计算机与现代化 ›› 2023, Vol. 0 ›› Issue (02): 89-95.

• 信息安全 • 上一篇    下一篇

工业控制系统网络资产探测技术研究

  

  1. (1. 网络空间安全四川省重点实验室,四川 成都 610041; 2. 中国电子科技集团公司第三十研究所,四川 成都  610041)
  • 出版日期:2023-04-10 发布日期:2023-04-10
  • 作者简介:蒋星宇(1997—),男,四川绵阳人,硕士,研究方向:网络空间测绘,E-mail: iamzedking@163.com; 徐锐(1977-),女,研究员,硕士,研究方向:网络空间测绘,网络态势感知,E-mail: jasmine_x@163.com; 张若愚(1992—),男,工程师,硕士,研究方向:网络空间测绘,E-mail: zryxzry@163.com; 张志勇(1985—),男,高级工程师,博士,研究方向:网络空间测绘,统计学习,知识图谱,E-mail: zhiyong_zhang1013@163.com

Research on Network Asset Detection Technology of Industrial Control System

  1. (1. Cyberspace Security Key Laboratory of Sichuan Province, Chengdu 610041, China;
    2. No.30 Institute of CETC, Chengdu 610041, China)
  • Online:2023-04-10 Published:2023-04-10

摘要: 工业控制系统的安全关系到国计民生,是国家安全的重要组成部分。随着物联网技术不断发展,工业控制系统网络已经深入到各行业,但由于设计的缺陷或安全手段的缺乏,工业控制系统相关资产极易受到黑客的攻击和利用。探测、知晓暴露在互联网环境下的工控资产是实现工业控制系统信息监测、发现安全漏洞和把握网络空间安全态势的重要步骤。本文介绍工业控制系统网络资产探测常用的探测方法,利用端口探测技术扫描目标主机上的端口,根据端口开放情况使用工控协议和通用协议的网络资产探测技术发现工控设备和收集资产信息。通过互联网实验,对探测结果数据进行全面分析,总结工业控制系统网络资产探测技术特点,并指出目前技术存在的问题,对未来的发展进行展望。

关键词: 工业控制系统, 网络资产探测, 资产指纹, 协议探测

Abstract: The security of the industrial control system is related to the national economy and people’s livelihood, and is an important part of national security. With the continuous development of the Internet of Things technology, the industrial control system network has penetrated into various industries. However, due to design defects or lack of security means, the relevant assets of the industrial control system are extremely vulnerable to hackers and exploits. Detecting and knowing the industrial control assets exposed to the Internet environment is an important step to realize the information monitoring of the industrial control system, find security loopholes and grasp the security situation of cyberspace. This paper introduces the commonly used detection methods for industrial control system network asset detection. The port detection technology is used to scan the ports on the target host, and then the industrial control protocol and general protocol network asset detection technology is used to discover industrial control equipment and collect asset information according to the port opening. Through the Internet experiment, the data of the detection results are comprehensively analyzed, the characteristics of the network asset detection technology of the industrial control system are summarized, the problems existing in the current technology are pointed out, and the future development is prospected.

Key words: industrial control system, network asset detection, asset fingerprint, protocol detection