A method to improve the ICS security through Whitelist-based SCADA network was proposed, which acting as a legitimate transit network packet contains 7-Tuple.Through studies on it for a period of time, the network traffic captured can be stored into the Whitelist, and any connection out of the Whitelist can incur an alarm after the learning time.Some petrochemical projects well verify both size and stability of the Whitelist characteristics.%提出一种基于白名单列表的SCADA系统来提高工控系统网络的安全性。白名单列表是一个合法传输网络包的七元组,系统以大小和稳定性两个重要的白名单属性进行安全评估,通过某个时间段的学习,将获得的白名单信息存储在列表中。学习阶段结束后,白名单流之外的任何连接都被视为非法并产生报警信息。在某石化企业实际项目的工控系统中成功应用,证实了该方法的有效性。
展开▼