期刊文献+

基于混合测试的工控系统攻击测试模拟方法研究 被引量:3

Research on attack test simulation method of industrial control system based on hybrid testing
下载PDF
导出
摘要 近些年工业控制系统逐步向通用化、标准化发展,原有封闭性和专有性被打破,造成易被攻击,各种渗透、病毒、木马等安全威胁向工控领域迅速扩散,导致了日益严重的信息安全问题。文章结合渗透测试技术,在传统网络攻击测试模拟基础上,设计并实现工控系统攻击测试模拟方法。该方法包含三个功能:一是提出一种基于攻击期望的攻击路径生成算法;二是实现基于白盒和黑盒测试的漏洞攻击测试模拟;三是结合工业以太网基于特征码进行请求应答通信的特征,对工控设备进行信息探测。这种方法具有三个优势:从不同角度提供工控系统攻击试验模拟;无需对攻击建模分析;系统操作简单。实验结果显示,与传统探测工具相比,基于该方法实现的系统检测率更高。 In recent years,industrial control systems have gradually developed towards generalization and standardization.The original closeness and exclusiveness have been broken,which makes them vulnerable to attack.Various security threats such as penetration,virus and Trojan horse have spread rapidly to the field of industrial control,resulting in increasingly serious information security problems.Based on penetration test technology and traditional network attack test simulation,this paper designs and implements an attack test simulation method for industrial control system.This method includes three functions:one is to propose an attack path generation algorithm based on attack expectation;the other is to realize vulnerability test simulation based on white-box and black-box test;the third is to detect the information of industrial control equipment by combining the characteristics of industrial Ethernet based on signature-based request-response communication.This method has three advantages:providing attack test simulation of industrial control system from different angles;no need for attack modeling and analysis;and simple operation of the system.The experimental results show that the detection rate of the system based on this method is higher than that of the traditional detection tools.
作者 段涛 向军 张宏 李千目 Duan Tao;Xiang Jun;Zhang Hong;Li Qianmu(School of Computer Science and Technology,Nanjing University of Science and Technology,JiangsuNanjing 210094;Shanghai Aerospace Computer and Technology Institute,Shanghai 200050;Jiangsu Zhongtian Technolgy Co.,Ltd.,JiangsuNantong 226463)
出处 《网络空间安全》 2019年第3期8-22,共15页 Cyberspace Security
基金 中央财政高校基础研究基金(项目编号:30918012204) 江苏省重点研发项目(项目编号:BE2017739) 上海航天科技创新基金(项目编号:SAST2018-103)
关键词 工业控制系统 测试模拟 白盒测试 黑盒测试 industrial control system test simulation white box test black box test
  • 相关文献

同被引文献17

引证文献3

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部