跳到主要导航 跳到搜索 跳到主要内容

ICT Supply Chain Security Evaluation Model Based on Bayesian Attack Graph

  • Xiao Zhou Wang
  • , Sheng Hong
  • , Jun Zhang
  • , Jiacheng Wang
  • , Lin Lin
  • , Yuanjun Ji
  • , Tong Liu
  • , Zun Wang*
  • *此作品的通讯作者
  • China Mobile Communications Group Co., Ltd.
  • Ltd.
  • Beihang University
  • China Mobile Group Design Institute Co., Ltd.
  • Ltd
  • Ministry of Industry and Information Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

With the fast development of technology, the importance of ICT (Information and Communication Technology) product supply chains in production and daily life is growing and becoming a bigger market. Given the differences that exist between traditional and ICT product supply chains, security issues relating to ICT product supply chains have been increasingly coming to the fore. This paper proposes an ICT supply chain security assessment model based on Bayesian attack graphs. The model begins by analyzing the ICT supply chain to identify potential vulnerabilities and establishing an attack graph. Once the attack graph model structure is constructed, Bayesian theory is applied for quantification. A quantitative evaluation index for ICT supply chain threats is established based on the difficulty of exploiting vulnerabilities and their impact level. The corresponding atomic attack probabilities are calculated and linked to the ICT supply chain's security attribute nodes in the form of conditional transition probabilities. This approach not only infers the risk probability of an attacker successfully reaching various attribute nodes but also dynamically updates the changes in risk status based on observed attack behaviors. This enables the assessment of the overall risk status of the target supply chain under different conditions.

源语言英语
主期刊名Proceedings - 2025 3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025
出版商Institute of Electrical and Electronics Engineers Inc.
407-413
页数7
ISBN(电子版)9798331535858
DOI
出版状态已出版 - 2025
活动3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025 - Dongguan, 中国
期限: 11 4月 202514 4月 2025

出版系列

姓名Proceedings - 2025 3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025

会议

会议3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025
国家/地区中国
Dongguan
时期11/04/2514/04/25

指纹

探究 'ICT Supply Chain Security Evaluation Model Based on Bayesian Attack Graph' 的科研主题。它们共同构成独一无二的指纹。

引用此