首页> 外文OA文献 >Investigating common SCADA security vulnerabilities using penetration testing
【2h】

Investigating common SCADA security vulnerabilities using penetration testing

机译:使用渗透测试调查常见的SCADA安全漏洞

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Supervisory Control and Data Acquisition (SCADA) systems were developed to assist in the management, control and monitor of critical infrastructure functions such as gas, water, waste, railway, electricity and traffic. In the past, these systems had little connectivity to the Internet because they ran on dedicated networks with proprietary control protocols and used hardware and software specific to the vendor. As a result, SCADA systems were secure, and did not face challenging vulnerabilities associated with the Internet. The need for remote connectedness, in order to collect and analyse data from remote locations, resulted in SCADA systems being increasingly getting connected to the Internet and corporate networks. Therefore, SCADA systems are no longer immune to cyber-attacks. There are reported cases on cyber-attacks targeted at SCADA systems. This research utilises penetration testing to investigate common SCADA security vulnerabilities. The investigation is conducted through experiments, under two different scenarios. Experiments were conducted using virtual plant environment. The results revealed vulnerabilities which are considered as common by the Idaho National Laboratory and others which are not common. Recommendations are provided on how to mitigate the vulnerabilities discovered in this research.
机译:开发了监督控制和数据采集(SCADA)系统,以协助管理,控制和监视关键基础设施功能,例如天然气,水,废物,铁路,电力和交通。过去,这些系统与Internet的连接很少,因为它们在具有专有控制协议的专用网络上运行,并且使用了特定于供应商的硬件和软件。结果,SCADA系统是安全的,并且没有面临与Internet相关的挑战性漏洞。为了从远程位置收集和分析数据,对远程连接的需求导致SCADA系统越来越多地连接到Internet和公司网络。因此,SCADA系统不再不受网络攻击的影响。据报道,针对SCADA系统的网络攻击案例。这项研究利用渗透测试来调查常见的SCADA安全漏洞。该调查是通过实验在两种不同的情况下进行的。实验是使用虚拟工厂环境进行的。结果表明,爱达荷州国家实验室认为这些漏洞很常见,其他不常见的漏洞也是如此。提供有关如何缓解此研究中发现的漏洞的建议。

著录项

  • 作者

    Ralethe Sello Glenton;

  • 作者单位
  • 年度 2015
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号