[1]郑铁军,王 齐,张宏杰,等.基于组合扫描的无状态工控设备资产探测方法[J].计算机技术与发展,2023,33(07):98-103.[doi:10. 3969 / j. issn. 1673-629X. 2023. 07. 015]
 ZHENG Tie-jun,WANG Qi,ZHANG Hong-jie,et al.Stateless Industrial Control Equipment Asset Detection Method Based on Combined Scanning[J].,2023,33(07):98-103.[doi:10. 3969 / j. issn. 1673-629X. 2023. 07. 015]
点击复制

基于组合扫描的无状态工控设备资产探测方法()
分享到:

《计算机技术与发展》[ISSN:1006-6977/CN:61-1281/TN]

卷:
33
期数:
2023年07期
页码:
98-103
栏目:
移动与物联网络
出版日期:
2023-07-10

文章信息/Info

Title:
Stateless Industrial Control Equipment Asset Detection Method Based on Combined Scanning
文章编号:
1673-629X(2023)07-0098-06
作者:
郑铁军1 王 齐23 张宏杰1 贺建伟1 雍少华4 孙知信5
1. 国网宁夏电力有限公司,宁夏 银川 750010;
2. 国网智能电网研究院有限公司,江苏 南京 210003;
3. 信息网络安全国网重点实验室,江苏 南京 210003;
4. 国网中卫供电公司,宁夏 中卫 755099;
5. 南京邮电大学 现代邮政学院,江苏 南京 210003
Author(s):
ZHENG Tie-jun1 WANG Qi23 ZHANG Hong-jie1 HE Jian-wei1 YONG Shao-hua4 SUN Zhi-xin5
1. State Grid Ningxia Electric Power Co. ,Ltd. ,Yinchuan 750010,China;
2. State Grid Smart Grid Research Institute Co. ,Ltd. ,Nanjing 210003,China;
3. State Grid Key Laboratory of Information & Network Security,Nanjing 210003,China;
4. State Grid Zhongwei Electric Power Supply Company,Zhongwei 755099,China;
5. School of Modern Posts,Nanjing University of Posts and Telecommunications,Nanjing 210003,China
关键词:
工业控制系统资产探测工控设备端口扫描异步处理
Keywords:
industrial control systemasset detectionindustrial control equipmentport scanningasynchronous processing
分类号:
TP393
DOI:
10. 3969 / j. issn. 1673-629X. 2023. 07. 015
摘要:
全面探测工控设备资产信息、了解资产状态是确保工业控制系统安全的重要前提。 端口探活是进行资产探测的第一步,端口探活的准确率和效率将直接影响资产探测的性能。 为提升端口探活的速度和准确性,提出了一种基于组合扫描的异步无状态端口扫描方法。 通过构造组合扫描数据包,解决工控设备因禁 ping 导致主机探活准确率降低的问题,同时建立发送数据包线程和接收数据包线程,实现组合扫描数据包的异步处理,消除了传统无状态扫描的回复等待时间,缩短了端口探活时间。 最后以 Modbus 协议为例,构造了资产请求数据包,并分析了数据包中主要字段和功能。 测试结果表明,提出的资产探测方法在端口探活阶段单位时间内可以探测到更多的设备,同时能在较短的时间内完成完整资产信息的探测,在探测准确度和探测时间方面都得到了提升。
Abstract:
Comprehensive detection of the asset information of industrial control equipment and understanding the asset status?
is animportant prerequisite to ensure the safety of industrial control system. Port detection is the first step of asset detection. The accuracy andefficiency of port detection will directly affect the performance of asset detection. In order to improve the speed and accuracy of port detection,an asynchronous stateless port scanning method based on combined scanning is proposed. By constructing combined scanningdata packets,the problem that the accuracy rate of host detection is reduced due to the prohibition of Ping in industrial control equipmentis solved. At the same time,a sending packet thread and a receiving packet thread are established to realize asynchronous processing ofcombined scanning packets,which eliminates the reply waiting time of traditional stateless scanning and shortens the port detection time. Finally,taking Modbus protocol as an example,the asset request data packet is constructed,and the main fields and functions in the datapacket are analyzed. The test results show that the proposed asset detection method can detect more equipment per unit time in the portdetection stage,and complete the detection of complete asset information in a shorter time,which improves the detection accuracy and detection time.

相似文献/References:

[1]胡建华,刘鑫朝,李辉.基于. NET的动态实时曲线的绘制方法[J].计算机技术与发展,2013,(03):179.
 HU Jian-hua,LIU Xin-chao,LI Hui.Method of Dynamic Real-time Curve Drawing Based on . Net[J].,2013,(07):179.
[2]刘知竹,冯璐,荀鹏,等.基于分散化序列的联网 ICS 设备搜索技术[J].计算机技术与发展,2018,28(11):1.[doi:10.3969/ j.issn.1673-629X.2018.11.001]
 LIU Zhi-zhu,FENG Lu,XUN Peng,et al.Networked ICS Device Search Technique Based on Dispersed Sequence[J].,2018,28(07):1.[doi:10.3969/ j.issn.1673-629X.2018.11.001]
[3]刘 俊,陈 慧,王 军.基于区块链的 ICS 数据安全策略研究[J].计算机技术与发展,2021,31(01):149.[doi:10. 3969 / j. issn. 1673-629X. 2021. 01. 027]
 LIU Jun,CHEN Hui,WANG Jun.Research on Data Security Strategy of ICS Based on Blockchain[J].,2021,31(07):149.[doi:10. 3969 / j. issn. 1673-629X. 2021. 01. 027]
[4]赵东东,石乐义,谢云飞.基于 CP-ABE 的工业控制系统加密传输方案[J].计算机技术与发展,2022,32(10):94.[doi:10. 3969 / j. issn. 1673-629X. 2022. 10. 016]
 ZHAO Dong-dong,SHI Le-yi,XIE Yun-fei.Encrypted Transmission Scheme of Industrial Control System Based on CP-ABE[J].,2022,32(07):94.[doi:10. 3969 / j. issn. 1673-629X. 2022. 10. 016]
[5]姚 旭,王 钢,任秀勤,等.基于发电厂控制系统的工控蜜罐设计与实现[J].计算机技术与发展,2022,32(10):114.[doi:10. 3969 / j. issn. 1673-629X. 2022. 10. 019]
 YAO Xu,WANG Gang,REN Xiu-qin,et al.Design and Implementation of Industrial Control Honeypot Based on Power Plant Control System[J].,2022,32(07):114.[doi:10. 3969 / j. issn. 1673-629X. 2022. 10. 019]
[6]韩子彬.选煤厂工控网络安全实验分析[J].计算机技术与发展,2022,32(S2):162.[doi:10. 3969 / j. issn. 1673-629X. 2022. S2. 029]
 HAN Zi-bin.Experimental Analysis of Industrial Control Network Security in Coal Preparation Plant[J].,2022,32(07):162.[doi:10. 3969 / j. issn. 1673-629X. 2022. S2. 029]

更新日期/Last Update: 2023-07-10