网络与信息安全学报 ›› 2017, Vol. 3 ›› Issue (1): 46-53.doi: 10.11959/j.issn.2096-109x.2017.00139

• 学术论文 • 上一篇    下一篇

乌克兰电力系统BlackEnergy病毒分析与防御

王勇,王钰茗(),张琳,张林鹏   

  1. 上海电力学院计算机科学与技术学院,上海 200090
  • 修回日期:2016-12-30 出版日期:2017-01-15 发布日期:2020-03-20
  • 作者简介:王勇(1973-),男,河南驻马店人,博士,上海电力学院教授,主要研究方向为电力系统攻防试验床、病毒分析、入侵检测。|王钰茗(1994-),女,山东烟台人,上海电力学院本科生,主要研究方向为病毒分析。|张琳(1995-),女,黑龙江绥化人,上海电力学院本科生,主要研究方向为病毒分析。|张林鹏(1991-),男,河北邢台人,上海电力学院硕士生,主要研究方向为电力系统防火墙。
  • 基金资助:
    上海科委地方能力建设基金资助项目(15110500700);上海市浦江人才计划基金资助项目(16PJ1433100);上海自然科学基金资助项目(16ZR1436300);上海科委中小企业创新基金资助项目(1601H1E2600)

Analysis and defense of the BlackEnergy malware in the Ukrainian electric power system

Yong WANG,Yu-ming WANG(),Lin ZHANG,Lin-peng ZHANG   

  1. School of Computer Science and Technology, Shanghai University of Electric Power, Shanghai 200090, China
  • Revised:2016-12-30 Online:2017-01-15 Published:2020-03-20
  • Supported by:
    The Project of Shanghai Science and Technology Committee(15110500700);Shanghai Pujiang Program(16PJ1433100);Shanghai Municipal Natural Science Foundation(16ZR1436300);Shanghai Science and TechnologyInnovation Fund for Small and Medium Enterprises(1601H1E2600)

摘要:

2015年12月,乌克兰电力系统遭到BlackEnergy病毒攻击,导致伊万诺—弗兰科夫斯克州地区发生多处同时停电的事故,该病毒也威胁到我国电力系统安全。通过获取不同版本的BlackEnergy病毒样本,构建了分析环境,发现了BlackEnergy攻击方式,并给出了防御方法。

关键词: BlackEnergy病毒, 病毒分析, 入侵防御

Abstract:

Ukrainian electric power system suffered BlackEnergy virus attacks in December 2015, resulting in blackout accident occurred simultaneously at multiple areas in Ivano-Frankovsk region, the malware also pose a threat to the electric power system security in China. Based on different versions of samples of BlackEnergy acquired, the attack mode was analyzed and the prevention of the virus was provided under the proper analysis environment.

Key words: BlackEnergy virus, virus analysis, intrusion prevention

中图分类号: 

No Suggested Reading articles found!