信息网络安全 ›› 2021, Vol. 21 ›› Issue (9): 16-24.doi: 10.3969/j.issn.1671-1122.2021.09.003

• 入选论文 • 上一篇    下一篇

基于半实物的机场供油自控系统网络安全测试

顾兆军1,2, 姚峰1,2, 丁磊3, 隋翯4()   

  1. 1.中国民航大学信息安全测评中心,天津 300300
    2.中国民航大学计算机科学与技术学院,天津 300300
    3.中国民用航空局信息中心,北京 100710
    4.中国民航大学航空工程学院,天津 300300
  • 收稿日期:2021-04-15 出版日期:2021-09-10 发布日期:2021-09-22
  • 通讯作者: 隋翯 E-mail:hsui@caucedu.cn
  • 作者简介:顾兆军(1966—),男,山东,教授,博士,主要研究方向为网络与信息安全、民航信息系统|姚峰(1998—),男,山东,硕士研究生,主要研究方向为工业控制系统网络与信息安全|丁磊(1995—),男,天津,硕士,主要研究方向为工业控制系统网络与信息安全|隋翯(1987—),男,吉林,讲师,博士,主要研究方向为工业控制系统网络与信息安全
  • 基金资助:
    中国民航大学信息安全测评中心开放基金(ISECCA-202004);民航安全能力建设基金(PESA2021007);民航安全能力建设基金(PESA2021009)

Network Security Test of Airport Fuel Supply Automatic Control System Based on Semi-physical Object

GU Zhaojun1,2, YAO Feng1,2, DING Lei3, SUI He4()   

  1. 1. Information Security Evaluation Center, Civil Aviation University of China, Tianjin 300300, China
    2. School of Computer Science and Technology, Civil Aviation University of China, Tianjin 300300, China
    3. Information Center, Civil Aviation Administration of China, Beijing 100710, China
    4. School of Aeronautical Engineering, Civil Aviation University of China, Tianjin 300300, China
  • Received:2021-04-15 Online:2021-09-10 Published:2021-09-22
  • Contact: SUI He E-mail:hsui@caucedu.cn

摘要:

仿真建模是ICS网络安全中一个重要的研究方法,但纯软件的仿真方法存在安全功能建模困难、缺乏核心控制层响应等问题,导致目标系统网络安全防护重点模糊、面对攻击的防护能力差。结合实际研究中仿真建模不灵活和测试方法不全面等情况,文章面向民航工业控制系统提出一种基于半实物平台的机场供油自控系统网络安全测试方法。首先,使用DCS设计模式分层搭建半实物仿真测试平台,采用PLC作为核心控制器构建收/发油模块、倒罐模块和罐群管理模块。随后,以攻击者完成系统入侵为前提,分别采用ARP攻击、洪泛攻击、工业协议篡改攻击对系统的生产流程进行网络测试攻击,采用组态演示界面和实物共同验证攻击效果。最后,利用工业防火墙与网闸进行防护能力测试验证,并给出机场供油自控系统防护意见。

关键词: 工业控制系统, 机场供油自控系统, 半实物平台, 网络安全测试

Abstract:

Simulation modeling is an important research method in ICS network security, but pure software simulation methods have difficulties in modeling security functions and lacking of response from the core control layer, which leads to the blurred focus of network security protection of the target system and the deterioration of the ability to defend against attacks. Combining the shortcomings of inflexible simulation modeling and incomplete testing methods in actual research,this paper proposed a network security testing method for airport fuel supply automatic control system based on a semi-physical platform for civil aviation industry control systems. Firstly, the DCS design model was used to build a semi-physical simulation test platform, and PLC was used as the core controller to construct the oil sending and receiving module, the tank dumping module and the tank group management module. Subsequently, based on the premise that the attacker completed the system intrusion, ARP attacks, flooding attacks, and industrial protocol tampering attacks were used to conduct network test attacks on the production process of the system, and the configuration demonstration interface and physical objects were used to jointly verify the attack effect. Finally, industrial firewalls and gatekeepers were used to test and verify the protection capabilities, and the protection opinions of airport fuel supply automatic control system were given.

Key words: industrial control system, airport fuel supply automatic control system, semi-physical platform, network security test

中图分类号: