Identifying and Scoring Vulnerability in SCADA Environments
Identifying and Scoring Vulnerability in SCADA Environments
复制标题
SCADA 环境中的漏洞识别和评分
DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Abdullah Abuhussein
中科院分区:
文献类型:
--
作者:
Parves Kamal;Abdullah Abuhussein
Supervisory Control and Data Acquisition (SCADA) systems form a critical component to industries such as national power grids, manufacturing automation, nuclear power production and more. By interacting with control machines and providing real-time support to monitor, gather, and record data, SCADA systems show major impact in industrial environments. Along with the uncountable benefits of SCADA systems, inconceivable risks have raised. Moreover, SCADA operators, production staff and sometimes systems experts have no or little knowledge when applying security due diligence. In this paper, we systematically review SCADA security based on different aspects (i.e. SCADA components, vulnerability, severity, impact, etc.). Our goal is to provide an all-inclusive reference for future SCADA users and researchers. We also use a time-based heuristic approach to evaluate vulnerabilities and show the importance of the evaluation. We aim to establish a fundamental level of security due diligence to ensure SCADA risks are wellcomprehended and managed. Keywords—Supervisory Control and Data Acquisition (SCADA) security; critical infrastructure security; SCADA; risk assessment; vulnerability scoring