首页> 外文期刊>Journal of information security and applications >Detection of attacks based on known vulnerabilities in industrial networked systems
【24h】

Detection of attacks based on known vulnerabilities in industrial networked systems

机译:基于工业网络系统中已知漏洞的攻击检测

获取原文
获取原文并翻译 | 示例
           

摘要

Vulnerabilities in software and hardware components can be exploited by attackers to cause damages through the cyberspace. Nowadays, this problem also affects a large number of industrial networked systems (INS) and experts are well aware that suitable prevention/detection techniques and countermeasures have to be developed, taking into account INS characteristics and peculiarities. The exposure of a large and complex system to attacks carried out by exploiting well-selected sequences of vulnerabilities can be hard to evaluate, but this is a fundamental step to prevent potential menaces in both the system design and operation phases. This paper deals with an innovative technique, which is able to compute all attack patterns leveraging known vulnerabilities present in an industrial system. The proposed approach is based on the extension of a twofold model, which was successfully developed for verifying the implementation of access control policies in INS. Our solution enables the development of an automated software analyser that can help with the design and maintenance of INS when their security is considered.
机译:攻击者可以利用软件和硬件组件中的漏洞通过网络空间造成损害。如今,此问题还会影响大量工业网络系统(INS),专家们非常意识到,必须考虑到INS的特征和特殊性,必须开发合适的预防/检测技术和对策。大型复杂的系统通过利用精心挑选的漏洞序列进行攻击可能很难评估,但这是防止系统设计和操作阶段中潜在威胁的基本步骤。本文介绍了一种创新技术,该技术能够计算利用工业系统中存在已知漏洞的所有攻击模式。所提出的方法基于两个模型的扩展,该模型成功开发出来,以验证INS中访问控制策略的实施。我们的解决方案可以开发自动化软件分析仪,该软件分析仪可以在考虑其安全性时帮助设计和维护INS。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号