课题基金 / 基金详情

RITICS: Trustworthy Industrial Control Systems

RITICS: Trustworthy Industrial Control Systems
RITICS:值得信赖的工业控制系统
批准号:
EP/L021013/1
负责人:
Chris Hankin
金额:
$96.33万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2014
资助国家:
英国
项目状态:
已结题
起止时间:
2014 至 --

项目摘要

项目成果

Chris Hankin的其他基金

相似基金

相关文献

中文摘要
翻译
工业控制系统(ics)可以采用一系列配置,涉及硬件、软件、人工输入、网络拓扑结构和通信协议的不同组合。一般来说,ICS实例可以被描述为一组监控设备——在某些情况下包括单个设备——通过获取数据和发布指令的能力,控制负责执行一个或多个工业过程的现场设备的动作和反应。在大型公用事业规模的工业过程中,集成控制系统表现为监控和数据采集(SCADA)系统;特点是地理上分散的控制目标,需要对不同的通信网络进行集中管理,通常使用不同的协议和模式,具有不同的可靠性和延迟。在更局部的范围内,例如在制造工厂中,访问高可靠性网络使ICS规范能够摆脱SCADA类型的限制,从而产生被称为分布式控制系统(dcs)的ICS表现形式。在更小的范围内,被称为可编程逻辑控制器(plc)的专用计算机提供对少量设备的控制,在某些情况下可能代表小型组织的整个ICS -其中DCS的规模可能不合适。因此,SCADA系统通常由许多DCS和PLC子系统和组件组成。通常,集成电路系统的数据输入由一系列传感器和半自动输入程序提供,控制输出则发给执行器、开关和其他部件等现场设备。通常,国际集成系统的一般定义止步于此,忽略了包括复杂的人类行为和更广泛的组织政策方面,这些方面对于此类系统的实际使用和完整性是不可或缺的。因此,无论何时提到任何形式的综合管理系统,本投标都将隐含地包括这些因素,因为忽视这样做将从一开始就大大限制发展值得信赖的综合管理系统的任务。与本次投标相关的ICS开发和实施的一些关键趋势可以总结为:组织向采用IT解决方案来支持ICS功能的发展,尽管缺乏在联合技术委员会中规划和管理两者的效用和安全性的组织文化/结构;由于推动使用COTS协议/代码模块/中间件进行ICS设计和交付(例如:http://openscada.org/)等因素,在不同规模的行业中增加了ICS解决方案的可用性和采用;在经济和效率驱动因素的推动下,组织网络基础设施的互联性增强;利用边缘计算技术的进步,向去中心化控制迈进;以及遗留ICS组件(配置、依赖关系和故障模式)专业知识的丧失。从攻击成功概率和后果的角度来看,上述任何一项都表明ICSs的威胁风险增加,值得考虑。然而,综合来看,增加风险的论点变得更加明确,需要解决的脆弱性的复杂性开始变得明显。国际系统是各种规模的公用事业、制造业和加工业的组成部分,因此,其妥协或失败的社会经济影响可能非常重大。该研究项目将解决呼叫文件的挑战3:“什么可能是新颖,有效和高效的干预措施?”。特别是,我们期望为有效的干预提供模型和工具。
英文摘要
Industrial control systems (ICSs) can take on a range of configurations, involving diverse mixtures of hardware, software, human inputs, network topologies and communication protocols. Generally, an ICS instance may be described as a set of supervisory devices -- including a single device in some cases -- which, through the acquisition of data and the ability to issue instructions, controls the actions and reactions of field devices responsible for the execution of an industrial process or processes. In large utility scale industrial processes, ICSs are manifest as Supervisory Control and Data Acquisition (SCADA) systems; characterised by geographically dispersed control targets requiring centralised management over disparate communication networks, often using diverse protocols and modalities, with varying reliability and latency. At more local scales, such as may be found in manufacturing plants, access to high reliability networks enables ICS specification to be freed of SCADA type constraints, giving rise to ICS manifestations referred to as Distributed Control Systems (DCSs). Examined on even smaller scales, specialised computers known as Programmable Logic Controllers (PLCs) provide control of small numbers of devices and in some cases may represent the entire ICS for a small organisation -- where the scale of a DCS may well be inappropriate. It follows that SCADA systems are often comprised of numerous DCS and PLC subsystems and components.Typically, data input in ICSs is provided by a series of sensors and semi-automated input procedures and control output is issued to field devices such as actuators, switches and other components. Often, general definitions of ICSs stop here, neglecting to include the complex human behavioural and wider organisational policy aspects that are integral to the real-world use and integrity of such systems. Therefore, whenever referring to ICS of any form, this bid will implicitly include such factors, as to neglect doing