《電子技術應用》
您所在的位置:首頁 > 其他 > 设计应用 > 基于蜜罐的工控网络安全防护技术研究进展
基于蜜罐的工控网络安全防护技术研究进展
信息技术与网络安全 2期
李 实1,万佳蓉2,林显盛3
(1.大亚湾核电运营管理有限责任公司,广东 深圳518124; 2.华北计算机系统工程研究所,北京100083;3.广州中软信息技术有限公司,广东 广州510665)
摘要: 摘 要: 工业控制系统是工业生产过程的控制枢纽,在国际网络安全形势愈发严峻的背景下,越来越多的攻击者将目标锁定在工业控制系统上,爆发了一系列造成严重影响的工控网络安全事件。作为一种主动防御技术,工控蜜罐正逐渐成为目前行业的研究热点。在调研现有相关工作的基础上,从蜜罐基本概念、工控蜜罐关键技术、应用实例和发展趋势对目前的研究工作进行梳理,并针对核电DCS系统的网络架构,研究了S7协议、操作系统等“诱惑陷阱”在Docker容器中的虚拟化技术,实现了TXP系统仿真蜜罐的设计。为了验证蜜罐系统的防护效果,在核电TXP系统中进行了蜜罐部署并通过脚本模拟攻击行为,结果表明,系统能够准确捕获攻击流量并对内容进行解析识别,成功诱骗非法渗透内网的攻击者进入由蜜网组成的虚拟环境并进行告警,全面提升TXP系统内发现、记录、溯源攻击行为的威胁感知能力。
中圖分類號: TP393.08
文獻標識碼: A
DOI: 10.19358/j.issn.2096-5133.2022.02.004
引用格式: 李實,萬佳蓉,林顯盛. 基于蜜罐的工控網絡安全防護技術研究進展[J].信息技術與網絡安全,2022,
41(2):20-26,32.
Research progress of honeypot-based ICS security protection technology
Li Shi1,Wan Jiarong2,Lin Xiansheng3
(1.Daya Bay Nuclear Power Operations and Management Co.,Ltd.,Shenzhen 518124,China; 2.National Computer System Engineering Research Institute of China,Beijing 100083,China; 3.Guangzhou CSS Information Technology Co.,Ltd.,Guangzhou 510665,China)
Abstract: Industrial Control System(ICS) is the core of the industrial production process. With the increasingly severe international network security situation, more and more attackers are taking ICS as target and causing a series of terrible security events. As an active defense technology, honeypot for ICS are gradually becoming a research hotspot. On the basis of investigating existing related work, in this paper we sort out the current research content from the concepts of honeypot, key technologies of honeypot, application instances and development trends. Aiming at the architecture of DCS in nuclear power industrial, we investigate the virtualization technology of S7 protocol, operating system and other temptation traps in the Docker container, and design a simulation honeypot for the TXP system. In order to verify the protection effect of the honeypot system, the honeypot is deployed in the TXP system and the attack is simulated through scripts. The results show that the system can accurately capture the attack traffic, analyze and identify the content, successfully trick the attacker who illegally penetrated the intranet into the virtual environment composed of the honeynet and alarm user. Honeypot can comprehensively improve the threat perception ability of the TXP system to detect, record, and trace the attack behavior.
Key words : honeypot;ICS security;system design

0 引言

工業控制系統是工業生產過程的核心控制樞紐,在過去,由于工業控制系統自身的特殊性和重要性,普遍采用內網形式運行,不與外界網絡進行通信。然而隨著信息化技術的發展和生產工藝要求的提高,工業控制系統的封閉性正在逐漸被打破,暴露在互聯網上的工業控制系統數量處于快速攀升狀態。國家互聯網應急中心在《2020年上半年我國互聯網網絡安全監測數據分析報告》[1]中指出:監測發現暴露在互聯網上的工業設備達4 630臺,境內工業控制系統的網絡資產持續遭受來自境外的掃描嗅探,日均超過2萬次。

目前業界主流針對工業控制系統網絡安全的防護手段屬于被動防護,例如安裝部署防火墻[2]、入侵檢測[3]等硬件設備或具有應用白名單功能的防護軟件等。被動防護手段主要的不足之處在于只能被動地應對或緩解攻擊者所造成的破壞,在網絡安全技術快速迭代的背景下,其局限性愈發明顯。

蜜罐作為最典型的主動防護手段,是當前學術界和產業界研究的熱點。蜜罐與被動防護手段最大的不同在于其扭轉了網絡安全博弈過程中防御方只能處于被動應對的局面。蜜罐通過誘捕攻擊者,使防御方能夠主動識別攻擊者的攻擊手段與攻擊意圖,進而提前部署防護策略,更加有效地保護工業控制系統穩定運行。由多個相互連接的蜜罐所構成的更為復雜的系統稱為蜜網,蜜網對于攻擊者具有更強的迷惑性。


本文詳細內容請下載http://www.tom3567.com/resource/share/2000003946




作者信息:

李  實1,萬佳蓉2,林顯盛3

(1.大亞灣核電運營管理有限責任公司,廣東 深圳518124;

2.華北計算機系統工程研究所,北京100083;3.廣州中軟信息技術有限公司,廣東 廣州510665)




微信圖片_20210517164139.jpg

此內容為AET網站原創,未經授權禁止轉載。
主站蜘蛛池模板: 免费国产成人看片在线| 一区二区三区四区欧美日韩| 国产精品日韩三级| 精品久久久91| 国产成人一区三区| www日韩视频| 亚洲a中文字幕| 91精品国产自产91精品| 久久精品国产成人精品| 国产精品视频导航| 国产精品福利在线观看网址| 日韩中文字幕在线| 久久亚洲精品国产亚洲老地址| 日韩人妻一区二区三区蜜桃视频| 青青久久av北条麻妃海外网| 国产精品视频自拍| 天天爽天天狠久久久| 国产二区视频在线播放| 欧美一级免费看| 亚洲午夜高清视频| 欧美视频在线第一页| 久久精品无码中文字幕| 91精品视频专区| 久久久人人爽| 久久av免费一区| 亚洲综合五月天| 日本精品一区二区三区在线播放视频| 国模吧无码一区二区三区| 日韩在线视频二区| 国产精品一区二区3区| 99久久久久国产精品免费| 精品人妻少妇一区二区| 日韩欧美一区二区三区四区五区 | 国产精品秘入口18禁麻豆免会员| 日韩福利视频| 日韩人妻精品无码一区二区三区| 亚洲视频在线观看日本a| 久久国产精品亚洲va麻豆| www..com日韩| 亚洲xxxx在线| 欧美大片va欧美在线播放|