基于模糊测试的工控系统漏洞发现和分析系统研究
2018-10-21孟强孟瑜炜俞荣栋
孟强 孟瑜炜 俞荣栋
摘要:工业控制系统是国家关键基础设施的重要组成部分,其在与信息化技术高度融合的过程中,面临着严峻的网络与信息安全风险的挑战。作为最常见的网络攻击方式,漏洞的利用攻击占据了工业控制系统安全事件中的绝大多数。因此,如何有效识别和发现工控系统漏洞,成为了解决工控系统安全问题的重要方面。模糊测试技术,由于不严格依赖于协议和系统逆向,一直以来都是漏洞发现的有效手段。然而,由于工控系统自身相对封闭的架构、相对苛刻的运行环境以及大量工控私有协议在线运行等实际问题,使得利用模糊测试的技术手段发现工控系统漏洞存在更大的挑战。本文从模糊测试技术的原理和发展现状入手,总结梳理了工控系统模糊测试技术的制约和限制条件。结合现有工控系统模糊测试工具和架构,提出了基于模糊测试的工控系统漏洞发现和分析系统的总体设计思路,依托抽象化的工控系统模糊测试通用架构,可以实现基于模糊测试技术的工控系统漏洞挖掘平台的定义和高效工具开发,对于指导相关工具研制具有重要意义。
关键词:工业控制系统;模糊测试;漏洞发现;漏洞分析;通用架构
Research on Fuzzing Testing Based Vulnerability Mining and Analysis System for Industrial Control Systems
MENG Qiang1,3,MENG Yuwei1,3,YU Rongdong2,3*
1 Zhejiang Energy Group,Hangzhou,Zhejiang,310007;
2 Zhejiang Energy Industrial Information Engineering Provincial Key Enterprise Research Institute,Hangzhou,Zhejiang,311121;
3 Zhejiang Energy Group Research Institute,Hangzhou,Zhejiang,311121
ABSTRACT:Industrial Control Systems(ICS)are the most important part of the national critical infrastructure. Within the merging process between the industrial control systems and information technologies,ICS is facing severe challenges in cyber security. As the most common cyber attacks,the vulnerabilities exploits are taking the majority of the cyber security incidents in ICS. Therefore,how to effectively identify and finding hidden vulnerabilities in ICS is becoming the key issue in ICS security area. Fuzzing testing,which may not strictly depend on the reverse engineering,is widely recognized as the effective means. However,due to the relatively closed architecture,the tough running environment,as well as the running proprietary protocols,there exists more challenges when using fuzzing testing in ICS. In this paper,we firstly review the theory of the fuzzing testing,and survey the current technical schemes. Based on the current fuzzing testing tools and frameworks,we propose a general architecture of the fuzzing testing based vulnerability mining and analysis system,which is based on a general model of the fuzzing testing framework for ICS. The general architecture is significant for the definition of the vulnerability mining and analysis system,and will promote the efficient development of the new fuzzing testing tools used for ICS.
KEY WORDS:Industrial control systems,Fuzzing testing,Vulnerability mining,General framework.
1引言
以电力网络、供水网络、天然气管网为代表的关键基础设施通常由工业控制系统实现数据采集与状态监管[1]。工业控制系统(ICS,Industrial Control System)通常包括过程控制系統(PCS,Process Control System),分布式控制系统(DCS,Distributed Control System),监视控制与数据采集(SCADA,Supervised Control And Data Acquisition)系统等[1,2]。……
