首页> 外文会议>Asia-Pacific Network Operations and Management Symposium >Whitelist representation for FTP service in SCADA system by using structured ACL model
【24h】

Whitelist representation for FTP service in SCADA system by using structured ACL model

机译:使用结构化ACL模型,SCTH服务中FTP服务的白名单代表

获取原文

摘要

Due to recent integration of SCADA systems with business systems, SCADA systems became open(unprotected), leading to not only security vulnerabilities increase but also sophisticated and intelligent cyber-attacks specifically targeting SCADA systems. A whitelist based security control technique that has attracted a lot of attention, is an emerging systems control, currently can be applied to solve security problems of the SCADA system. Most of the current security techniques for systems control based on whitelist, use static ACL model. But the static ACL model has limitations in use of ANY-ANY rule which is the only way to express communications using dynamic server port and express ranges of communication features in a control device. In this paper, we propose an structured ACL model to represent an FTP service to overcome the problem of dynamice server port in passive FTP. We demonstrate the feasibility of the proposed model in this paper by applying the FTP features extraction algorithm to FTP traffic.
机译:由于近期与业务系统的SCADA系统集成,SCADA系统变得开放(无保护),不仅领导安全漏洞增加而且还具有特异性瞄准SCADA系统的复杂和智能网络攻击。基于白名单的安全控制技术,吸引了很多关注,是一种新兴系统控制,目前可以应用于解决SCADA系统的安全问题。基于白名单的系统控制的大多数安全技术,使用静态ACL模型。但是静态ACL模型在使用任何规则方面具有限制,这些规则是使用动态服务器端口表达通信的唯一方法,并在控制设备中表达通信功能的范围。在本文中,我们提出了一个结构化的ACL模型来代表FTP服务,以克服被动FTP中的Dynamice服务器端口问题。我们通过将FTP特征提取算法应用于FTP流量,展示了本文所提出的模型的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号