期刊文献+

基于区域/边界规则的Modbus TCP通讯安全防御模型 被引量:19

Security defense module of Modbus TCP communication based on region/enclave rules
下载PDF
导出
摘要 针对目前工业控制系统中新型工业病毒的入侵检测难点问题,分析Modbus通讯协议的设计缺陷,提出Modbus TCP通讯深度解析方法,通过对Modbus应用层协议的关键字段的解析,有效应对来自协议应用层的威胁。在此基础上,提出Modbus TCP通讯的安全规则描述的一般形式,并进一步提出基于入侵检测规则和"白名单"相结合的工业SCADA系统中Modbus TCP通讯安全防御模型,通过定义不同区域间正常通讯的最小集合,极大程度上消除系统存在的风险敞口,通过及时报警兼顾可能合法但可疑的通讯流量。仿真实验验证了该方法的有效性。 To solve the problem that it is difficult to detect the intrusion of advanced industrial virus into the industrial control system, design flaws of Modbus TCP were analyzed, and a method was proposed, through which the Modbus TCP packet was deeply parsed to deal with the threat from the application layer. Furthermore, a normal method describing the security rule was proposed and a Modhus TCP communication protection method in the industrial control system or SCADA system that combining the IDS rule with "white-list" was designed, which defined what was necessary between different zones, thus the possibility of being attacked was diminished, while in the meantime a suspicious but probable legal packet would trigger an alarm. The simula- tion experiments validate the effectiveness of the proposed method.
出处 《计算机工程与设计》 CSCD 北大核心 2014年第11期3701-3707,共7页 Computer Engineering and Design
基金 国家自然科学基金项目(61164012) 国家863高技术研究发展计划基金项目(2012AA041102-03)
关键词 工业通讯协议 工业控制系统 白名单 入侵检测 数据采集与监控系统 industrial communication protocol industrial control system white-list intrusion detection SCADA
  • 相关文献

参考文献19

二级参考文献124

  • 1缪学勤.20种类型现场总线进入IEC61158第四版国际标准[J].自动化仪表,2007,28(z1):25-29. 被引量:17
  • 2张奇智,张彬,张卫东.基于网络演算计算交换式工业以太网中的最大时延[J].控制与决策,2005,20(1):117-120. 被引量:44
  • 3彭杰,应启戛.工业以太网实时性能评价的分析[J].微计算机信息,2007(01S):33-34. 被引量:6
  • 4Loeser J,Haertig H.Low-latency hard real-time communication over switched Ethernet[C] //Proceedings of the Euromicro Conference on Real-time Systems.Piscataway,NJ,USA:IEEE, 2004:13-22. 被引量:1
  • 5Pedreiras P,Leite R,Almeida L.Characterizing the real-time behavior of prioritized switched Ethemet[C] //Proceedings of the 2nd International Workshop on Real-time LANs in the Internet Age.Piscataway,NJ,USA:IEEE,2003:56-63. 被引量:1
  • 6Duato J,Yalamanchilli S,Ni L M.Interconnection networks: An engineering approach[M].San Mateo,CA,USA:Morgan Kaufmann,2003. 被引量:1
  • 7Alimujiang Y,Toshio E.Support industrial hard real-time traffic with switched Ethernet[D].Kitami.Japan:Kitami Institute of Technology,2005:671-682. 被引量:1
  • 8Cruz R L.A calculus for network delay.Part I:Network elements in isolation[J].IEEE Transactions on Information Theory, 1991,37(1):114-131. 被引量:1
  • 9Zhang Q Z,Zhang W D.Priority scheduling in switched industrial Ethemet[C] //Proceedings of the 2005 American Control Conference.Piscataway,NJ,USA:IEEE,2005:3366-3370. 被引量:1
  • 10OPNETModel[EB/OL].(2010-10-23)[2010-12-20].http:// www.opnet.com. 被引量:1

共引文献256

同被引文献159

引证文献19

二级引证文献138

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部