期刊文献+

电力行业工业控制系统信息安全风险评估研究 被引量:7

Research on Information Security Risk Assessment of Power Industry Control System
下载PDF
导出
摘要 简要地分析了电力行业工业控制系统面临的信息安全威胁,列出了电力行业工业控制系统主要的安全问题,并在此基础上建立了工业控制系统信息安全风险评估与管理模型,提出了工业控制系统信息安全风险评估的方法和流程,总结出了一套针对工业控制系统的信息安全风险评估解决方案,并阐述了关于风险评估和工业控制系统网络安全工作的一些新认识,进一步分析了工业控制系统网络安全脆弱性,借此提请有关单位和有关主管部门应进一步明确和规范工业控制系统信息安全风险评估工作的管理,加强有关评估标准、技术的研究,增加面向专业测评机构和用户单位的技术培训,推动我国工业控制系统信息风险评估工作的发展. This paper briefly analyzed the information security threats faced by the industrial control system in the power industry. The main safety problems of industrial control system in electric power industry are listed. We also built an information security risk assessment and management model for industrial control systems, proposed methods and processes for information security risk assessment of industrial control systems. Hence, we summed up a set of information security risk assessment solutions for industrial control systems. Some new understandings about risk assessment and industrial control system network security are also discussed. The vulnerability of industrial control system network security is further analyzed. Therefore, the relevant units and relevant competent departments should further clarify and standardize the management of information security risk assessment of industrial control systems. Strengthen research on evaluation standards and technology. Increasing technical training for professional evaluation organizations and user units. Promoting the development of information risk assessment for industrial control systems in China.
作者 魏晓雷 刘龙涛 Wei Xiaolei;Liu Longtao(AVIC International E-Business Inc,Beijing 100176;Department of Information and Net-cvork Security,State Inforzrmtion Center,Beijing 100045)
出处 《信息安全研究》 2018年第10期904-913,共10页 Journal of Information Security Research
关键词 电力行业 工业控制系统 信息安全 风险评估 脆弱性 power industry industrial control system information security risk assessment vulnerability
  • 相关文献

参考文献5

二级参考文献162

  • 1陈壮奕.基于GPRS的电能远程抄表系统的设计与实现[J].广东电力,2006,19(1):71-74. 被引量:18
  • 2庞志勇,刘冬华,黄沫,陈弟虎.基于GPRS数据传输终端的实现[J].中山大学学报论丛,2006,26(2):129-133. 被引量:4
  • 3张晶,马国政.电力需求侧管理技术支持系统[J].电力需求侧管理,2006,8(5):56-57. 被引量:7
  • 4刘水,陶文娟.SqlServerCE在电力设备巡检系统中的开发应用[J].江西电力,2007,31(2):1-4. 被引量:1
  • 5NIST SP800-82.Guide to Industrial Control Systems(ICS)Security[S].Gaithersburg,USA:National Institute of Standards and Technology(NIST),2011.
  • 6Simon H A.The architecture of complexity[C] //Proceedings of the American Philosophical Society.Philadelphia,USA:Batsford,1962:467-482.
  • 7Bishop M.Computer Security[M].Boston,USA:Addison Wesley,2003.
  • 8Department of Homeland Security(DHS).Cyber Security Assessments of Industrial Control System[S].Washington DC,USA:Department of Homeland Security(DHS),2010.
  • 9The European Network and Information Security Agency(ENISA).Protecting Industrial Control Systems,Recommendations for Europe and Member States[R].Heraklion,Greece:Recommendations for Europe and Member States,2011.
  • 10Byres E J,Kay J,Carter J.Myths and facts behind cyber security and industrial control(2003)[Z/OL].(2010-02-12),http://www.pimaweb.org/conference/april2003/pdfs/MythsAndFactsBehindCyberSecurity.pdf.

共引文献247

同被引文献42

引证文献7

二级引证文献58

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部