首页> 外文会议>Annual Conference for Protective Relay Engineers >Attack and defend tools for remotely accessible control and protection equipment in electric power systems
【24h】

Attack and defend tools for remotely accessible control and protection equipment in electric power systems

机译:电力系统远程可访问控制和保护设备的攻击和防守工具

获取原文

摘要

The industry trend to increase the level of power system automation and remote accessibility, coupled with a dramatic increase in the number and sophistication of Internet and telephone based cyber attacks, is exposing the electric power industry to a growing risk of electronic intrusion. Furthermore, our electric power infrastructure is a potentially high-value target for individuals, organizations, and nations with anti-U.S. sentiments or political agendas. As a result, there is a very real and rapidly increasing probability that malicious individuals will attempt to gam remote access to your power control equipment in order to destabilize the power grid and/or destroy parts of your power system. Similar attacks have been launched against telecommunications companies and E-commerce sites for several years now. Fortunately, we can learn from their experiences. Many defensive techniques and practices have been used to reduce the chances of cyber attack and electronic intrusion, including password protection, audit logging, multi-tiered access levels, alarm conditions, remote authentication, redundant controllers, time-out communication parameters, virus protection, firewalls, encryption, and intrusion detection systems. However, to understand these defensive practices you first need to understand the offensive techniques that may be used to carry out a cyber attack or intrusion. In this paper, we describe the offensive techniques and capabilities of individuals (malicious and otherwise) so that you can counteract their actions with equally effective defensive measures. For each offensive procedure, we provide defensive tools and techniques that you can apply to your power system automation solutions. We note, however, that no system is ever 100 percent secure - only continued vigilance can ensure reliable operation of our electric power systems.
机译:行业潮流,以增加电力系统自动化和远程访问的水平,再加上数量的急剧增长和成熟的互联网和基于电话的网络攻击,被暴露电力工业电子入侵的风险越来越大。此外,我们的电力基础设施是为个人,组织,并与反美国家一个潜在的高价值目标。情绪或政治议程。其结果是,有一个非常真实和迅速增加的可能性恶意的个人将尝试GAM你的电源控制设备,以破坏电网和/或破坏你的电力系统的部分远程访问。类似的攻击已经已经推出针对电信公司和电子商务网站好几年了。幸运的是,我们可以从他们的经验中学习。许多防守技术和做法已经被用于降低网络攻击和电子入侵,包括密码保护,审计日志,多层次的访问级别,报警状态,远程认证,冗余控制器的机会,超时通信参数,病毒防护,防火墙,加密,和入侵检测系统。但是,要了解你首先需要了解的是可以用来进行网络攻击或入侵的进攻技巧,这些防御性的做法。在本文中,我们描述了进攻技术和个人能力(恶意和其他方式),这样就可以抵消他们的行为与同等有效的防御措施。对于每一个进攻过程中,我们提供防御性的工具和技术可以应用到你的电力系统自动化解决方案。我们注意到,但是,没有任何系统是有史以来百分之百安全 - 只有继续保持警惕可以确保我们的电力系统的可靠运行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号