论文部分内容阅读
结合电力控制过程的信息安全风险评估是目前尚未妥善解决的问题,缺乏符合电力信息系统特点的资产识别方法是其中的主要因素之一。网络环境下变电站自动化系统属于典型的电力信息系统,在分析该系统资产识别难点的基础上,从资产分类、业务识别和资产赋值等3个方面提出完整的信息资产识别方法。在资产分类问题上,结合IEC61850标准,将实际的智能电子设备与虚拟的逻辑节点结合,定义结构化的资产模型;在业务识别问题上,以变电站自动化功能作为业务识别的对象,定义功能图的概念来反映功能与资产以及资产之间的逻辑关系;在资产赋值问题上,分别定义了功能级和变电站级2个层次的资产价值,来量化资产在信息安全属性上的达成程度和信息安全价值未达成时可能造成的事故影响。最后,基于IEC61850标准构建了分析实例,验证了资产识别方法的有效性。
Information security risk assessment combined with power control process is not yet a proper solution to the problem. The lack of asset identification method that is consistent with the characteristics of power information system is one of the main factors. Substation automation system is a typical power information system under network environment. Based on the analysis of the system’s asset identification difficulties, a complete information asset identification method is proposed from three aspects: asset classification, business identification and asset assignment. In terms of asset classification, combined with the IEC61850 standard, the actual intelligent electronic devices are combined with virtual logical nodes to define a structured asset model. On the problem of business identification, the function of substation automation is taken as the object of business identification, and the function diagram Concept to reflect the logical relationship between function and assets and assets. On asset assignment, two levels of asset value are defined respectively at function level and substation level to quantify the degree of achievement of asset security and information security value The possible accident impact if not reached. Finally, based on the IEC61850 standard, an analysis example is constructed to verify the effectiveness of the asset identification method.