Nowadays,industrial control system(ICS)has begun to integrate with the Internet.While the Internet has brought convenience to ICS,it has also brought severe security concerns.Traditional ICS network traffic anomaly de...Nowadays,industrial control system(ICS)has begun to integrate with the Internet.While the Internet has brought convenience to ICS,it has also brought severe security concerns.Traditional ICS network traffic anomaly detection methods rely on statistical features manually extracted using the experience of network security experts.They are not aimed at the original network data,nor can they capture the potential characteristics of network packets.Therefore,the following improvements were made in this study:(1)A dataset that can be used to evaluate anomaly detection algorithms is produced,which provides raw network data.(2)A request response-based convolutional neural network named RRCNN is proposed,which can be used for anomaly detection of ICS network traffic.Instead of using statistical features manually extracted by security experts,this method uses the byte sequences of the original network packets directly,which can extract potential features of the network packets in greater depth.It regards the request packet and response packet in a session as a Request-Response Pair(RRP).The feature of RRP is extracted using a one-dimensional convolutional neural network,and then the RRP is judged to be normal or abnormal based on the extracted feature.Experimental results demonstrate that this model is better than several other machine learning and neural network models,with F1,accuracy,precision,and recall above 99%.展开更多
随着互联网的发展,工业控制系统(Industrial Control Systems,ICS)面临的网络威胁越来越多,因此建立工业控制系统网络安全防御系统十分必要。文章设计了一种基于对抗战术、技术和常识(Adversarial Tactics、Techniques and Common Knowl...随着互联网的发展,工业控制系统(Industrial Control Systems,ICS)面临的网络威胁越来越多,因此建立工业控制系统网络安全防御系统十分必要。文章设计了一种基于对抗战术、技术和常识(Adversarial Tactics、Techniques and Common Knowledge,ATT&CK)框架的工业控制系统网络安全防御系统,旨在为工业控制系统的网络安全防御提供参考及指导,确保其安全运行。展开更多
在介绍智能电网的信息通信系统(information and communication system,ICS)业务需求的基础上,提出了支持中国特色智能化电网的ICS体系架构,给出了支持中国特色智能化电网的ICS标准体系结构。ICS体系架构涉及信息通信技术、ICS体系框架...在介绍智能电网的信息通信系统(information and communication system,ICS)业务需求的基础上,提出了支持中国特色智能化电网的ICS体系架构,给出了支持中国特色智能化电网的ICS标准体系结构。ICS体系架构涉及信息通信技术、ICS体系框架、ICS网络管理和ICS网络安全防护等方面内容。预期了支撑中国智能化电网的信息通信技术研究热点和ICS建设与示范工程。建议加强支持中国特色智能化电网ICS的网络管理、安全防护和技术标准体系建设工作。展开更多
工业控制系统(ICS)作为国家基础设施的核心控制设备,其安全关系国计民生。震网(Stuxnet)病毒爆发以后,工控安全逐渐引起国家、企业、战略安全人士的高度重视。总结分析了工控系统的结构资产、脆弱性、存在的威胁、安全措施与风险评估等...工业控制系统(ICS)作为国家基础设施的核心控制设备,其安全关系国计民生。震网(Stuxnet)病毒爆发以后,工控安全逐渐引起国家、企业、战略安全人士的高度重视。总结分析了工控系统的结构资产、脆弱性、存在的威胁、安全措施与风险评估等内容;提出了四层功能的仿免疫系统的安全管理模型,并重点分析其中的关键防御技术,例如深度防御、防火墙、异常检查、Conpot(Control Systems Honeypot)、安全远程访问以及管理策略;指出工控系统安全将会是智慧城市、智慧制造与工业4.0等新兴技术的发展契机与最大挑战;最后结合国内工控安全布局规划,给出工控安全建议,并展望未来的发展前景。展开更多
基金supported by the National Natural Science Foundation of China(No.62076042,No.62102049)the Key Research and Development Project of Sichuan Province(No.2021YFSY0012,No.2020YFG0307,No.2021YFG0332)+3 种基金the Science and Technology Innovation Project of Sichuan(No.2020017)the Key Research and Development Project of Chengdu(No.2019-YF05-02028-GX)the Innovation Team of Quantum Security Communication of Sichuan Province(No.17TD0009)the Academic and Technical Leaders Training Funding Support Projects of Sichuan Province(No.2016120080102643).
文摘Nowadays,industrial control system(ICS)has begun to integrate with the Internet.While the Internet has brought convenience to ICS,it has also brought severe security concerns.Traditional ICS network traffic anomaly detection methods rely on statistical features manually extracted using the experience of network security experts.They are not aimed at the original network data,nor can they capture the potential characteristics of network packets.Therefore,the following improvements were made in this study:(1)A dataset that can be used to evaluate anomaly detection algorithms is produced,which provides raw network data.(2)A request response-based convolutional neural network named RRCNN is proposed,which can be used for anomaly detection of ICS network traffic.Instead of using statistical features manually extracted by security experts,this method uses the byte sequences of the original network packets directly,which can extract potential features of the network packets in greater depth.It regards the request packet and response packet in a session as a Request-Response Pair(RRP).The feature of RRP is extracted using a one-dimensional convolutional neural network,and then the RRP is judged to be normal or abnormal based on the extracted feature.Experimental results demonstrate that this model is better than several other machine learning and neural network models,with F1,accuracy,precision,and recall above 99%.
文摘随着互联网的发展,工业控制系统(Industrial Control Systems,ICS)面临的网络威胁越来越多,因此建立工业控制系统网络安全防御系统十分必要。文章设计了一种基于对抗战术、技术和常识(Adversarial Tactics、Techniques and Common Knowledge,ATT&CK)框架的工业控制系统网络安全防御系统,旨在为工业控制系统的网络安全防御提供参考及指导,确保其安全运行。
文摘在介绍智能电网的信息通信系统(information and communication system,ICS)业务需求的基础上,提出了支持中国特色智能化电网的ICS体系架构,给出了支持中国特色智能化电网的ICS标准体系结构。ICS体系架构涉及信息通信技术、ICS体系框架、ICS网络管理和ICS网络安全防护等方面内容。预期了支撑中国智能化电网的信息通信技术研究热点和ICS建设与示范工程。建议加强支持中国特色智能化电网ICS的网络管理、安全防护和技术标准体系建设工作。
文摘工业控制系统(ICS)作为国家基础设施的核心控制设备,其安全关系国计民生。震网(Stuxnet)病毒爆发以后,工控安全逐渐引起国家、企业、战略安全人士的高度重视。总结分析了工控系统的结构资产、脆弱性、存在的威胁、安全措施与风险评估等内容;提出了四层功能的仿免疫系统的安全管理模型,并重点分析其中的关键防御技术,例如深度防御、防火墙、异常检查、Conpot(Control Systems Honeypot)、安全远程访问以及管理策略;指出工控系统安全将会是智慧城市、智慧制造与工业4.0等新兴技术的发展契机与最大挑战;最后结合国内工控安全布局规划,给出工控安全建议,并展望未来的发展前景。