摘要
该文通过研究国内外工业控制系统(ICS)漏洞库及建设现状,设计并实现了一个专注于工业控制系统漏洞发布、检索及管理的工业控制系统漏洞数据库。文中漏洞库的设计结合工业控制系统漏洞的特点及其与传统漏洞属性的差异,建立了工业控制系统漏洞库描述模型。同时,兼顾漏洞信息收集的覆盖率和漏洞信息发布的标准化,能够更好地支持工业控制系统漏洞信息的收集、跟踪及漏洞数据的分析、研究,为工业控制系统安全研究提供了丰富的数据支撑。
By studying the status of domestic and foreign research and construction on vulnerability database of industrial control systems,We designed and implemented a vulnerability database whichfocus on the industrial control system vulnerability publishing,retrieving and managing.In this paper,the design of vulnerability database combinedthe characteristics of industrial control systemsvulnerability and the differences with traditional vulnerability property.We establishedthe description model for industrial control systems vulnerability database.This vulnerability databasetook into account both standardization for thecollection of vulnerability information and the coverage rate of vulnerability information released.It can sustain industrial control system vulnerability collection and tracking,also for the research and analysis of vulnerability,and provide the research on the security of industrial control system a wealth of data support.
出处
《电子质量》
2015年第12期56-60,共5页
Electronics Quality
关键词
工业控制系统
漏洞库
信息安全
Industrial Control System
Vulnerability Database
Information Security