首页> 外文会议>IEEE Advanced Information Management, Communicates, Electronic and Automation Control Conference >Research on Key Technology of Industrial Network Boundary Protection based on Endogenous Security
【24h】

Research on Key Technology of Industrial Network Boundary Protection based on Endogenous Security

机译:基于内源性安全的工业网络边界保护关键技术研究

获取原文

摘要

Industrial network boundary protection equipment faces threats from attackers when protecting the industrial control system network. The similarity and static characteristics caused by large-scale and long-term deployment determine that it could only defend against known attacks but could not deal with unknown APT threats, which leads to the breakthrough of one defense line is equivalent to the breakthrough of all defense lines and may bring challenges to industrial production safety. This paper proposes a mimic defense model of industrial isolation gateway based on endogenous security. With the dynamic scheduling mechanism to transform the attack surface, the gateway selects multiple heterogeneous filter executors to process the same packet simultaneously. By comparing the processing results of each executor, anomaly detection is carried out to realize the dynamic defense of the industrial isolation gateway. The experimental results show that the industrial isolation gateway based on mimic architecture can significantly increase the difficulty of backdoor utilization, such as paralysis, rule tampering, and information theft, and effectively defend the industrial control system from the threats caused by the backdoors and vulnerabilities of the isolation gateway while exerting the normal boundary protection function.
机译:工业网络边界保护设备在保护工业控制系统网络时面临攻击者的威胁。由大规模和长期部署引起的相似性和静态特性决定它只能防御已知的攻击,但不能处理未知的APT威胁,这导致一个防御线的突破相当于所有防御的突破线条并可能为工业生产安全带来挑战。本文提出了一种基于内源性安全性工业隔离网关的模拟防御模型。利用动态调度机制来转换攻击面,网关选择多个异构过滤器执行器以同时处理相同的分组。通过比较每个执行者的处理结果,执行异常检测,以实现工业隔离网关的动态防御。实验结果表明,基于模拟架构的工业隔离网关可以显着增加后门利用的难度,如瘫痪,规则篡改和信息盗窃,并有效地保护工业控制系统免受由后门造成的威胁的威胁施加正常边界保护功能的同时隔离网关。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号