Chinese Journal of Network and Information Security ›› 2022, Vol. 8 ›› Issue (3): 1-17.doi: 10.11959/j.issn.2096-109x.2022030

• Comprehensive Review •     Next Articles

Review on security risks of key components in industrial control system

Shijie TANG1,2, Fang YUAN3, Jun LI4, Yong DING5,6, Huiyong WANG7   

  1. 1 School of Computer Science and Information Security, Guilin University of Electronic Technology, Guilin 541004, China
    2 School of Electronic Engineering and Automation, Guilin University of Electronic Technology, Guilin 541004, China
    3 Communications Office of the Ministry of Foreign Affairs, Beijing 100016, China
    4 National Industrial Information Security Development Research Center, Beijing 100040, China
    5 Guangxi Key Laboratory of Cryptography and Information Security, Guilin University of Electronic Technology, Guilin 541004, China
    6 New Network Research Department of Pengcheng Laboratory, Shenzhen 518055, China
    7 School of Mathematics &Computing Science, Guilin University of Electronic Technology, Guilin 541004, China
  • Revised:2022-03-16 Online:2022-06-15 Published:2022-06-01
  • Supported by:
    The National Natural Science Foundation of China(61772150);The National Natural Science Foundation of China(61862012);The National Natural Science Foundation of China(61962012);Pengcheng Laboratory’s Major Task Project(PCL2021A09)

Abstract:

With the rapid development of modern information technology and communication technology, industrial control system has become an important part of national key infrastructure, whose security is related to national strategic security and social stability.The close connection between modern industrial control system and Internet promotes the rapid progress of industrial control technology, meanwhile it brings serious security risks.Since the“Stuxnet” virus incident, attacks on industrial control systems have occurred frequently, which causes huge economic losses to global production enterprises.Besides, it also poses significant impact on the social stability and security to many countries and regions, which has aroused people’s great concern about the security of industrial control systems.Due to the wide variety of automation equipment and proprietary protocols, complex data flow and rapid development in modern industrial control system, it is very difficult to summarize the safety of key components of industrial control.There are few literatures related to this area, and most of them are old and incomplete.To solve the above problems, the mainstream architecture and related components of the current industrial control system were introduced.Then the security vulnerabilities and potential threats in the key industrial control components were analyzed.The attack methods of SCADA control center, programmable logic controller and field equipment were summarized.Furthermore, the preconditions, objects, steps and hazards of the attack in the literature in recent years were also analyzed.The attacks against industrial control network were classified from the perspective of integrity and confidentiality.Finally, the possible development trend of industrial control system attack was given.

Key words: industrial control system, supervisory control and data acquisition, programmable logic controller, attack trend

CLC Number: 

No Suggested Reading articles found!