可编程控制器(PLC)的安全问题研究  被引量:4

Research on the Security of PLC

在线阅读下载全文

作  者:马跃强 杨盛明[2] 韩儒剑 杨涛 曹旭 Ma Yueqiang;Yang Shengming;Han Rujian;Yang Tao;Cao Xu(Nsfocus Technologies Group Co.,Ltd.,Beijing,100089;The Fifth Electronic Research Institute of MIIT,Guangzhou Guangdong,511370)

机构地区:[1]绿盟科技集团股份有限公司,北京100089 [2]工业和信息化部电子第五研究所,广州511370

出  处:《工业信息安全》2022年第6期52-58,共7页Industry Information Security

摘  要:随着工业数字化的高速发展,越来越多控制设备、设备上云,打破了原本封闭可信的生产环境,面临了来自信息网、互联网以及第三方网络的病毒、木马、勒索软件、工业间谍、黑客等威胁,这样先天缺乏安全基因的PLC控制器就容易被这些威胁利用导致安全事件。为此,本文以西门子PLC为研究对象,对其存在的安全问题进行分析,分别从安全漏洞、协议脆弱性以及不安全的配置基线等三个方面进行分析论证,研究出西门子PLC存在的安全隐患,并给出安全建议,为今后对PLC的防护以及控制器设备的防护提供理论指导。Under the guidance and promotion of the European Data Strategy,the construction of data space and the development of digital platforms in the EU has continued to advance.This paper summarizes and analyzes the development modes of EU digital platforms:data sharing,platform support,production cooperation,market expansion,etc.By exploring the representative digital platform development cases that emerged in the EU in the fields of industry,energy and smart agriculture,this paperproposes that there are driving factors in the construction of data space and digital platforms in the EU,such as efficiency improvement,open collaboration,value enhancement,and there are also obstacles to development,such as insufficient interoperability,regulatory uncertainty and the lack of enterprise motivation.China should learn from the EU's development experience to accelerate the cultivation of a unified data elements market,actively promote the implementation of data information security laws and regulations,and strive to enhance the level of data sharing between government and enterprises.

关 键 词:PLC 安全漏洞 通信协议 脆弱性 安全配置基线 安全编程 

分 类 号:TP273[自动化与计算机技术—检测技术与自动化装置] TP309[自动化与计算机技术—控制科学与工程]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象