论文标题
关键基础架构中使用的SCADA系统安全的有效性
Effectiveness of SCADA System Security Used Within Critical Infrastructure
论文作者
论文摘要
自1960年代以来,监督控制和数据获取(SCADA)系统已在行业中使用。使用SCADA控制电源站,水处理和能源网络等关键装置,例如关键基础设施(CI)。现有的文献揭示了CI的固有安全风险,并表明这是由于互连网络的兴起,导致了这样一个假设,即公司网络与SCADA系统网络之间的互连性的兴起对CI构成了安全风险。对先前涉及SCADA和CI的全球攻击的研究的结果,重点是伊朗和乌克兰的两起严重事件,表明,尽管互连性是主要因素,但由于SCADA控制器和协议中的风险,孤立的CI仍然很容易受到攻击。
Since the 1960s Supervisory Control and Data Acquisition (SCADA) systems have been used within industry. Referred to as critical infrastructure (CI), key installations such as power stations, water treatment and energy grids are controlled using SCADA. Existing literature reveals inherent security risks to CI and suggests this stems from the rise of interconnected networks, leading to the hypothesis that the rise of interconnectivity between corporate networks and SCADA system networks pose security risks to CI. The results from studies into previous global attacks involving SCADA and CI, with focus on two highly serious incidents in Iran and Ukraine, reveal that although interconnectivity is a major factor, isolated CIs are still highly vulnerable to attack due to risks within the SCADA controllers and protocols.