信息安全研究 ›› 2022, Vol. 8 ›› Issue (6): 534-.

• 工业控制网络安全专题 • 上一篇    下一篇

一种针对拟态工业控制器的裁决及调度方法

杨汶佼;刘星宇;张奕;张兴明;张汝云   

  1. (之江实验室智能网络研究院杭州311100)
  • 出版日期:2022-06-05 发布日期:2022-06-03
  • 通讯作者: 杨汶佼 高级工程师.主要研究方向为工业互联网内生安全与控制系统内生安全. yangwj@zhejianglab.com
  • 作者简介:杨汶佼 高级工程师.主要研究方向为工业互联网内生安全与控制系统内生安全. yangwj@zhejianglab.com 刘星宇 硕士,工程师.主要研究方向为工业控制系统安全. damon_lxy@zhejianglab.com 张奕 硕士,工程师.主要研究方向为工业控制系统安全. zhangyi@zhejianglab.com 张兴明 硕士,研究员.主要研究方向为拟态计算及拟态安全. zhangxm@zhejianglab.com 张汝云 博士,之江实验室智能网络研究院执行院长.主要研究方向为拟态计算及拟态安全. zhangry@zhejianglab.com

  • Online:2022-06-05 Published:2022-06-03

摘要: 针对工业系统的安全性问题,根据拟态防御理论中的动态异构冗余模型,并结合工业系统的实际应用场景,首先提出了一种针对工业现场协议的4异构执行体拟态混合裁决方法,再依据执行体间的异构度及共模防御系数提出了一种在有限的异构资源下的执行体调度方法,最后将调度算法与随机调度算法进行仿真分析.结果表明,这种新的裁决和调度算法,不但可以有效支撑数字和模拟信号混合的复杂拟态工控应用场景,同时还能快速识别共模攻击,减小系统的共模逃逸时间,进一步提升工控系统的防御能力.关键词拟态防御;工业控制器;异构执行体;裁决;调度

关键词: 拟态防御, 工业控制器, 异构执行体, 裁决, 调度

Abstract: AbstractAiming at the security issues of industrial systems, according to the dynamic heterogeneous redundancy (DHR) model in the mimic defense theory, and combined with the actual application scenarios of industrial systems. Firstly, this paper proposed a hybrid adjudication method, which aims at four heterogeneous executants for industrial field protocols. And then an executive scheduling method under limited heterogeneous resources is proposed, which based on the heterogeneity of the executive body set and the commonmode defense coefficient. Finally, the algorithm in this paper and the random scheduling algorithm will be simulated and analyzed. The results show that the new algorithm can not only effectively support complex simulated industrial control application scenarios, which mixed digital and analog signals, but also can quickly identify common mode attack, reduce the common mode escape time of the system, and further improve the defense capability of industrial control system.Key words mimic defense; industrial controller; heterogeneous actuator; arbitration; scheduling

Key words: mimic defense, industrial controller, heterogeneous actuator, arbitration, scheduling