论文标题

工业控制系统的网络安全:一项调查

Cybersecurity for Industrial Control Systems: A Survey

论文作者

Bhamare, Deval, Zolanvari, Maede, Erbad, Aiman, Jain, Raj, Khan, Khaled, Meskin, Nader

论文摘要

工业控制系统(ICS)是一个通用术语,包括监督控制和数据采集(SCADA)系统,分布式控制系统(DCS)和其他控制系统配置,例如可编程逻辑控制器(PLC)。 ICS通常在工业部门和关键基础设施中发现,例如核和热工厂,水处理设施,发电,重工业和分销系统。尽管ICS与Internet隔绝了这么长时间,但可实现的巨大业务利益正在推动ICS和Internet之间的融合以及信息技术(IT)环境(例如云​​计算)。结果,ICS已暴露于大多数网络攻击中使用的攻击媒介。但是,ICS设备在此类高级攻击方案中本质上不太安全。对IC的妥协会导致巨大的身体损害和对人类生命的危险。在这项工作中,我们仔细研究了IC从独立系统转移到基于云的环境的转变。然后,我们讨论从行业和学术界到安全ICS的开发,尤其是机器学习技术对ICS网络安全的适用性。这项工作可能有助于应对保护工业流程的挑战,尤其是在将其迁移到云环境时。

Industrial Control System (ICS) is a general term that includes supervisory control & data acquisition (SCADA) systems, distributed control systems (DCS), and other control system configurations such as programmable logic controllers (PLC). ICSs are often found in the industrial sectors and critical infrastructures, such as nuclear and thermal plants, water treatment facilities, power generation, heavy industries, and distribution systems. Though ICSs were kept isolated from the Internet for so long, significant achievable business benefits are driving a convergence between ICSs and the Internet as well as information technology (IT) environments, such as cloud computing. As a result, ICSs have been exposed to the attack vectors used in the majority of cyber-attacks. However, ICS devices are inherently much less secure against such advanced attack scenarios. A compromise to ICS can lead to enormous physical damage and danger to human lives. In this work, we have a close look at the shift of the ICS from stand-alone systems to cloud-based environments. Then we discuss the major works, from industry and academia towards the development of the secure ICSs, especially applicability of the machine learning techniques for the ICS cyber-security. The work may help to address the challenges of securing industrial processes, particularly while migrating them to the cloud environments.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源