首页> 外文会议>Annual Conference for Protective Relay Engineers >Ukraine cyber-induced power outage: Analysis and practical mitigation strategies
【24h】

Ukraine cyber-induced power outage: Analysis and practical mitigation strategies

机译:乌克兰网络诱导的停电:分析和实际缓解策略

获取原文

摘要

On December 23, 2015, a “temporary malfunction of the power supply” in three provinces in Ukraine resulted in power outages that lasted up to six hours and affected 225,000 customers. Following the event, an investigation identified evidence that several regional Ukraine power control systems had been compromised by cyber attacks. This was the first publicly documented successful cyber attack on an electric utility's control system. Both asset owners and government officials around the world now are asking, “What happened and could a similar cyber attack happen in our control systems?” This paper provides an analysis of the Ukraine cyber attack, including how the malicious actors gained access to the control system, what methods the malicious actors used to explore and map the control system, a detailed description of the December 23, 2015 attacks, and methods used by the malicious actors to erase their activities and make remediation more difficult. We then present a detailed description of securing utility power system control systems based on best practices, including control system network design, whitelisting techniques, monitoring and logging, and personnel education. The paper concludes with a discussion of mitigation methods and recommendations that would have protected the Ukraine control system and alerted personnel in advance of the cyber attack.
机译:2015年12月23日,乌克兰三个省份“电力供应暂时故障”导致停电,持续了六个小时,影响了225,000名客户。在此次活动之后,调查确定了若干区域乌克兰电力控制系统被网络攻击损害。这是第一次公开记录的电力效用控制系统的成功攻击。世界各地的资产所有者和政府官员现在都在问:“发生了什么,在我们的控制系统中发生了类似的网络攻击?”本文提供了对乌克兰网络攻击的分析,包括恶意演员如何获得控制系统的访问,是什么方法,用于探索和绘制控制系统的恶意演员,详细描述2015年12月23日攻击和方法恶意演员用于删除他们的活动并使修复更加困难。然后,我们基于最佳实践来提供保护实用电力系统控制系统的详细描述,包括控制系统网络设计,白名单技术,监控和伐木和人员教育。本文讨论了减缓方法和建议,这些方法和建议将在网络攻击前保护乌克兰控制系统和警报人员。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号