首页> 外文会议>55th Annual Conference for Protective Relay Engineers Apr 9-11, 2002 College Station, Texas >ATTACK AND DEFEND TOOLS FOR REMOTELY ACCESSIBLE CONTROL AND PROTECTION EQUIPMENT IN ELECTRIC POWER SYSTEMS
【24h】

ATTACK AND DEFEND TOOLS FOR REMOTELY ACCESSIBLE CONTROL AND PROTECTION EQUIPMENT IN ELECTRIC POWER SYSTEMS

机译:电力系统远程访问控制和保护设备的攻击和防御工具

获取原文
获取原文并翻译 | 示例

摘要

The industry trend to increase the level of power system automation and remote accessibility, coupled with a dramatic increase in the number and sophistication of Internet and telephone based cyber attacks, is exposing the electric power industry to a growing risk of electronic intrusion. Furthermore, our electric power infrastructure is a potentially high-value target for individuals, organizations, and nations with anti-U.S. sentiments or political agendas. As a result, there is a very real and rapidly increasing probability that malicious individuals will attempt to gain remote access to your power control equipment in order to destabilize the power grid and/or destroy parts of your power system. Similar attacks have been launched against telecommunications companies and E-commerce sites for several years now. Fortunately, we can learn from their-experiences. Many defensive techniques and practices have been used to reduce the chances of cyber attack and electronic intrusion, including password protection, audit logging, multi-tiered access levels, alarm conditions, remote authentication, redundant controllers, time-out communication parameters, virus protection, firewalls, encryption, and intrusion detection systems. However, to understand these defensive practices you first need to understand the offensive techniques that may be used to carry out a cyber attack or intrusion. In this paper, we describe the offensive techniques and capabilities of individuals (malicious and otherwise) so that you can counteract their actions with equally effective defensive measures. For each offensive procedure, we provide defensive tools and techniques that you can apply to your power system automation solutions. We note, however, that no system is ever 100 percent secure ― only continued vigilance can ensure reliable operation of our electric power systems.
机译:行业趋势是提高电力系统自动化和远程可访问性的水平,再加上基于Internet和电话的网络攻击的数量和复杂性急剧增加,这使电力行业面临着越来越多的电子入侵风险。此外,对于反对美国的个人,组织和国家,我们的电力基础设施是潜在的高价值目标。情绪或政治议程。结果,恶意人员极有可能会以非常真实且迅速增加的势头企图远程访问您的电源控制设备,从而破坏电网的稳定性和/或破坏您的电源系统的各个部分。几年来,已经对电信公司和电子商务站点发起了类似的攻击。幸运的是,我们可以从他们的经验中学到东西。许多防御技术和做法已被用来减少网络攻击和电子入侵的机会,包括密码保护,审核日志记录,多层访问级别,警报条件,远程身份验证,冗余控制器,超时通信参数,病毒防护,防火墙,加密和入侵检测系统。但是,要了解这些防御措施,您首先需要了解可用于进行网络攻击或入侵的攻击技术。在本文中,我们描述了个人(恶意和其他)的攻击技术和能力,以便您可以使用同样有效的防御措施来抵消他们的行动。对于每个进攻性程序,我们提供可应用于您的电力系统自动化解决方案的防御性工具和技术。但是,我们注意到,没有任何系统能够百分百安全-只有持续保持警惕才能确保我们的电力系统可靠运行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号