO/IEC 18045، ارزیابی ریسک مبتنی بر درخت تصمیم منطبق با استاندارد IEC 62443، کنترلر انتقال حالت ایمن، بهینهسازی نظریه بازی برای استراتژیهای دفاعی و سیستم توصیهگر مبتنی بر الگوریتم جنگل تصادفی (Random Forest). شبیهسازیهای گسترده در نرمافزار MATLAB نشان میدهد که این چارچوب نسبت به روشهای ایستا، کاهش متوسط ۲۸٪ در نمره ریسک تمام داراییها را محقق میکند و نرخ مثبت کاذب را زیر ۵٪ نگه میدارد.
چکیده انگلیسی :
constitute the backbone of critical infrastructure operations worldwide. The increasing convergence of Operational Technology (OT) with Information Technology (IT) networks has created unprecedented cybersecurity challenges, evidenced by sophisticated attacks including Stuxnet (2010), the Ukraine power grid incident (2015), and the Colonial Pipeline ransomware attack (2021). These systems demand exceptional reliability with 99.999% availability and sub-10ms latency for Programmable Logic Controllers. Conventional risk assessment methodologies exhibit significant qualitative limitations due to their static nature and inability to model dynamic threats, asset interdependencies, and temporal variations in operational context. This research introduces an advanced dynamic cybersecurity risk assessment framework specifically designed for SCADA systems in high-sensitivity industrial environments. The framework incorporates seven integrated components: layered asset valuation with damage impact weighting, Multilayer and Dynamic Bayesian Networks for probabilistic threat modeling, offline CVSS and ISO/IEC 18045 scoring mechanisms, decision-tree-based risk assessment aligned with IEC 62443 standards, secure state transition controllers, game-theoretic optimization for adaptive defense strategies, and a Random Forest-based mitigation recommender.
Through comprehensive MATLAB simulations, the framework demonstrates substantial improvements over static baselines, achieving a significant reduction in assessment uncertainty and an average risk score reduction of 28% across all assets, while maintaining false positive rates below 5%.
[1] D Kaur, A Anwar, I Kamwa, S Islam, SM Muyeen. "A Bayesian deep learning approach with convolutional feature engineering to discriminate cyber-physical intrusions in smart grid systems", - IEEE, 2023 - ieeexplore.ieee.org
[2] F. Brancati, D. Mongelli, F. Mariotti P. Lollini. "A cybersecurity risk assessment methodology for industrial automation control systems". volume 24, article number 76, (2025).
[3] C. Alcaraz and S. Zeadally, "Critical infrastructure protection: Requirements and challenges for the 21st century," International Journal of Critical Infrastructure Protection, vol. 8, pp. 53-66, 2015.
[4] National Institute of Standards and Technology (NIST), "Guide to industrial control systems security," NIST Special Publication 800-82 Rev. 3, 2011.
[5] J. P. Farwell and R. Rohozinski, "Stuxnet and the future of cyber war," Survival, vol. 53, no. 1, pp. 23-40, 2011.
[6] R. M. Lee, M. J. Assante, and T. Conway, "Analysis of the cyber attack on the Ukrainian power grid," Electricity Information Sharing and Analysis Center (E-ISAC), 2016.
[7] C. Krauss, "Colonial Pipeline hack reveals critical infrastructure vulnerabilities," The New York Times, May 13, 2021.
[8] National Institute of Standards and Technology (NIST), "Guide for conducting risk assessments," NIST Special Publication 800-30 Rev. 1, 2012.
[9] Y. Cherdantseva, P. Burnap, A. Blyth, P. Eden, K. Jones, H. Soulsby, and K. Stoddart, "A review of cyber security risk assessment methods for SCADA systems," Computers & Security, vol. 56, pp. 1-27, 2016.
[10] W. Wang, Z. Lu, and T. Chen, "Cybersecurity challenges in industrial control systems," International Journal of Critical Infrastructure Protection, vol. 9, pp. 52-80, 2015.
[11] Bhamare, D., Zolanvari, M., Erbad, A., Jain, R., Khan, K. and Meskin, N., 2020. Cybersecurity for industrial control systems: A survey. computers & security, 89, p.101677.
[12] International Organization for Standardization (ISO/IEC), "Information technology -- Security techniques -- Methodology for IT security evaluation," ISO/IEC Standard 18045, 2022.
[13] Hu, C.L., Wang, L., Chen, M.L. and Pei, C., 2024. A real-time interactive decision-making and control framework for complex cyber-physical-human systems. Annual Reviews in Control, 57, p.100938.
[14] Patel, R., 2023. Automated Threat Detection and Risk Mitigation for ICS (Industrial Control Systems) Employing Deep Learning in Cybersecurity Defence. Int. J. Curr. Eng. Technol, 13(06), pp.584-591.
[15] Ali, B.S., Ullah, I., Al Shloul, T., Khan, I.A., Khan, I., Ghadi, Y.Y., Abdusalomov, A., Nasimov, R., Ouahada, K. and Hamam, H., 2024. ICS-IDS: application of big data analysis in AI-based intrusion detection systems to identify cyberattacks in ICS networks. The Journal of Supercomputing, 80(6), pp.7876-7905.
[16] Barua, S., Gao, X., Pasman, H. and Mannan, M.S., 2016. Bayesian network based dynamic operational risk assessment. Journal of Loss Prevention in the Process Industries, 41, pp.399-410.
[17] Almaiah, M.A., Yelisetti, S., Arya, L., Babu Christopher, N.K., Kaliappan, K., Vellaisamy, P., Hajjej, F. and Alkdour, T., 2023. A novel approach for improving the security of IoT–medical data systems using an enhanced dynamic Bayesian network. Electronics, 12(20), p.4316.
[18] Abdulhamid, A., Kabir, S., Ghafir, I. and Lei, C., 2024, January. Reliability Assessment of IoT-enabled Systems using Fault Trees and Bayesian Networks. In International Conference on Advances in Distributed Computing and Machine Learning (pp. 267-277). Singapore: Springer Nature Singapore.