首页> 外文学位 >Security and Threat Analysis of Industrial Control Systems and Applicable Solutions
【24h】

Security and Threat Analysis of Industrial Control Systems and Applicable Solutions

机译:工业控制系统的安全与威胁分析及适用解决方案

获取原文
获取原文并翻译 | 示例

摘要

Physical, network, internal, and cyber security for Industrial Control Systems is extremely low, leaving these critical systems vulnerable to attack by sophisticated cyber-threats. Outdated control systems have been in place for upwards of thirty years and are riddled with significant vulnerabilities, with no clear solutions to be found. The purpose of this research was to examine the current state of security for Industrial Control Systems and to provide clear and applicable solutions to any issues that may be discovered. This research also analyzed the threats that are enabled through the current state of ICS security. Central focal points of this research include discovering the age and state of current running control systems, uncovering the vulnerabilities and threats against them, and locating applicable security solutions to and problems observed. Key findings of this research show that many Industrial Control Systems have been in place for upwards of thirty years and run outdated hardware and software. ICS were designed with a focus on functionality and not internal security. Vulnerabilities include weak access control, weak user authentication, unauthenticated protocols, remote access, poor network security and visibility, increased IT/OT convergence, and a lack of involvement by senior level management. Threats toward Industrial Control Systems are on the rise and consist of enemy nation-states and politically motivated attacks, internal threats such as human error or sabotage, terrorist organizations, and hacktivists. Industrial Control Systems can be made more secure through the use of defense-in-depth strategies, detailed procedures, timely application of system patches, network segmentation, multi-layered access mechanisms, and an increased understanding of what systems are most at risk. ICS need to be secured one step at a time to avoid disruption and physical damage from an attack.
机译:工业控制系统的物理,网络,内部和网络安全性非常低,使这些关键系统容易受到复杂的网络威胁的攻击。过时的控制系统已经存在了三十多年,并且充斥着重大漏洞,没有明确的解决方案。这项研究的目的是检查工业控制系统的当前安全状态,并为可能发现的任何问题提供清晰适用的解决方案。这项研究还分析了通过ICS安全性当前状态启用的威胁。这项研究的重点包括发现当前运行的控制系统的年龄和状态,发现针对它们的漏洞和威胁以及找到适用的安全解决方案和发现的问题。这项研究的主要发现表明,许多工业控制系统已经存在了三十多年,并且运行的硬件和软件已经过时。 ICS的设计重点是功能而不是内部安全性。漏洞包括访问控制薄弱,用户身份验证薄弱,未经身份验证的协议,远程访问,网络安全性和可见性差,IT / OT融合增加以及高层管理人员缺乏参与。对工业控制系统的威胁正在上升,其威胁包括敌对的民族国家和出于政治动机的攻击,诸如人为错误或破坏活动的内部威胁,恐怖组织和黑客主义者。通过使用纵深防御策略,详细的过程,及时应用系统补丁,网络分段,多层访问机制以及加深对哪些系统风险最大的了解,可以使工业控制系统更加安全。一次必须确保ICS的安全性,以避免攻击造成的破坏和物理损坏。

著录项

  • 作者

    Mack, Michael J.;

  • 作者单位

    Utica College.;

  • 授予单位 Utica College.;
  • 学科 Information technology.;Industrial engineering.;Computer engineering.
  • 学位 M.S.
  • 年度 2018
  • 页码 149 p.
  • 总页数 149
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号