信息安全研究 ›› 2024, Vol. 10 ›› Issue (4): 325-.

• 学术论文 • 上一篇    下一篇

 基于仿真的工控蜜罐研究进展与挑战

颜欣晔1李昕2张博3付安民1,3


  

  1. 1(南京理工大学网络空间安全学院江苏江阴214443)
    2(北京计算机技术及应用研究所北京100854)
    3(南京理工大学计算机科学与工程学院南京210094)

  • 出版日期:2024-04-20 发布日期:2024-04-21
  • 通讯作者: 付安民 博士,教授.主要研究方向为网络与信息安全. fuam@njust.edu.cn
  • 作者简介:颜欣晔 硕士研究生.主要研究方向为工控安全. yanxinye@njust.edu.cn 李昕 硕士.主要研究方向为工业信息安全. lx83@live.cn 张博 博士研究生.主要研究方向为网络攻防. zhangbo07@njust.edu.cn 付安民 博士,教授.主要研究方向为网络与信息安全. fuam@njust.edu.cn

Research Progress and Challenge of Industrial Control Systems  Honeypot Based on Simulation

Yan Xinye1, Li Xin2, Zhang Bo3, and Fu Anmin1,3#br#

#br#
  

  1. 1(School of Cyber Science and Engineering, Nanjing University of Science and Technology, Jiangyin, Jiangsu 214443)
    2(Beijing Institute of Computer Technology and Application, Beijing 100854)
    3(School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing 210094)

  • Online:2024-04-20 Published:2024-04-21

摘要: 随着工业互联网的快速发展,针对工业控制系统的攻击层出不穷,造成工业基础设施瘫痪、生产中断、经济损失和人身伤害等严重后果.工控蜜罐是一种欺骗工具,可以作为诱饵吸引攻击者并伪装成真实系统提供访问权限,以诱骗攻击者进行下一步攻击,保护真正的工业控制系统.针对工控蜜罐研究现状进行了深入分析,给出了工控蜜罐的定义及其特征,并重点从基于协议模拟的工控蜜罐、基于结构仿真的工控蜜罐、基于模拟工具的工控蜜罐、基于漏洞模拟的工控蜜罐以及基于混合模拟的工控蜜罐等方面全面分析了基于仿真的工控蜜罐研究进展情况.最后,讨论和分析了当前工控蜜罐仿真模拟过程中面临的挑战和未来发展方向.

关键词: 工控安全, 蜜罐, 工控协议, 可编程逻辑控制器, 工控仿真

Abstract: With the rapid development of the industrial Internet, attacks against industrial control systems have emerged one after another, causing serious consequences such as industrial infrastructure paralysis, production interruptions, economic losses, and personal injury. Honeypot for industrial control system is one kind of deceptive tools which can lure attackers and masquerade as genuine systems to provide access privileges, thus deceiving attackers into conducting subsequent attacks and safeguarding the actual industrial control systems. This paper conducts an indepth analysis of the current research status of industrial honeypots, providing definitions and characteristics of industrial honeypots. It particularly focuses on various types of simulationbased industrial honeypots, including protocolbased simulation honeypots, structurebased simulation honeypots, simulationtoolbased honeypots, vulnerabilitybased simulation honeypots, and hybrid simulation honeypots, comprehensively analyzing the research progress in simulationbased industrial honeypots. Finally, the challenges and future development directions in the simulation and emulation progress of industrial honeypots are discussed and analyzed.

Key words: ICS security, honeypot, ICS protocol, programmable logic controller, ICS simulation

中图分类号: