Netinfo Security ›› 2017, Vol. 17 ›› Issue (7): 73-79.doi: 10.3969/j.issn.1671-1122.2017.07.011

• Orginal Article • Previous Articles     Next Articles

Research on Configuration Software for Industrial Control System

Zixian XU1(), Jian LUO2, Nan MENG1, Xiangnan ZHAO1   

  1. 1. China Academy of Information and Communications Technology, Beijing 100191, China
    2. ICESEC Information Security Co. Ltd. Shenzhen Guangdong 518000, China
  • Received:2017-04-01 Online:2017-07-20 Published:2020-05-12

Abstract:

With the continuous development of automatic control technology, in the combination of industry automation control and computer information technology, more and more widely used, and gradually formed the industrial control system based on automatic control. Hackers have also turned their attention from previous attacks on Web servers to industrial control systems. By attacking the industrial control system not only pose a threat to the network system, and even destroy the industrial infrastructure, endangering personal safety and national security, industrial control system security has been widespread concern. Configuration software is an important part of industrial control system software, and its security will directly affect the safety of the whole industrial control system. This paper summarizes the characteristics of the industrial control system configuration software and the security risks, and to buffer overflow vulnerabilities as examples to analyze causes, attack and harm, and finally puts forward the security building on configuration software business logic, rights management, deployment, enhance the ability of security protection of the industrial control system and configuration software.

Key words: industrial control safety, configuration security, configuration software, buffer overflow

CLC Number: