|国家科技期刊平台
首页|期刊导航|通信学报|工控协议安全研究综述

工控协议安全研究综述OA北大核心CSTPCD

Survey on industrial control protocol security research

中文摘要英文摘要

工控协议安全是保障ICS稳定运行的关键,大量工控协议在设计阶段忽视了对安全性的考量,导致目前大部分主流工控协议普遍存在脆弱性问题.结合ICS架构和工控协议的发展特征,深入解析目前工控协议普遍面临的脆弱性问题和攻击威胁.同时,针对工控协议的潜在漏洞,深入分析基于静态符号执行、代码审计和模糊测试等工控协议漏洞挖掘技术,并从工控协议的规范设计、通信机制以及第三方中间件3个方面全面剖析协议设计的安全防护技术.另外,从沙箱研制、安全防护及漏洞挖掘等方面,对工控协议安全的未来发展趋势进行展望.

The security of industrial control protocol is the cornerstone to ensure ICS's stable operation,a large number of industrial control protocols in the design phase ignore the consideration of security,resulting in most of the main-stream industrial control protocols generally having vulnerabilities.Considering the ICS architecture and the develop-mental characteristics of industrial control protocols,the various vulnerabilities and attack threats commonly faced by in-dustrial control protocols were systematically summarized.At the same time,for the unknown potential vulnerabilities of industrial control protocols,the vulnerability mining techniques of industrial control protocols were analyzed in-depth,including the static symbolic execution-based,code audit-based,and fuzzing-based.The protocol design security protec-tion technology was comprehensively dissected from the three directions of industrial control protocol specification de-sign,communication mechanism,and third-party middleware.In addition,the future development trend of industrial con-trol protocol security was further prospected from the aspects of sandbox development,security protection,and vulner-ability mining.

黄涛;王郅伟;刘家池;龙千禧;况博裕;付安民;张玉清

南京理工大学计算机科学与工程学院,江苏 南京 210094中国科学院大学国家计算机网络入侵防范中心,北京 101408||中关村实验室,北京 100194中国科学院大学国家计算机网络入侵防范中心,北京 101408||中关村实验室,北京 100194||海南大学网络空间安全学院(密码学院),海南 海口 571835

计算机与自动化

ICS工控协议协议脆弱性安全防护漏洞挖掘

ICSindustrial control protocolprotocol vulnerabilitysecurity protectionvulnerability mining

《通信学报》 2024 (006)

60-74 / 15

国家重点研发计划基金资助项目(No.2023QY1202);国家自然科学基金资助项目(No.U1836210,No.62372236);海南省重点研发计划基金资助项目(No.GHYF2022010)The National Key Research and Development Program of China(No.2023QY1202),The National Natural Sci-ence Foundation of China(No.U1836210,No.62372236),The Key Research and Development Program of Hainan Province(No.GHYF2022010)

10.11959/j.issn.1000-436x.2024104

评论