基于CLPN的系统安全性分析方法OA北大核心CSTPCD
System Security Analysis Method Based on CLPN
随着安全性攸关系统的智能化、自动化发展,系统规模和复杂度急剧增加,传统基于链式/树式安全性因果模型的安全性分析方法在非线性致危因素、非失效致危因素分析方面存在很大的局限性,现代基于系统理论的安全性因果模型虽然在航空航天、核电能源等多个领域得到有效性验证,但目前该类方法尚缺乏严格统一的分析步骤和自动化分析工具.为此,提出复杂系统控制过程的建模工具——控制逻辑Petri网(CLPN),对控制过程中的活动及其之间的交互影响关系进行形式化描述,并对系统CLPN模型的可达图进行失效扩展,在不影响安全性分析的前提下尽量避免因失效事件建模造成的分析模型规模激增.基于CLPN模型,以系统理论事故模型与过程(STAMP)系统安全性因果模型危险因素分类为标准,在可达性分析的基础上对作为系统致危因素的危险控制活动进行探索,实现系统安全性的自动化分析.最后,通过实例分析和方法对比,对所提方法的可用性和有效性进行验证.实验结果表明,基于CLPN的系统安全性分析方法在结果完备性和分析效率方面具有较大的优势.
With the development of intelligent and automated safety critical systems,the scale and complexity of these systems have increased significantly.Traditional security analysis methods based on chain/tree safety causal models have major limitations in terms of their ability to analyze nonlinear and non-failure hazardous factors.Although modern safety causal models based on system theory have been effectively validated in multiple fields such as aerospace and nuclear energy,these methods currently lack strict and unified analytical steps and automated analytical tools.Accordingly,this study proposes a modeling tool for complex system control processes called Control Logic Petri Net(CLPN)to formalize the activities and their interactive relationships in the control process and to extend the reachability graph of the CLPN model.To the greatest extent possible,the latter prevents analysis model increase caused by failure event modeling without affecting security analysis.Based on the CLPN model and using the System Theory Accident Model and Process(STAMP)system safety causal model as the standard for hazard factor classification,the study then explores hazard control activities,which serve as system hazards based on accessibility analysis,and achieves automated analysis of system safety.Finally,the study employs case analysis and method comparison to verify the usability and effectiveness of the proposed method.Experimental results show that the proposed system security analysis method based on CLPN has significant advantages in terms of the completeness of the results and analysis efficiency.
余新胜;朱丹江;罗论涵
中国电子科技集团公司第三十二研究所,上海 201808
计算机与自动化
Petri网系统安全性安全性分析系统理论事故模型与过程控制逻辑Petri网
Petri netsystem securitysecurity analysisSystem Theory Accident Model and Process(STAMP)Control Logic Petri Net(CLPN)
《计算机工程》 2024 (010)
255-265 / 11
国家重点研发计划(2022YFB3104300).
评论