so would significantly limit the mission of developing trustworthy ICSs, from the outset.Some of the key trends in the development and implementation of ICS of relevance to this bid may be summarised as: the evolution of organisations towards adopting IT solutions to support ICS functions, despite the lack of organisational cultures/structures where the utility and security of both are planned and managed in joint technical committees; increased availability and uptake of ICS solutions in industry of varying scales due to factors such as the drive towards the use of COTS protocols/code modules/middleware for ICS design and delivery (eg: http://openscada.org/); increased interconnectivity of organisations' cyber infrastructures motivated by economic and efficiency drivers; the move toward decentralised control, exploiting edge computing advances; and the loss of expertise in legacy ICS components (configurations, dependencies and failure modes). From both the perspectives of attack success probability and consequence, any one of the above suggest an increase of threat risk to ICSs that would be worth considering. Viewed in combination, however, the argument for increased risk becomes far more explicit and the complexity of the vulnerabilities that need to be addressed begins to become apparent. ICSs are integral to utility, manufacturing and processing industries of all scales and, as a result, the socio-economic impact of their compromise or failure has the potential to be very significant.This research project will address Challenge 3 of the call document: ``What could be novel, effective and efficient interventions?''. In particular, we expect to produce models and tools in support of effective interventions.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
Scalable Approach to Enhancing ICS Resilience by Network Diversity
通过网络多样性增强 ICS 弹性的可扩展方法
DOI: 10.1109/dsn48063.2020.00055
发表时间: 2020
期刊:
影响因子: --
作者: [Li T]
通讯作者: Li T
A Model-based Approach to Interdependency between Safety and Security in ICS
基于模型的 ICS 安全与安保相互依赖关系方法
DOI: 10.14236/ewic/ics2015.4
发表时间: 2015
期刊:
影响因子: --
作者: [Li T]
通讯作者: Li T
Defense-in-depth vs. Critical Component Defense for Industrial Control Systems
工业控制系统的深度防御与关键组件防御
DOI: 10.14236/ewic/ics2016.1
发表时间: 2016
期刊:
影响因子: --
作者: [Fielder A]
通讯作者: Fielder A
Computer Safety, Reliability, and Security
计算机安全、可靠性和保密性
DOI: 10.1007/978-3-642-24270-0_8
发表时间: 2011
期刊:
影响因子: --
作者: [Felici M]
通讯作者: Felici M
共 6 条
    Research Institute in Trustworthy Inter-connected Cyber-physical Systems (RITICS)
    • 批准号:
      EP/R022844/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $83.97万
    • 财政年份:
      2018
    • 负责人:
      Chris Hankin
    • 依托单位:
    Customized and Adaptive approach for Optimal Cybersecurity Investment
    • 批准号:
      EP/R002983/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $49.2万
    • 财政年份:
      2017
    • 负责人:
      Chris Hankin
    • 依托单位:
    Games and Abstraction: The Science of Cyber Security
    • 批准号:
      EP/K005790/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $62.86万
    • 财政年份:
      2013
    • 负责人:
      Chris Hankin
    • 依托单位:
    IDEAS Factory - Detecting Terrorist Activities: Making Sense
    • 批准号:
      EP/H023135/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $278.43万
    • 财政年份:
      2010
    • 负责人:
      Chris Hankin
    • 依托单位:
    海外基金