Identifying and Scoring Vulnerability in SCADA Environments

Identifying and Scoring Vulnerability in SCADA Environments
复制标题

SCADA 环境中的漏洞识别和评分

DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Abdullah Abuhussein
Abdullah Abuhussein
中科院分区:
--
文献类型:
--
作者:
Parves Kamal;Abdullah Abuhussein

文献摘要

被引文献

相似文献

监控和数据采集(SCADA)系统是国家电网、制造业自动化、核电生产等行业的关键组成部分。通过与控制机器交互并提供实时支持来监控、收集和记录数据,SCADA系统在工业环境中显示出重大影响。随着SCADA系统带来的不可估量的好处,难以想象的风险也随之产生。此外,SCADA操作人员、生产人员,有时甚至是系统专家,在应用安全尽职调查时都没有或几乎没有知识。本文从SCADA组件、脆弱性、严重性、影响等不同方面系统地综述了SCADA的安全性。我们的目标是为未来的SCADA用户和研究人员提供一个全面的参考。我们还使用基于时间的启发式方法来评估漏洞并显示评估的重要性。我们的目标是建立一个基本的安全尽职调查水平,以确保SCADA风险得到很好的理解和管理。关键词:监控与数据采集(SCADA);关键基础设施安全;SCADA;风险评估;危险得分
Supervisory Control and Data Acquisition (SCADA) systems form a critical component to industries such as national power grids, manufacturing automation, nuclear power production and more. By interacting with control machines and providing real-time support to monitor, gather, and record data, SCADA systems show major impact in industrial environments. Along with the uncountable benefits of SCADA systems, inconceivable risks have raised. Moreover, SCADA operators, production staff and sometimes systems experts have no or little knowledge when applying security due diligence. In this paper, we systematically review SCADA security based on different aspects (i.e. SCADA components, vulnerability, severity, impact, etc.). Our goal is to provide an all-inclusive reference for future SCADA users and researchers. We also use a time-based heuristic approach to evaluate vulnerabilities and show the importance of the evaluation. We aim to establish a fundamental level of security due diligence to ensure SCADA risks are wellcomprehended and managed. Keywords—Supervisory Control and Data Acquisition (SCADA) security; critical infrastructure security; SCADA; risk assessment; vulnerability scoring