信息网络安全 ›› 2024, Vol. 24 ›› Issue (11): 1710-1720.doi: 10.3969/j.issn.1671-1122.2024.11.010

• 入选论文 • 上一篇    下一篇

Modbus TCP协议安全风险分析及对策研究

马如坡(), 王群, 尹强, 高谷刚   

  1. 江苏警官学院计算机信息与网络安全系,南京 210031
  • 收稿日期:2024-07-03 出版日期:2024-11-10 发布日期:2024-11-21
  • 通讯作者: 马如坡 mrpjet@163.com
  • 作者简介:马如坡(1980—),男,河南,讲师,博士,主要研究方向为工业互联网安全、安全防范技术|王群(1971—),男,甘肃,教授,博士,CCF杰出会员,主要研究方向为网络空间安全|尹强(2001—),男,江苏,本科,主要研究方向为工业互联网安全|高谷刚(1974—),男,江苏,高级实验师,博士,主要研究方向为智慧警务、人工智能
  • 基金资助:
    “十四五”江苏省重点学科“网络空间安全”建设项目;江苏本科高校卓越工程师教育培养计划2.0专业项目(安全防范工程专业)

Analysis of Security Risks and Countermeasures for Modbus TCP Protocol

MA Rupo(), WANG Qun, YIN Qiang, GAO Gugang   

  1. Department of Computer Information and Cyber Security, Jiangsu Police Institute, Nanjing 210031, China
  • Received:2024-07-03 Online:2024-11-10 Published:2024-11-21

摘要:

工业互联网作为新一代信息技术与工业系统深度融合的产物,正推动着工业生产方式的变革。然而,工控网络协议在设计之初因注重效率提升和功能实现忽视了一些安全性问题,加之应用中的安全漏洞和异常行为,导致其存在严峻的安全隐患。文章介绍了工业互联网的发展背景、趋势和工控网络协议特点,分析了当前应用最广泛的典型工控网络协议Modbus TCP的安全风险,研究了数据加密、数据完整性检测、身份认证及异常入侵检测等安全对策,提出一套Modbus TCP协议安全方案。该方案包含采用AES算法和RSA算法的数据加密和解密模块、采用SM3算法的数据完整性检测模块、采用动态口令认证技术的身份认证模块和基于数据特征的异常入侵检测系统,同时引入PKI进一步加强工控系统的安全性,为其他工控网络协议的安全防范提供借鉴和参考。

关键词: 工业互联网, 工控网络协议, Modbus TCP, 安全风险分析

Abstract:

As the product of the deep integration of new generation information technology and industrial system, industrial internet is promoting the transformation of industrial production mode. However, in the initial design of industrial control network protocols, some security issues are overlooked due to the emphasis on efficiency improvement and functional implementation. In addition, security vulnerabilities and abnormal behaviors in applications have led to serious security risks. This paper introduced the development background and trend of industrial Internet and the characteristics of industrial control network protocol, analyzed the security risks of the typical industrial control network protocol Modbus TCP, which was widely used at present, studied the security countermeasures such as data encryption, data integrity detection, identity authentication and anomaly intrusion detection, and finally proposed a set of security scheme of Modbus TCP protocol. This scheme included data encryption and decryption modules using AES and RSA algorithms, data integrity detection module using SM3 algorithm, identity authentication module using dynamic password authentication technology, and anomaly intrusion detection system based on data features. At the same time, the scheme adopted PKI, which could further enhance the security of the industrial control system.

Key words: industrial internet, industrial control network protocol, Modbus TCP, safety risk analysis

中图分类号: