首页|基于模糊测试技术的工控协议安全性分析系统

基于模糊测试技术的工控协议安全性分析系统

扫码查看
随着网络犯罪和网络威胁的不断演化,工控系统的安全性已经成为一个紧迫的问题.因此,设计安全性分析引擎用于检测协议中的潜在漏洞,利用模糊测试生成的数据包进行深入分析.实验结果表明,针对3种不同协议,本文提出的方法拒绝率分别达到了 30.7%、41%和42.1%.特别是在Modbus协议下,拒绝率约为30%.此外,本文方法显著增加了协议覆盖路径的数量,平均提高了 23.7%.因此,通过协议模糊测试提高工控系统的安全性,有助于减少潜在的威胁和漏洞,确保系统的可靠性.
Industrial Control Protocol Security Analysis System Based on Fuzzy Testing Technology
With the continuous evolution of cybercrime and cyber threats,the security of industrial control systems becomes an urgent issue.This paper designs a security analysis engine to detect potential vulnerabilities in protocols,and conducts in-depth analysis using data packets generated by fuzzy testing.The experimental results show that the proposed method achieves rejec-tion rates of 30.7%,41%,and 42.1%for three different protocols,respectively.Especially under the Modbus protocol,the rejection rate is about 30%.In addition,the proposed method significantly increased the number of protocol coverage paths,with an average improvement of 23.7%.Therefore,it improves the security of industrial control systems through protocol fuzzy testing,which can help reduce potential threats and vulnerabilities,and ensure the reliability of the system.

fuzzy testingindustrial control protocolsecurity researchvulnerability detectioncoverage path

许伟杰、邹洪、张佳发、曾子峰、江家伟

展开 >

南方电网数字电网集团信息通信科技有限公司,广东,广州 510663

模糊测试 工控协议 安全性研究 漏洞检测 覆盖路径

2024

微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
年,卷(期):2024.40(9)