信息安全研究 ›› 2017, Vol. 3 ›› Issue (6): 560-567.

• 电子认证专辑 • 上一篇    下一篇

基于靶场技术的DNC网络安全分析

阎诗晨   

  1. 西北工业大学国家保密学院
  • 收稿日期:2017-06-19 出版日期:2017-06-15 发布日期:2017-06-19
  • 通讯作者: 阎诗晨
  • 作者简介:硕士研究生,主要研究方向为工业控制系统信息安全.

Cyber Range Based Security Analysis of DNC Protocol

  • Received:2017-06-19 Online:2017-06-15 Published:2017-06-19

摘要: 随着网络技术在分布式控制系统(distributed numerical control, DNC)中的使用与普及,传统的DNC系统面临越来越严峻的信息安全问题.为了深入分析网络化DNC系统的通信安全风险隐患,提出利用靶场技术构建DNC高逼真半实物平台的方法,分析DNC系统内的工业通信协议和文件传输协议及其安全性,特别得出了等时同步协议、DHCP和SSHv2面对的安全风险.基于安全性分析,提出相应的DNC系统安全防护建议,为现实网络化制造系统的安全防护提供借鉴.

关键词: 网络信息安全, 分布式数控, 网络化数控靶场, 协议安全分析, DNC系统安全防护

Abstract: Widely available, lowcost Internet Protocol (IP) devices are now replacing specialized proprietary control protocols in Distributed Numerical Control (DNC) system, which increases the possibility of cyber security vulnerabilities and incidents. In order to analyze the security of protocol in DNC system, in this paper, a cyber range technique for building DNC system is proposed. The potential risks against DNC system are then revealed based on the security analysis on the acquired boundary protocol. Respective to the risks, the boundary protection policies are formulated at last, suggesting the protection measures taken for real manufacturing industry.

Key words: network information security, distributed numerical control, numerical control cyber range, analysis of protocol security, DNC system security