{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T22:47:10Z","timestamp":1776811630983,"version":"3.51.2"},"reference-count":23,"publisher":"European Society of Computational Methods in Sciences and Engineering","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCM"],"published-print":{"date-parts":[[2022,3,28]]},"abstract":"<jats:p>As the SCADA system develops continuously, the dissemination of malicious network behaviors has brought great risk to the normal operation of enterprises, meanwhile resulting in huge economic burden to personal work and life. Therefore, the security reinforcement strategy is crucial to the field of network security management and analysis of the SCADA system. Some researchers have started to investigate on how to minimize the cost of realizing the SCADA system reinforcement strategy. However, the SCADA system administrators are facing a very challenging problem, that\u2019s the reinforcement budget is less than the minimal input of SCADA system security reinforcement. The core of this problem lies on how to choose a subset from massive security reinforcement strategies, so as to minimize the risks from not patching all essential security vulnerabilities within the budget. Based on a deep comparative analysis of existing multi-objective optimization technologies, this paper proposes a multi-objective optimization method based on system attack tree model, and uses Pareto algorithm to solve this problem. The experimental results demonstrate that the Pareto algorithm can effectively make the multi-objective decision in security reinforcement strategy, and can solve practical issues in actual SCADA system security reinforcement practice.<\/jats:p>","DOI":"10.3233\/jcm-215910","type":"journal-article","created":{"date-parts":[[2021,12,21]],"date-time":"2021-12-21T12:58:44Z","timestamp":1640091524000},"page":"697-709","source":"Crossref","is-referenced-by-count":0,"title":["Research on SCADA system security reinforcement method based on distributed Pareto algorithm"],"prefix":"10.66113","volume":"22","author":[{"given":"Hua","family":"Ning","sequence":"first","affiliation":[{"name":"China Academy of Information and Communications Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaijun","family":"Liu","sequence":"additional","affiliation":[{"name":"Beijing University of Posts and Telecommunications, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuan","family":"Li","sequence":"additional","affiliation":[{"name":"Beijing Information Security Assessment Center, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"55691","reference":[{"key":"10.3233\/JCM-215910_ref1","doi-asserted-by":"crossref","unstructured":"Noel S, Jajodia S, O\u2019Berry B, Jacobs M. Efficient minimum-cost network hardening via exploit dependency graphs. In 19th Annual Computer Security Applications Conference, 2003. Proceedings. 2003 Dec 8 (pp. 86-95). IEEE.","DOI":"10.1109\/CSAC.2003.1254313"},{"key":"10.3233\/JCM-215910_ref2","unstructured":"Jha S, Sheyner O, Wing J. Two formal analyses of attack graphs. In Proceedings 15th IEEE Computer Security Foundations Workshop. CSFW-15 2002 Jun 24 (pp. 49-63). IEEE."},{"issue":"3","key":"10.3233\/JCM-215910_ref3","doi-asserted-by":"crossref","first-page":"592","DOI":"10.1016\/j.dss.2004.06.004","article-title":"Matching information security vulnerabilities to organizational security profiles: a genetic algorithm approach","volume":"41","author":"Gupta","year":"2006","journal-title":"Decision Support Systems."},{"issue":"4","key":"10.3233\/JCM-215910_ref4","doi-asserted-by":"crossref","first-page":"469","DOI":"10.1145\/321906.321910","article-title":"On finding the maxima of a set of vectors","volume":"22","author":"Kung","year":"1975","journal-title":"Journal of the ACM (JACM)."},{"key":"10.3233\/JCM-215910_ref5","doi-asserted-by":"crossref","unstructured":"Balke WT, G\u00fcntzer U. Multi-objective query processing for database systems. In Proceedings of the Thirtieth international conference on Very large data bases-Volume 30, 2004 Aug 31 (pp. 936-947).","DOI":"10.1016\/B978-012088469-8.50082-6"},{"issue":"1-3","key":"10.3233\/JCM-215910_ref6","doi-asserted-by":"crossref","first-page":"499","DOI":"10.1016\/j.jmatprotec.2008.01.014","article-title":"Multi-objective optimization of sheet metal forming process using Pareto-based genetic algorithm","volume":"208","author":"Wei","year":"2008","journal-title":"Journal of materials processing technology."},{"key":"10.3233\/JCM-215910_ref7","unstructured":"Borzsony S, Kossmann D, Stocker K. The skyline operator. In Proceedings 17th international conference on data engineering, 2001 Apr 2 (pp.\u00a0421-430). IEEE."