期刊文献+

基于组合扫描的无状态工控设备资产探测方法

Stateless Industrial Control Equipment Asset Detection Method Based on Combined Scanning
下载PDF
导出
摘要 全面探测工控设备资产信息、了解资产状态是确保工业控制系统安全的重要前提。端口探活是进行资产探测的第一步,端口探活的准确率和效率将直接影响资产探测的性能。为提升端口探活的速度和准确性,提出了一种基于组合扫描的异步无状态端口扫描方法。通过构造组合扫描数据包,解决工控设备因禁ping导致主机探活准确率降低的问题,同时建立发送数据包线程和接收数据包线程,实现组合扫描数据包的异步处理,消除了传统无状态扫描的回复等待时间,缩短了端口探活时间。最后以Modbus协议为例,构造了资产请求数据包,并分析了数据包中主要字段和功能。测试结果表明,提出的资产探测方法在端口探活阶段单位时间内可以探测到更多的设备,同时能在较短的时间内完成完整资产信息的探测,在探测准确度和探测时间方面都得到了提升。 Comprehensive detection of the asset information of industrial control equipment and understanding the asset status is an important prerequisite to ensure the safety of industrial control system.Port detection is the first step of asset detection.The accuracy and efficiency of port detection will directly affect the performance of asset detection.In order to improve the speed and accuracy of port detection,an asynchronous stateless port scanning method based on combined scanning is proposed.By constructing combined scanning data packets,the problem that the accuracy rate of host detection is reduced due to the prohibition of Ping in industrial control equipment is solved.At the same time,a sending packet thread and a receiving packet thread are established to realize asynchronous processing of combined scanning packets,which eliminates the reply waiting time of traditional stateless scanning and shortens the port detection time.Finally,taking Modbus protocol as an example,the asset request data packet is constructed,and the main fields and functions in the data packet are analyzed.The test results show that the proposed asset detection method can detect more equipment per unit time in the port detection stage,and complete the detection of complete asset information in a shorter time,which improves the detection accuracy and detection time.
作者 郑铁军 王齐 张宏杰 贺建伟 雍少华 孙知信 ZHENG Tie-jun;WANG Qi;ZHANG Hong-jie;HE Jian-wei;YONG Shao-hua;SUN Zhi-xin(State Grid Ningxia Electric Power Co.,Ltd.,Yinchuan 750010,China;State Grid Smart Grid Research Institute Co.,Ltd.,Nanjing 210003,China;State Grid Key Laboratory of Information&Network Security,Nanjing 210003,China;State Grid Zhongwei Electric Power Supply Company,Zhongwei 755099,China;School of Modern Posts,Nanjing University of Posts and Telecommunications,Nanjing 210003,China)
出处 《计算机技术与发展》 2023年第7期98-103,共6页 Computer Technology and Development
基金 宁夏自然科学基金项目(2022AAC03613)。
关键词 工业控制系统 资产探测 工控设备 端口扫描 异步处理 industrial control system asset detection industrial control equipment port scanning asynchronous processing
  • 相关文献

参考文献4

二级参考文献46

共引文献23

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部