课题基金 / 基金详情

Digital Forensic Readiness for Hyper-Connected Critical Infrastructure

Digital Forensic Readiness for Hyper-Connected Critical Infrastructure
超连接关键基础设施的数字取证准备就绪
批准号:
2644351
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2020
资助国家:
英国
项目状态:
未结题
起止时间:
2020 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
一座城市因电力供应中断而陷入黑暗,生产线和核离心机关闭,一个城镇的供水试图中毒,美国最大的燃料管道被勒索软件摧毁-这些灾难性的网络攻击可能会削弱我们现代社会日常生活核心所依赖的关键国家基础设施(CNI)。此类旨在破坏物理过程控制并造成经济、地缘政治或环境持久损害和/或生命损失的事件已经并将继续发生在工业控制系统(ICS)上,也被称为监控和数据采集(SCADA)系统。复杂和状态的上升,发起了Stuxnet和Triton等针对可编程逻辑控制器PLC等核心组件的攻击,沿着的是缺乏可靠的取证工具,方法和技术促使这位博士研究传统数字取证工具和能力在关键国家基础设施内的网络物理系统领域的适用性和可转移性。随着SCADA取证调查面临的主要挑战,例如ICS设备中有限的计算/存储资源,特定于供应商的专有固件,ICS协议规范的不透明性,缺乏内存获取工具和日志记录能力不足,一个新的和实验验证的ICS法医准备架构,以建立一个法医能力,在事件发生前,同时保持安全-关键特性是我博士学位的核心目标。
英文摘要
A city plunged into darkness due to a disrupted electric supply, production lines and nuclear centrifuges shut down, water supplies to a town attempted to be poisoned and the largest fuel pipeline in the US was taken down by a ransomware - these catastrophic cyberattacks could cripple critical national infrastructures (CNI) on which the core of everyday life in our modern societies heavily relies. Such incidents which aim to disrupt the control of physical processes and cause an economic, geopolitical, or environmental lasting damage and/or loss of life, have and will continue to occur against industrial control systems (ICS), also referred to as Supervisory Control and Data Acquisition (SCADA) systems.The ascent of sophisticated and state-sponsored attacks such as Stuxnet and Triton against core components like Programmable Logic Controllers PLCs, along with the lack of forensically sound tools, approaches and techniques have motivated this PhD to examine the applicability and transferability of traditional digital forensics tools and capabilities to the realm of cyber physical systems within critical national infrastructures. With major challenges forensic investigators are facing in SCADA forensic investigations such as limited computing/storage resources in ICS devices , vendor-specific proprietary firmware, opacity of ICS protocol specifications, lack of memory acquisition tools and insufficient logging capabilities, a new and experimentally validated ICS forensic readiness architecture to establish a forensic capability before an incident while maintaining the safety-critical properties represent the core objective of my PhD.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金