微型电脑应用2024,Vol.40Issue(9) :250-253.

基于模糊测试技术的工控协议安全性分析系统

Industrial Control Protocol Security Analysis System Based on Fuzzy Testing Technology

许伟杰 邹洪 张佳发 曾子峰 江家伟
微型电脑应用2024,Vol.40Issue(9) :250-253.

基于模糊测试技术的工控协议安全性分析系统

Industrial Control Protocol Security Analysis System Based on Fuzzy Testing Technology

许伟杰 1邹洪 1张佳发 1曾子峰 1江家伟1
扫码查看

作者信息

  • 1. 南方电网数字电网集团信息通信科技有限公司,广东,广州 510663
  • 折叠

摘要

随着网络犯罪和网络威胁的不断演化,工控系统的安全性已经成为一个紧迫的问题.因此,设计安全性分析引擎用于检测协议中的潜在漏洞,利用模糊测试生成的数据包进行深入分析.实验结果表明,针对3种不同协议,本文提出的方法拒绝率分别达到了 30.7%、41%和42.1%.特别是在Modbus协议下,拒绝率约为30%.此外,本文方法显著增加了协议覆盖路径的数量,平均提高了 23.7%.因此,通过协议模糊测试提高工控系统的安全性,有助于减少潜在的威胁和漏洞,确保系统的可靠性.

Abstract

With the continuous evolution of cybercrime and cyber threats,the security of industrial control systems becomes an urgent issue.This paper designs a security analysis engine to detect potential vulnerabilities in protocols,and conducts in-depth analysis using data packets generated by fuzzy testing.The experimental results show that the proposed method achieves rejec-tion rates of 30.7%,41%,and 42.1%for three different protocols,respectively.Especially under the Modbus protocol,the rejection rate is about 30%.In addition,the proposed method significantly increased the number of protocol coverage paths,with an average improvement of 23.7%.Therefore,it improves the security of industrial control systems through protocol fuzzy testing,which can help reduce potential threats and vulnerabilities,and ensure the reliability of the system.

关键词

模糊测试/工控协议/安全性研究/漏洞检测/覆盖路径

Key words

fuzzy testing/industrial control protocol/security research/vulnerability detection/coverage path

引用本文复制引用

出版年

2024
微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
段落导航相关论文