增强可重构网络物理供应链的安全性:使用AND/OR/QUORUM图重构脆弱攻击路径

Enhancing the security of reconfigurable cyber-physical supply chains: reconstructing vulnerable attack paths using AND/OR/QUORUM graphs

International Journal of Production Research · 2025
被引 0
ABS 3

中文导读

提出一种基于AND/OR/QUORUM图的攻击路径提取与重构方法,自动识别网络物理供应链中最脆弱的攻击路径,并通过加固组件和部署蜜罐技术进行主动防御,实验证明优于传统算法。

Abstract

Cyber-physical supply chains (CPSCs) integrate physical assets with cyber technologies to form connected and intelligent ecosystems. The increasing frequency and sophistication of cyber-attacks on CPSCs have made defence against these threats increasingly complex. A key strategy in this direction is to identify vulnerable attack paths to detect the most endangered components in the CPSC, thereby allowing the development of more effective and attack-resistant countermeasures. We begin by presenting generalised attack graphs with AND, OR, and QUORUM nodes (so-called AOQ graphs), using them to model and counter attacks on CPSC. Then, we develop an efficient path-extraction method that exploits supply chains’ structural dynamics and reconfigurability to find vulnerable attack paths in AOQ graphs. Finally, we reconstruct the most vulnerable paths by hardening components and deploying an innovative honeypot technology – this is a decoy system that imitates assets to distract attackers. Unlike known methods, the proposed methodology automatically extracts the most vulnerable attack paths from the AOQ graphs in polynomial time without human intervention and provides proactive defence against intrusions. This approach has been tested on experimental benchmark problems and a real post-harvest supply chain and has demonstrated its superiority over previously known pathfinding algorithms.

供应链管理网络安全网络物理系统图论攻击路径分析