论文标题
离岸石油和天然气行业的网络安全挑战:工业网络物理系统(ICP)观点
Cybersecurity Challenges in the Offshore Oil and Gas Industry: An Industrial Cyber-Physical Systems (ICPS) Perspective
论文作者
论文摘要
海上石油和天然气行业最近一直在使用数字化驱动器,并使用“智能”设备使用工业互联网(IIOT)和工业网络物理系统(ICP)等技术。针对石油和天然气公司的网络攻击也相应增加。海上石油生产通常位于偏远地区,需要远程访问和控制。这是通过整合ICP,监督,控制和数据获取(SCADA)系统以及IIT技术来实现的。对石油和天然气海上资产的成功进行网络攻击可能会对人员的环境,海洋生态系统和人员安全产生毁灭性影响。任何破坏世界石油和天然气供应(O \&G)也会对石油价格和全球经济产生影响。这使得保护行业免受网络威胁至关重要。我们描述了石油和天然气行业中潜在的网络攻击表面,讨论了离岸子行业的新兴趋势,并提供了已知的网络攻击时间表。我们还提出了一个通常用于海上石油和天然气操作中的海底控制系统体系结构的案例研究,并突出了影响系统组件的潜在漏洞。这项研究是第一个对海底控制系统中攻击向量进行详细分析的研究,对于理解关键漏洞至关重要,主要是实施有效的缓解方法,以保护使用此类系统时人员和环境的安全性。
The offshore oil and gas industry has recently been going through a digitalisation drive, with use of `smart' equipment using technologies like the Industrial Internet of Things (IIoT) and Industrial Cyber-Physical Systems (ICPS). There has also been a corresponding increase in cyber attacks targeted at oil and gas companies. Oil production offshore is usually in remote locations, requiring remote access and control. This is achieved by integrating ICPS, Supervisory, Control and Data Acquisition (SCADA) systems, and IIoT technologies. A successful cyber attack against an oil and gas offshore asset could have a devastating impact on the environment, marine ecosystem and safety of personnel. Any disruption to the world's supply of oil and gas (O\&G) can also have an effect on oil prices and in turn, the global economy. This makes it important to secure the industry against cyber threats. We describe the potential cyberattack surface within the oil and gas industry, discussing emerging trends in the offshore sub-sector, and provide a timeline of known cyberattacks. We also present a case study of a subsea control system architecture typically used in offshore oil and gas operations and highlight potential vulnerabilities affecting the components of the system. This study is the first to provide a detailed analysis on the attack vectors in a subsea control system and is crucial to understanding key vulnerabilities, primarily to implement efficient mitigation methods that safeguard the safety of personnel and the environment when using such systems.