首页> 外文OA文献 >SimaticScan:towards a specialised vulnerability scanner for industrial control systems
【2h】

SimaticScan:towards a specialised vulnerability scanner for industrial control systems

机译:SimaticScan:面向工业控制系统的专用漏洞扫描器

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Over the years, modern Industrial Control Systems (ICS) have become widely computerised and connected via the Internet and are, therefore, potentially vulnerable to cyber attacks. Currently there is a lack of vulnerability scanners specialised to ICS settings. Systems such as PLCScan and ModScan output pertinent information from a Programmable Logic Controller (PLC). However, they do not offer any information as to how vulnerable a PLC is to an attack. In this paper, we address these limitations and propose SimaticScan, a vulnerability scanner specialised to Siemens SIMATIC PLCs. Through experimentation in a comprehensive water treatment testbed, we demonstrate SimaticScan’s effectiveness in determining a range of vulnerabilities across three distinct PLCs, including a previously unknown vulnerability in one of the PLCs. Our experiments also show that SimaticScan outperforms the widely used Nessus vulnerability scanner (with relevant ICS-specific plugins deployed).
机译:多年以来,现代工业控制系统(ICS)已被广泛地计算机化并通过Internet连接,因此很容易受到网络攻击。当前,缺少专门针对ICS设置的漏洞扫描程序。诸如PLCScan和ModScan之类的系统从可编程逻辑控制器(PLC)输出相关信息。但是,它们没有提供有关PLC受到攻击的脆弱程度的任何信息。在本文中,我们解决了这些限制,并提出了SimaticScan,这是专门针对Siemens SIMATIC PLC的漏洞扫描程序。通过在综合水处理测试床上进行的试验,我们证明了SimaticScan在确定三个不同PLC的一系列漏洞(包括其中一个PLC以前未知的漏洞)方面的有效性。我们的实验还表明,SimaticScan优于广泛使用的Nessus漏洞扫描程序(已部署相关的ICS特定插件)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号