论文标题
IT和SCADA的融合:相关的安全威胁和漏洞
Convergence of IT and SCADA: Associated Security Threats and Vulnerabilities
论文作者
论文摘要
随着许多行业转向集中的受控信息系统进行监视和控制,因此对诸如监管控制和数据采集工业系统(SCADA)等技术更为重要。对集成和互操作性的关注为安全人员和组织管理带来了许多挑战。因此,在组织中将这一新方向偿还了足够的计划和框架,以确保其SCADA架构的保护和安全性。对相关威胁和脆弱性的清晰了解对于采用/制定适当的政策和框架至关重要。为此,在这项研究中,我们确定并分析了相关的SCADA安全威胁和脆弱性,并提出了一个简单的计划,以更好地理解它们。
As many industries shift towards centralised controlled information systems for monitoring and control, more importance is being placed upon technologies such as Supervisory Control and Data Acquisitions industrial systems (SCADA). This focus on integration and interoperability presents numerous challenges for security personnel and organisational management alike. It becomes paramount therefore to reciprocate this new direction within an organisation with adequate plans and frameworks that ensure protection and security of its SCADA architecture. A clear understanding of the relevant threats and vulnerabilities is critical for adopting/developing appropriate policy and frameworks. To this end, in this research we identify and analyse relevant SCADA security threats and vulnerabilities and present a simple scheme to classify them for better understanding.