控制系统网络事件报告协议

S. Hennin
{"title":"控制系统网络事件报告协议","authors":"S. Hennin","doi":"10.1109/THS.2008.4534497","DOIUrl":null,"url":null,"abstract":"Information sharing about cyber incidents that affect the normal, safe operation of industrial control systems is not well coordinated or standardized across critical infrastructure sectors of the economy. Consequently there is little situational awareness about the frequency, type and extent of control system cyber incidents - a deficiency with potential national security implications. Control system disruption due to cyber rather than physical means is increasingly a concern of industry and government. More and more control systems utilize commercial off-the-shelf computer technology, and are inter-connected with business enterprise systems and the Internet. Not only are control systems in different sectors interdependent but the commonality of technology means that all sectors face a common cyber threat. These common cyber threats and vulnerabilities present the opportunity for common solutions to be adopted across industry sectors. The solutions include the elimination of vulnerabilities in control system designs and implementations. But with constantly evolving technology and the ever-present threat of cyber attack, tools are needed to support the early detection and timely reporting of control system cyber incidents. A Raytheon-led team is working in consultation with industry and government to define a standard protocol and data schema for the timely reporting of actual and potential cyber attacks on industrial control systems. Previous efforts to share cyber incident information have encountered barriers, including data confidentiality and detection of novel cyber attack methods. Potential solutions to these barriers and deployment approaches for information sharing tools based on the protocol standard are described.","PeriodicalId":366416,"journal":{"name":"2008 IEEE Conference on Technologies for Homeland Security","volume":"120 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-05-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"Control System Cyber Incident Reporting Protocol\",\"authors\":\"S. Hennin\",\"doi\":\"10.1109/THS.2008.4534497\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Information sharing about cyber incidents that affect the normal, safe operation of industrial control systems is not well coordinated or standardized across critical infrastructure sectors of the economy. Consequently there is little situational awareness about the frequency, type and extent of control system cyber incidents - a deficiency with potential national security implications. Control system disruption due to cyber rather than physical means is increasingly a concern of industry and government. More and more control systems utilize commercial off-the-shelf computer technology, and are inter-connected with business enterprise systems and the Internet. Not only are control systems in different sectors interdependent but the commonality of technology means that all sectors face a common cyber threat. These common cyber threats and vulnerabilities present the opportunity for common solutions to be adopted across industry sectors. The solutions include the elimination of vulnerabilities in control system designs and implementations. But with constantly evolving technology and the ever-present threat of cyber attack, tools are needed to support the early detection and timely reporting of control system cyber incidents. A Raytheon-led team is working in consultation with industry and government to define a standard protocol and data schema for the timely reporting of actual and potential cyber attacks on industrial control systems. Previous efforts to share cyber incident information have encountered barriers, including data confidentiality and detection of novel cyber attack methods. Potential solutions to these barriers and deployment approaches for information sharing tools based on the protocol standard are described.\",\"PeriodicalId\":366416,\"journal\":{\"name\":\"2008 IEEE Conference on Technologies for Homeland Security\",\"volume\":\"120 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-05-12\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2008 IEEE Conference on Technologies for Homeland Security\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/THS.2008.4534497\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 IEEE Conference on Technologies for Homeland Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/THS.2008.4534497","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

摘要

影响工业控制系统正常、安全运行的网络事件的信息共享在经济的关键基础设施部门之间没有得到很好的协调或标准化。因此,对控制系统网络事件的频率、类型和程度几乎没有态势感知——这是一个潜在的国家安全隐患的缺陷。由于网络而非物理手段造成的控制系统中断日益受到业界和政府的关注。越来越多的控制系统采用商用现成的计算机技术,并与企业系统和互联网相互连接。不同部门的控制系统不仅相互依存,而且技术的通用性意味着所有部门都面临共同的网络威胁。这些常见的网络威胁和漏洞为跨行业采用通用解决方案提供了机会。解决方案包括消除控制系统设计和实现中的漏洞。但随着技术的不断发展和网络攻击威胁的不断存在,需要工具来支持控制系统网络事件的早期发现和及时报告。一个由雷神公司领导的团队正在与工业界和政府协商,定义一个标准协议和数据模式,以便及时报告对工业控制系统的实际和潜在网络攻击。以前共享网络事件信息的努力遇到了障碍,包括数据保密性和检测新的网络攻击方法。描述了这些障碍的潜在解决方案和基于协议标准的信息共享工具的部署方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Control System Cyber Incident Reporting Protocol
Information sharing about cyber incidents that affect the normal, safe operation of industrial control systems is not well coordinated or standardized across critical infrastructure sectors of the economy. Consequently there is little situational awareness about the frequency, type and extent of control system cyber incidents - a deficiency with potential national security implications. Control system disruption due to cyber rather than physical means is increasingly a concern of industry and government. More and more control systems utilize commercial off-the-shelf computer technology, and are inter-connected with business enterprise systems and the Internet. Not only are control systems in different sectors interdependent but the commonality of technology means that all sectors face a common cyber threat. These common cyber threats and vulnerabilities present the opportunity for common solutions to be adopted across industry sectors. The solutions include the elimination of vulnerabilities in control system designs and implementations. But with constantly evolving technology and the ever-present threat of cyber attack, tools are needed to support the early detection and timely reporting of control system cyber incidents. A Raytheon-led team is working in consultation with industry and government to define a standard protocol and data schema for the timely reporting of actual and potential cyber attacks on industrial control systems. Previous efforts to share cyber incident information have encountered barriers, including data confidentiality and detection of novel cyber attack methods. Potential solutions to these barriers and deployment approaches for information sharing tools based on the protocol standard are described.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信