网络与信息安全学报 ›› 2022, Vol. 8 ›› Issue (3): 1-17.doi: 10.11959/j.issn.2096-109x.2022030

• 综述 •    下一篇

工业控制系统关键组件安全风险综述

唐士杰1,2, 袁方3, 李俊4, 丁勇5,6, 王会勇7   

  1. 1 桂林电子科技大学计算机与信息安全学院,广西 桂林 541004
    2 桂林电子科技大学电子工程与自动化学院,广西 桂林 541004
    3 外交部通信总台,北京 100016
    4 国家工业信息安全发展研究中心,北京 100040
    5 桂林电子科技大学广西密码学与信息安全重点实验室,广西 桂林 541004
    6 鹏城实验室新型网络研究部,广东 深圳 518055
    7 桂林电子科技大学数学与计算科学学院,广西 桂林 541004
  • 修回日期:2022-03-16 出版日期:2022-06-15 发布日期:2022-06-01
  • 作者简介:唐士杰(1980− ),女,广西灌阳人,桂林电子科技大学讲师,主要研究方向为工控安全
    袁方(1980− ),男,江苏沛县人,外交部通信总台高级工程师,主要研究方向为专用通信建设、信息化应用、信息安全、密码应用、网络安全
    李俊(1986− ),男,江西吉安人,国家工业信息安全发展研究中心高级工程师,主要研究方向为工控安全、工业互联网安全、新一代信息技术安全
    丁勇(1975− ),男,四川潼南人,桂林电子科技教授、博士生导师,主要研究方向为网络信息安全、工控安全、密码学
    王会勇(1977− ),男,山东诸城人,桂林电子科技副教授,主要研究方向为网络信息安全与隐私保护
  • 基金资助:
    国家自然科学基金(61772150);国家自然科学基金(61862012);国家自然科学基金(61962012);鹏城实验室重大任务项目(PCL2021A09)

Review on security risks of key components in industrial control system

Shijie TANG1,2, Fang YUAN3, Jun LI4, Yong DING5,6, Huiyong WANG7   

  1. 1 School of Computer Science and Information Security, Guilin University of Electronic Technology, Guilin 541004, China
    2 School of Electronic Engineering and Automation, Guilin University of Electronic Technology, Guilin 541004, China
    3 Communications Office of the Ministry of Foreign Affairs, Beijing 100016, China
    4 National Industrial Information Security Development Research Center, Beijing 100040, China
    5 Guangxi Key Laboratory of Cryptography and Information Security, Guilin University of Electronic Technology, Guilin 541004, China
    6 New Network Research Department of Pengcheng Laboratory, Shenzhen 518055, China
    7 School of Mathematics &Computing Science, Guilin University of Electronic Technology, Guilin 541004, China
  • Revised:2022-03-16 Online:2022-06-15 Published:2022-06-01
  • Supported by:
    The National Natural Science Foundation of China(61772150);The National Natural Science Foundation of China(61862012);The National Natural Science Foundation of China(61962012);Pengcheng Laboratory’s Major Task Project(PCL2021A09)

摘要:

随着现代信息技术与通信技术的快速发展,工业控制(简称“工控”)系统已经成为国家关键基础设施的重要组成部分,其安全性关系到国家的战略安全和社会稳定。现代工控系统与互联网越来越紧密的联系,一方面促进了工控技术的快速进步,另一方面为其带来了巨大安全问题。自“震网”病毒事件之后,针对工控系统的攻击事件频发,给全球生产企业造成了巨大经济损失,甚至对很多国家和地区的社会稳定与安全造成重大影响,引起人们对工控系统安全的极大关注。现代工控系统中自动化设备品类和专有协议种类繁多、数据流复杂且发展迅速等,导致对工控关键组件安全的综述难度很大,现有与此相关的综述性文献较少,且大多较为陈旧、论述不全面。针对上述问题,介绍了当前工控系统的主流体系结构和相关组件。阐述并分析了关键工控组件中存在的安全漏洞及潜在的威胁,并重点针对数据采集与监视控制(SCADA)中的控制中心、可编程逻辑控制器、现场设备的攻击方法进行归纳、总结,对近几年文献中实施攻击的前提条件、攻击的对象、攻击的实施步骤及其危害性进行了归纳与分析,并从可用性、完整性和机密性的角度对针对工控网络的攻击进行了分类。给出了针对工控系统攻击的可能发展趋势。

关键词: 工控系统, 数据采集与监视控制, 可编程逻辑控制器, 攻击趋势

Abstract:

With the rapid development of modern information technology and communication technology, industrial control system has become an important part of national key infrastructure, whose security is related to national strategic security and social stability.The close connection between modern industrial control system and Internet promotes the rapid progress of industrial control technology, meanwhile it brings serious security risks.Since the“Stuxnet” virus incident, attacks on industrial control systems have occurred frequently, which causes huge economic losses to global production enterprises.Besides, it also poses significant impact on the social stability and security to many countries and regions, which has aroused people’s great concern about the security of industrial control systems.Due to the wide variety of automation equipment and proprietary protocols, complex data flow and rapid development in modern industrial control system, it is very difficult to summarize the safety of key components of industrial control.There are few literatures related to this area, and most of them are old and incomplete.To solve the above problems, the mainstream architecture and related components of the current industrial control system were introduced.Then the security vulnerabilities and potential threats in the key industrial control components were analyzed.The attack methods of SCADA control center, programmable logic controller and field equipment were summarized.Furthermore, the preconditions, objects, steps and hazards of the attack in the literature in recent years were also analyzed.The attacks against industrial control network were classified from the perspective of integrity and confidentiality.Finally, the possible development trend of industrial control system attack was given.

Key words: industrial control system, supervisory control and data acquisition, programmable logic controller, attack trend

中图分类号: 

No Suggested Reading articles found!