基于仿真的工控蜜罐研究进展与挑战OACSTPCD
Research Progress and Challenge of Industrial Control Systems Honeypot Based on Simulation
随着工业互联网的快速发展,针对工业控制系统的攻击层出不穷,造成工业基础设施瘫痪、生产中断、经济损失和人身伤害等严重后果.工控蜜罐是一种欺骗工具,可以作为诱饵吸引攻击者并伪装成真实系统提供访问权限,以诱骗攻击者进行下一步攻击,保护真正的工业控制系统.针对工控蜜罐研究现状进行了深入分析,给出了工控蜜罐的定义及其特征,并重点从基于协议模拟的工控蜜罐、基于结构仿真的工控蜜罐、基于模拟工具的工控蜜罐、基于漏洞模拟的工控蜜罐以及基于混合模拟的工控蜜罐等方面全面分析了基于仿真的工控蜜罐研究进展情况.最后,讨论和分析了当前工控蜜罐仿真模拟过程中面临的挑战和未来发展方向.
With the rapid development of the industrial Internet,attacks against industrial control systems have emerged one after another,causing serious consequences such as industrial infrastructure paralysis,production interruptions,economic losses,and personal injury.Honeypot for industrial control system is one kind of deceptive tools which can lure attackers and masquerade as genuine systems to provide access privileges,thus deceiving attackers into conducting subsequent attacks and safeguarding the actual industrial control systems.This paper conducts an in-depth analysis of the current research status of industrial honeypots,providing definitions and characteristics of industrial honeypots.It particularly focuses on various types of simulation-based industrial honeypots,including protocol-based simulation honeypots,structure-based simulation honeypots,simulation-tool-based honeypots,vulnerability-based simulation honeypots,and hybrid simulation honeypots,comprehensively analyzing the research progress in simulation-based industrial honeypots.Finally,the challenges and future development directions in the simulation and emulation progress of industrial honeypots are discussed and analyzed.
颜欣晔;李昕;张博;付安民
南京理工大学网络空间安全学院 江苏江阴 214443北京计算机技术及应用研究所 北京 100854南京理工大学计算机科学与工程学院 南京 210094南京理工大学网络空间安全学院 江苏江阴 214443||南京理工大学计算机科学与工程学院 南京 210094
计算机与自动化
工控安全蜜罐工控协议可编程逻辑控制器工控仿真
ICS securityhoneypotICS protocolprogrammable logic controllerICS simulation
《信息安全研究》 2024 (004)
325-334 / 10
国家自然科学基金项目(62072239,62372236);未来网络科研基金项目(FNSRFP-2021-ZD-05)
评论