首页> 外文期刊>International Journal on Critical Infrastructure Protection >Experimental assessment of network design approaches for protecting industrial control systems
【24h】

Experimental assessment of network design approaches for protecting industrial control systems

机译:保护工业控制系统的网络设计方法的实验评估

获取原文
获取原文并翻译 | 示例
           

摘要

This paper surveys and provides experimental results related to network design techniques focused on enhancing the security of industrial control systems. It analyzes defensein-depth strategies, network segmentation, network firewall configurations and the role of intrusion prevention systems, intrusion detection systems and anomaly detection systems. The paper also studies the applicability of emerging technologies in the area of IP networks, including software-defined networking, network functions virtualization and next generation firewalls in securing industrial control systems. The main contribution of this paper is the experimental assessment of existing and future network design approaches in the presence of real malware (e.g., Stuxnet) and synthetic attacks (e.g., denial-of-service attacks). The experimental results confirm the importance of defense-in-depth strategies and also highlight the embryonic state of software-defined networking security, which requires profound transformation and validation in order to be embraced by the industrial control system community. (C) 2015 Elsevier B.V. All rights reserved.
机译:本文调查并提供了与网络设计技术相关的实验结果,这些技术专注于增强工业控制系统的安全性。它分析了深度防御策略,网络分段,网络防火墙配置以及入侵防御系统,入侵检测系统和异常检测系统的作用。本文还研究了IP网络领域中新兴技术的适用性,包括软件定义网络,网络功能虚拟化和用于保护工业控制系统的下一代防火墙。本文的主要贡献是在存在真实恶意软件(例如Stuxnet)和综合攻击(例如拒绝服务攻击)的情况下对现有和未来网络设计方法进行实验评估。实验结果证实了深度防御策略的重要性,并突出了软件定义的网络安全性的萌芽状态,这需要深入的转换和验证才能被工业控制系统社区所接受。 (C)2015 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号