信息网络安全 ›› 2025, Vol. 25 ›› Issue (3): 341-363.doi: 10.3969/j.issn.1671-1122.2025.03.001

• 综述论文 • 上一篇    下一篇

工业控制系统安全研究综述

金增旺1,2, 江令洋1, 丁俊怡1, 张慧翔1(), 赵波1, 方鹏飞3   

  1. 1.西北工业大学网络空间安全学院,西安 710072
    2.西北工业大学太仓长三角研究院,太仓 215400
    3.国家工业信息安全发展研究中心,北京 100040
  • 收稿日期:2024-12-25 出版日期:2025-03-10 发布日期:2025-03-26
  • 通讯作者: 张慧翔 E-mail:zhanghuixiang@nwpu.edu.cn
  • 作者简介:金增旺(1990—),男,福建,副教授,博士,主要研究方向为工业协议安全分析和工业控制系统安全分析|江令洋(1999—),男,河南,硕士研究生,主要研究方向为工业控制安全和模糊测试|丁俊怡(2003—),女,安徽,硕士研究生,主要研究方向为工业控制安全和模糊测试|张慧翔(1981—),男,陕西,副教授,博士,主要研究方向为网络与系统安全|赵波(1992—),男,山东,副教授,博士,主要研究方向为无人系统安全分析、空天地一体化网络安全传输协议|方鹏飞(1986-),男,北京,工程师,硕士,主要研究方向为协议逆向分析、工业控制系统安全
  • 基金资助:
    国家重点研发计划(2022YFB3104005);太仓市基础研究计划(TC2022JC17)

A Review of Research on Industrial Control System Security

JIN Zengwang1,2, JIANG Lingyang1, DING Junyi1, ZHANG Huixiang1(), ZHAO Bo1, FANG Pengfei3   

  1. 1. School of Cybersecurity, Northwestern Polytechnical University, Xi’an 710072, China
    2. Yangtze River Delta Research Institute, Northwestern Polytechnical University, Taicang 215400, China
    3. China Industrial Control Systems Cyber Emergency Response Team, Beijing 100040, China
  • Received:2024-12-25 Online:2025-03-10 Published:2025-03-26
  • Contact: ZHANG Huixiang E-mail:zhanghuixiang@nwpu.edu.cn

摘要:

随着工业4.0和智能制造的快速发展,工业控制系统的安全性成为关键问题。工业控制协议作为工业控制系统的核心通信机制,其安全性直接关系到系统的稳定性和数据保护。然而,许多工业控制协议在设计时缺乏充分的网络安全考虑,导致系统容易受到恶意软件、拒绝服务等攻击,可能危及企业利益甚至国家安全。当前,研究者们正积极探索工业控制协议的安全问题,并提出了多种解决方案。文章综述了工业控制协议的安全现状、主要挑战和发展趋势。首先,介绍了工业控制协议的基本概念和分类,分析了其安全特性及脆弱性。然后,重点讨论了符号执行、逆向分析和模糊测试在漏洞挖掘中的应用,这些技术在应对复杂工业协议时尤为有效。而且还探讨了加密认证、入侵检测及深度防御等安全防护措施。最后,文章探索了生成式大语言模型在工业控制系统安全中的应用,涉及代码生成、网络防护及自动化控制等领域,助力工业控制系统从被动防御向主动防护转变。通过本研究,期望能够提升对工业控制协议安全性的认识,为工业控制系统的可靠性和安全性提供坚实的基础和实用的解决方案,以有效保护关键信息基础设施免受潜在威胁和攻击。

关键词: 工业控制协议安全, 深度学习, 模糊测试, 入侵检测

Abstract:

With the rapid advancement of Industry 4.0 and smart manufacturing, the security of industrial control systems (ICS) has become a critical concern. As the core communication mechanisms of ICS, industrial control protocols are essential for maintaining system stability and protecting data. However, many industrial control protocols lack sufficient network security considerations in their design, making the systems vulnerable to cyberattacks such as malicious software and denial of service, which may endanger corporate interests and even national security. This paper provided a comprehensive review of the security landscape, major challenges, and development trends of industrial control protocols. Firstly, the basic concepts and classifications of industrial control protocols were introduced, and their security characteristics and vulnerabilities were analyzed. Subsequently, the application of symbolic execution, reverse analysis, and fuzz testing in vulnerability mining was discussed in detail. These technologies were particularly effective when dealing with complex industrial protocols. The paper also examined security measures such as encryption, authentication, intrusion detection, and layered defenses. Finally, it explored the application of generative large language models in ICS security, focusing on code generation, network protection, and automation control. These advancements enable ICS to transition from passive defense to proactive protection strategies. Through this research, we aim to enhance the understanding of the security challenges in industrial control protocols and provide practical solutions to improve the reliability and safety of ICS, thereby effectively safeguarding critical infrastructure from potential threats and attacks.

Key words: industrial control protocol security, deep learning, fuzz testing, intrusion detection

中图分类号: