期刊文献+

工控协议安全研究综述

Survey on industrial control protocol security research
下载PDF
导出
摘要 工控协议安全是保障ICS稳定运行的关键,大量工控协议在设计阶段忽视了对安全性的考量,导致目前大部分主流工控协议普遍存在脆弱性问题。结合ICS架构和工控协议的发展特征,深入解析目前工控协议普遍面临的脆弱性问题和攻击威胁。同时,针对工控协议的潜在漏洞,深入分析基于静态符号执行、代码审计和模糊测试等工控协议漏洞挖掘技术,并从工控协议的规范设计、通信机制以及第三方中间件3个方面全面剖析协议设计的安全防护技术。另外,从沙箱研制、安全防护及漏洞挖掘等方面,对工控协议安全的未来发展趋势进行展望。 The security of industrial control protocol is the cornerstone to ensure ICS’s stable operation,a large number of industrial control protocols in the design phase ignore the consideration of security,resulting in most of the mainstream industrial control protocols generally having vulnerabilities.Considering the ICS architecture and the developmental characteristics of industrial control protocols,the various vulnerabilities and attack threats commonly faced by industrial control protocols were systematically summarized.At the same time,for the unknown potential vulnerabilities of industrial control protocols,the vulnerability mining techniques of industrial control protocols were analyzed in-depth,including the static symbolic execution-based,code audit-based,and fuzzing-based.The protocol design security protection technology was comprehensively dissected from the three directions of industrial control protocol specification design,communication mechanism,and third-party middleware.In addition,the future development trend of industrial control protocol security was further prospected from the aspects of sandbox development,security protection,and vulnerability mining.
作者 黄涛 王郅伟 刘家池 龙千禧 况博裕 付安民 张玉清 HUANG Tao;WANG Zhiwei;LIU Jiachi;LONG Qianxi;KUANG Boyu;FU Anmin;ZHANG Yuqing(School of Computer Science and Engineering,Nanjing University of Science and Technology,Nanjing 210094,China;National Computer Network Intrusion Protection Center,University of Academy of Sciences,Beijing 101408,China;Zhongguancun Laboratory,Beijing 100194,China;School of Cyberspace Security(School of Cryptology),Hainan University,Haikou 571835,China)
出处 《通信学报》 EI CSCD 北大核心 2024年第6期60-74,共15页 Journal on Communications
基金 国家重点研发计划基金资助项目(No.2023QY1202) 国家自然科学基金资助项目(No.U1836210,No.62372236) 海南省重点研发计划基金资助项目(No.GHYF2022010)。
关键词 ICS 工控协议 协议脆弱性 安全防护 漏洞挖掘 ICS industrial control protocol protocol vulnerability security protection vulnerability mining
  • 相关文献

参考文献9

二级参考文献56

共引文献91

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部