电信科学 ›› 2018, Vol. 34 ›› Issue (2): 153-160.doi: 10.11959/j.issn.1000-0801.2018047

• 运营技术广角 • 上一篇    下一篇

电力信息系统云安全风险分析与评估技术

沈亮,王栋,玄佳兴   

  1. 国家电网公司信息通信分公司,北京 100761
  • 修回日期:2018-01-15 出版日期:2018-02-01 发布日期:2018-02-13
  • 作者简介:沈亮(1969-),男,国家电网公司信息通信分公司教授级高级工程师,主要从事电力信息化管理工作。|王栋(1985-),男,国家电网公司信息通信分公司高级工程师,主要从事电力信息安全工作。|玄佳兴(1990-),男,国家电网公司信息通信分公司工程师,主要从事电力信息化工作。

Security risk analysis and evaluation techniques in power information system cloud

Liang SHEN,Dong WANG,Jiaxing XUAN   

  1. State Grid Information and Telecommunication Branch,Beijing 100761,China
  • Revised:2018-01-15 Online:2018-02-01 Published:2018-02-13

摘要:

结合电力行业对云计算技术的应用,针对电力云安全分析与评估方法展开了系统研究,对电力信息系统云环境下的功能实体和业务流程进行全面梳理,通过静态 STRIDE 威胁建模与动态攻击链算法相结合的方式对云平台面临的主要风险进行了分类识别和量化评估,并有针对性地提出了适用于电力云系统的安全防护架构,以促进云计算在电力行业的推广和应用,并为电力信息系统安全可控提供有力的支撑。

关键词: 电力云, 风险分析, 威胁建模, 攻击链

Abstract:

Combining the power industry with cloud computing technology,a systematic study on safety analysis and evaluation methods of the power cloud was carried out.A comprehensive combing on functional entities and business processes of the power information system under the cloud environment was conducted.Through the combination of static STRIDE threat modeling and dynamic attack chain algorithm,the main risks of cloud platform were classified and quantified.A security protection architecture of power cloud system was put forward to promote the popularization and application of cloud computing in the power industry,and to provide a strong support for the safety and control of power information system.

Key words: power cloud, risk analysis, threat modeling, attack chain

中图分类号: 

No Suggested Reading articles found!