Be secure

被引:22
作者
Creery, Adam A.
Byres, E. J.
机构
[1] Universal Dynamics Ltd., Richmond, BC, Canada
[2] Byres Security Inc., Canada
关键词
Electric power plants - Electric power system protection - Electric power transmission networks - Interconnection networks - Process control - SCADA systems - Security systems;
D O I
10.1109/MIA.2007.4283509
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In today's interconnected networks, the possibility of breaching security in plant systems are not to be ignored. They are in fact vulnerable. As such, there is now a growing interest in ensuring that systems are secured. One useful guide is the ISA's Technical Report ISA-TR99.00.02-2004 Integrating Electronic Security into the Manufacturing and Control Systems Environment. There are also mitigation measures that can be followed. For instance, an inventory of networked control devices must be developed and the creation of an outline of the key devices on the network through network diagrams of the control network system. There are also tools, such as vulnerability assessment (VA) scanning tools determine if devices attached to the network are correctly configured and patched. An assessment report will then be made from the surveying of the various concerns and gaps, if found then compared with current best practices. On the other hand, protective measures are also a helpful tool. In order to ensure security implementations crossing IT/process boundaries, there will be a need to improve the communication and execution of security solutions between the IT group and the control engineers in the process area. Although looked at as unnecessary, unnecessary services and applications from process control computer must be removed including which may only increase the opportunities for a hacker or virus to exploit the system.
引用
收藏
页码:49 / 55
页数:7
相关论文
共 13 条
[1]  
API 1164, 2004, 1164 API
[2]  
*BSI, 1995, BSI 7799
[3]  
BYRES E, P VDE C 2004 BERLIN
[4]  
DAMICO E, 2002, CHEM WEEK AUG, V164
[5]  
FRASER B, 1997, RCF 2196 SITE SECURI, P21
[6]  
*ISO, 2000, 17799 ISO IEC
[7]  
LOWE J, 2003, P EL SEC SCADA CONTR
[8]  
NIST, 1995, INTR COMP SEC NIST H
[9]  
North American Electric Reliability Council, 2003, SQL SLAMM WORM LESS
[10]  
RODRIGUEZ A, 2001, TCP IP TUTORIAL TECH