A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System

Aiming at the risk assessment requirements of typical industrial control systems with integrated architecture of security and safety, we propose an objective and quantitative integrated security and safety assessment scheme based on Fuzzy Analytic Hierarchy Process (FAHP). First, we establish a safe...

Full description

Bibliographic Details
Main Authors: Junpeng Mi, Wenjun Huang, Mengchi Chen, Wei Zhang
Format: Article
Language:English
Published: IEEE 2021-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9461806/
id doaj-15085e1417e9433dab87d3c3aba805d3
record_format Article
spelling doaj-15085e1417e9433dab87d3c3aba805d32021-06-29T23:00:22ZengIEEEIEEE Access2169-35362021-01-019909199093210.1109/ACCESS.2021.30911369461806A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control SystemJunpeng Mi0https://orcid.org/0000-0002-9714-5243Wenjun Huang1Mengchi Chen2Wei Zhang3Department of Control Science and Engineering, Zhejiang University, Hangzhou, ChinaDepartment of Control Science and Engineering, Zhejiang University, Hangzhou, ChinaDepartment of Control Science and Engineering, Zhejiang University, Hangzhou, ChinaDepartment of Industrial Communication Technology, Zhejiang Supcon Technology Company Ltd., Hangzhou, ChinaAiming at the risk assessment requirements of typical industrial control systems with integrated architecture of security and safety, we propose an objective and quantitative integrated security and safety assessment scheme based on Fuzzy Analytic Hierarchy Process (FAHP). First, we establish a safety and security integrated (SSI) architecture for typical industrial control systems with security measures integrated into safety failure modes. On this basis, we establish a hierarchical model of risk assessment with SSI failure mode as an element of the evaluation layer, and then standardize characteristic values of various safety-related heterogeneous index parameters. We design an entropy weight method that uses Grey Relation Analysis (GRA) method to modify the correlation of multiple indicators as a parameter strategy for determining the relative importance of element layer and evaluation layer and then use the membership function method of fuzzy statistical method to obtain the membership degree of hierarchical elements, and finally obtain the failure risk level value of equipment and system by fuzzy comprehensive evaluation. Based on a typical distributed control system, we build an experimental platform to test and verify the risk assessment plan, and compared with expert experience parameter method. The result shows that the scheme takes into account the correlation between indicators which measure the SSI risk level of industrial control system, and the entropy weight method is used to evaluate the risk of industrial control system which can overcome the subjectivity and uncertainty of individual judgment. Furthermore, the quantitative evaluation of system risk is completed by using fuzzy statistical method in the case of industrial control system without prior knowledge, and the idea of this scheme has a wide range of engineering value.https://ieeexplore.ieee.org/document/9461806/Security and safety integratedfuzzy analytic hierarchy processfailure moderisk assessmentgrey relation analysis
collection DOAJ
language English
format Article
sources DOAJ
author Junpeng Mi
Wenjun Huang
Mengchi Chen
Wei Zhang
spellingShingle Junpeng Mi
Wenjun Huang
Mengchi Chen
Wei Zhang
A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System
IEEE Access
Security and safety integrated
fuzzy analytic hierarchy process
failure mode
risk assessment
grey relation analysis
author_facet Junpeng Mi
Wenjun Huang
Mengchi Chen
Wei Zhang
author_sort Junpeng Mi
title A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System
title_short A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System
title_full A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System
title_fullStr A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System
title_full_unstemmed A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System
title_sort method of entropy weight quantitative risk assessment for the safety and security integration of a typical industrial control system
publisher IEEE
series IEEE Access
issn 2169-3536
publishDate 2021-01-01
description Aiming at the risk assessment requirements of typical industrial control systems with integrated architecture of security and safety, we propose an objective and quantitative integrated security and safety assessment scheme based on Fuzzy Analytic Hierarchy Process (FAHP). First, we establish a safety and security integrated (SSI) architecture for typical industrial control systems with security measures integrated into safety failure modes. On this basis, we establish a hierarchical model of risk assessment with SSI failure mode as an element of the evaluation layer, and then standardize characteristic values of various safety-related heterogeneous index parameters. We design an entropy weight method that uses Grey Relation Analysis (GRA) method to modify the correlation of multiple indicators as a parameter strategy for determining the relative importance of element layer and evaluation layer and then use the membership function method of fuzzy statistical method to obtain the membership degree of hierarchical elements, and finally obtain the failure risk level value of equipment and system by fuzzy comprehensive evaluation. Based on a typical distributed control system, we build an experimental platform to test and verify the risk assessment plan, and compared with expert experience parameter method. The result shows that the scheme takes into account the correlation between indicators which measure the SSI risk level of industrial control system, and the entropy weight method is used to evaluate the risk of industrial control system which can overcome the subjectivity and uncertainty of individual judgment. Furthermore, the quantitative evaluation of system risk is completed by using fuzzy statistical method in the case of industrial control system without prior knowledge, and the idea of this scheme has a wide range of engineering value.
topic Security and safety integrated
fuzzy analytic hierarchy process
failure mode
risk assessment
grey relation analysis
url https://ieeexplore.ieee.org/document/9461806/
work_keys_str_mv AT junpengmi amethodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
AT wenjunhuang amethodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
AT mengchichen amethodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
AT weizhang amethodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
AT junpengmi methodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
AT wenjunhuang methodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
AT mengchichen methodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
AT weizhang methodofentropyweightquantitativeriskassessmentforthesafetyandsecurityintegrationofatypicalindustrialcontrolsystem
_version_ 1721354175010308096