{"title":"工业控制设备的自动化测试:delphi数据库","authors":"N. Kube, K. Yoo, D. Hoffman","doi":"10.1145/1982595.1982611","DOIUrl":null,"url":null,"abstract":"Delphi is a database designed to centralize and distribute current industrial automation vulnerability information. Over the past two years, with the aid of many of the world's largest equipment vendors and operators, we have populated this databse through extensive testing of industrial control devices. Delphi stores over 500 vulnerabilities on 31 popular distributed control system and safety instrumented system controllers. There are two primary reasons why Delphi data is useful: to distribute vulnerability data and to improve mitigation strategies. With detailed knowledge of which vulnerabilities are present, vendors can produce more robust devices and operators can construct business cases and calculate return-on-investment when considering investments in security measures. Furthermore, known vulnerabilities can be mitigated without applying device patches and shutting down plant operations.","PeriodicalId":443108,"journal":{"name":"International Conference/Workshop on Automation of Software Test","volume":"20 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-05-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Automated testing of industrial control devices: the delphi database\",\"authors\":\"N. Kube, K. Yoo, D. Hoffman\",\"doi\":\"10.1145/1982595.1982611\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Delphi is a database designed to centralize and distribute current industrial automation vulnerability information. Over the past two years, with the aid of many of the world's largest equipment vendors and operators, we have populated this databse through extensive testing of industrial control devices. Delphi stores over 500 vulnerabilities on 31 popular distributed control system and safety instrumented system controllers. There are two primary reasons why Delphi data is useful: to distribute vulnerability data and to improve mitigation strategies. With detailed knowledge of which vulnerabilities are present, vendors can produce more robust devices and operators can construct business cases and calculate return-on-investment when considering investments in security measures. Furthermore, known vulnerabilities can be mitigated without applying device patches and shutting down plant operations.\",\"PeriodicalId\":443108,\"journal\":{\"name\":\"International Conference/Workshop on Automation of Software Test\",\"volume\":\"20 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-05-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Conference/Workshop on Automation of Software Test\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/1982595.1982611\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference/Workshop on Automation of Software Test","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/1982595.1982611","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Automated testing of industrial control devices: the delphi database
Delphi is a database designed to centralize and distribute current industrial automation vulnerability information. Over the past two years, with the aid of many of the world's largest equipment vendors and operators, we have populated this databse through extensive testing of industrial control devices. Delphi stores over 500 vulnerabilities on 31 popular distributed control system and safety instrumented system controllers. There are two primary reasons why Delphi data is useful: to distribute vulnerability data and to improve mitigation strategies. With detailed knowledge of which vulnerabilities are present, vendors can produce more robust devices and operators can construct business cases and calculate return-on-investment when considering investments in security measures. Furthermore, known vulnerabilities can be mitigated without applying device patches and shutting down plant operations.