},{"key":"10.3233\/JCM-215910_ref8","first-page":"717","article-title":"Skyline with presorting","author":"Chomicki","year":"2003","journal-title":"ICDE"},{"key":"10.3233\/JCM-215910_ref9","doi-asserted-by":"crossref","unstructured":"Tan PN, Kumar V, Srivastava J. Indirect association: Mining higher order dependencies in data. In European Conference on Principles of Data Mining and Knowledge Discovery, 2000 Sep 13 (pp. 632-637). Springer, Berlin, Heidelberg.","DOI":"10.1007\/3-540-45372-5_77"},{"key":"10.3233\/JCM-215910_ref10","first-page":"229","article-title":"Maximal vector computation in large data sets","author":"Godfrey","year":"2005","journal-title":"VLDB"},{"key":"10.3233\/JCM-215910_ref11","first-page":"145","article-title":"Mining indirect associations in web data","author":"Tan","year":"2001","journal-title":"International Workshop on Mining Web Log Data Across All Customers Touch Points"},{"key":"10.3233\/JCM-215910_ref12","doi-asserted-by":"crossref","unstructured":"Lin Q, Zhang Y, Zhang W, Li A. General spatial skyline operator. In International Conference on Database Systems for Advanced Applications 2012 Apr 15 (pp. 494-508). Springer, Berlin, Heidelberg.","DOI":"10.1007\/978-3-642-29038-1_36"},{"issue":"1","key":"10.3233\/JCM-215910_ref13","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1145\/1061318.1061320","article-title":"Progressive skyline computation in database systems","volume":"30","author":"Papadias","year":"2005","journal-title":"ACM Transactions on Database Systems (TODS)."},{"issue":"9","key":"10.3233\/JCM-215910_ref14","doi-asserted-by":"crossref","first-page":"1222","DOI":"10.1080\/0305215X.2013.832237","article-title":"Flower pollination algorithm: a novel approach for multiobjective optimization","volume":"46","author":"Yang","year":"2014","journal-title":"Engineering optimization."},{"issue":"1","key":"10.3233\/JCM-215910_ref15","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1007\/s11280-011-0122-8","article-title":"Finding superior skyline points for multidimensional recommendation applications","volume":"15","author":"Yang","year":"2012","journal-title":"World Wide Web."},{"key":"10.3233\/JCM-215910_ref16","doi-asserted-by":"crossref","unstructured":"Chan CY, Eng PK, Tan KL. Stratified computation of skylines with partially-ordered domains. In Proceedings of the 2005 ACM SIGMOD international conference on Management of data, 2005 Jun 14 (pp. 203-214).","DOI":"10.1145\/1066157.1066181"},{"key":"10.3233\/JCM-215910_ref17","doi-asserted-by":"crossref","unstructured":"Ammann P, Wijesekera D, Kaushik S. Scalable, graph-based network vulnerability analysis. In Proceedings of the 9th ACM Conference on Computer and Communications Security, 2002 Nov 18 (pp. 217-224).","DOI":"10.1145\/586110.586140"},{"key":"10.3233\/JCM-215910_ref18","unstructured":"Sheyner O, Haines J, Jha S, Lippmann R, Wing JM. Automated generation and analysis of attack graphs. In Proceedings 2002 IEEE Symposium on Security and Privacy, 2002 May 12 (pp. 273-284). IEEE."},{"issue":"12","key":"10.3233\/JCM-215910_ref19","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s Journal."},{"key":"10.3233\/JCM-215910_ref20","first-page":"231","article-title":"Using attack trees to identify malicious attacks from authorized insiders","author":"Ray","year":"2005","journal-title":"European Symposium on Research in Computer Security"},{"key":"10.3233\/JCM-215910_ref21","doi-asserted-by":"crossref","unstructured":"Kordy B, Pouly M, Schweitzer P. Computational aspects of attack\u2013defense trees. InInternational Joint Conferences on Security and Intelligent Information Systems, 2011 Jun 13 (pp. 103-116). Springer, Berlin, Heidelberg.","DOI":"10.1007\/978-3-642-25261-7_8"},{"issue":"1-2","key":"10.3233\/JCM-215910_ref22","doi-asserted-by":"crossref","first-page":"5","DOI":"10.3233\/JCS-2002-101-202","article-title":"Toward cost-sensitive modeling for intrusion detection and response","volume":"10","author":"Lee","year":"2002","journal-title":"Journal of computer security."},{"key":"10.3233\/JCM-215910_ref23","doi-asserted-by":"crossref","unstructured":"Butler SA. Security attribute evaluation method: a cost-benefit approach. In Proceedings of the 24th international conference on Software engineering, 2002 May 19 (pp. 232-240).","DOI":"10.1145\/581339.581370"}],"container-title":["Journal of Computational Methods in Sciences and Engineering"],"original-title":[],"link":[{"URL":"https:\/\/content.iospress.com\/download?id=10.3233\/JCM-215910","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T22:06:46Z","timestamp":1776809206000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/full\/10.3233\/JCM-215910"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,28]]},"references-count":23,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.3233\/jcm-215910","relation":{},"ISSN":["1472-7978","1875-8983"],"issn-type":[{"value":"1472-7978","type":"print"},{"value":"1875-8983","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,28]]}}}