期刊文献+

工业以太网PROFINET安全隔离器的设计 被引量:4

Design of PROFINET Security Isolator of Industrial Ethernet
下载PDF
导出
摘要 随着智能制造技术的发展,工业控制网络的安全问题日益突出。基于工业通信网络诊断、隔离和安全防护技术,以应用前景广泛的PROFINET工业以太网为研究对象,设计了基于PROFINET的专用工业网络安全隔离器。安全隔离器主要作用于工业网络内部,具有通用的工业网络层防火墙功能。对PROFINET通信协议进行了深度解析,并识别相应的报文类型与关键数据。通过配置安全策略,并将其传输到安全隔离器,可以实时监控网络状态和PROFINET关键数据,阻断异常畸形报文,同时可以防止未授权设备的非法访问。针对以上情形产生的报警信息,将被实时发送到配置管理平台并进行报警显示。经测试表明,工业网络安全隔离器对正常工业控制网络无影响。配置策略可有效保护关键设备,从而保护工业控制网络的安全。 With the in-depth development of intelligent manufacturing technology,the security problem industrial control network is becoming more and more prominent. Based on the technologies of industrial communication network diagnosis,isolation,and security protection,with the most widely used PROFINET industrial Ethernet as the research object,the dedicated industrial network security isolator is designed based on PROFIBUS. Security isolator is mostly acting inside the industrial network,and offers generic industrial network layer firewall function. PROFINET communication protocol is deeply analyzed,and message types and key data are diagnosed and recognized. Through configuring the safety strategy on the configuration management platform,and transmitting the safety strategy to security isolator,network status and the critical data of PROFINET can be monitored in real-time,while the abnormal and malformed messages can be blocked,and the illegal access from unauthorized devices can also be prevented. The alarm information generated from above situation is sent to the configuration management platform in real time for alarm display. Tested,the industrial network security isolator has no influence on the normal industrial control network,and the key devices can be effectively protected by configuration strategy,thus the security of industrial control network can be protected.
出处 《自动化仪表》 CAS 2017年第7期46-49,53,共5页 Process Automation Instrumentation
基金 科技部转制科研院所创新能力专项基金资助项目(2014EG119050)
关键词 工业控制网络 PROFINET 通信协议 网络层防火墙 安全隔离器 Industrial control network PROFINET Communication protocol Network layer firewall Security isolator
  • 相关文献

参考文献8

二级参考文献216

  • 1彭杰,应启戛.工业以太网的安全性研究[J].仪器仪表学报,2004,25(z1):516-517. 被引量:10
  • 2彭杰,应启戛.工业控制网络安全问题分析[J].仪器仪表学报,2003,24(z2):338-339. 被引量:2
  • 3陈星,贾卓生.工业控制网络的信息安全威胁与脆弱性分析与研究[J].计算机科学,2012,39(S2):188-190. 被引量:29
  • 4康军,戴冠中.工业以太网控制系统安全性问题研究[J].信息与控制,2007,36(2):245-249. 被引量:9
  • 5高国辉.西门子被曝工业系统漏洞或影响多数工业化国家[N].南方日报.2011-6-8.
  • 6NIST SP800-82.Guide to Industrial Control Systems(ICS)Security[S].Gaithersburg,USA:National Institute of Standards and Technology(NIST),2011.
  • 7Simon H A.The architecture of complexity[C] //Proceedings of the American Philosophical Society.Philadelphia,USA:Batsford,1962:467-482.
  • 8Bishop M.Computer Security[M].Boston,USA:Addison Wesley,2003.
  • 9Department of Homeland Security(DHS).Cyber Security Assessments of Industrial Control System[S].Washington DC,USA:Department of Homeland Security(DHS),2010.
  • 10The European Network and Information Security Agency(ENISA).Protecting Industrial Control Systems,Recommendations for Europe and Member States[R].Heraklion,Greece:Recommendations for Europe and Member States,2011.

共引文献261

同被引文献22

引证文献4

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部