首页> 外文会议>Annual International Conference on Privacy, Security and Trust >Securing Promiscuous Use of Untrusted USB Thumb Drives in Industrial Control Systems
【24h】

Securing Promiscuous Use of Untrusted USB Thumb Drives in Industrial Control Systems

机译:在工业控制系统中确保滥交使用不受信任的USB拇指驱动器

获取原文

摘要

Industrial Control Systems (ICS) are sensible targets for high profile attackers and advanced persistent threats, which are known to exploit USB thumb drives as an effective spreading vector. In ICSes, these devices are widely used to transfer files among disconnected systems and represent a serious security risks, since, they may be promiscuously used in both critical and regular systems. We show a method that adopts cryptographic techniques to inhibit critical machines from reading possibly malicious files coming from regular machines on untrusted USB thumb drives. Our approach exposes limited attack surface for any malware, even those based on zero-days. We do not require users to change the way they use removable storage devices, or to authenticate. Our approach can be adopted for disconnected machines and does not need complex key management. We describe the architecture of our solution and provide a thorough analysis of the security of our approach in the ICS context.
机译:工业控制系统(IC)是高调攻击者和高级持久威胁的明智目标,已知将USB Thumb驱动器作为一种有效的扩展向量来利用USB Thumb驱动器。 在ICSES中,这些设备广泛用于传输断开连接的系统之间的文件,并且代表严重的安全风险,因为它们可能会在关键和常规系统中进行混乱地使用。 我们展示了一种采用加密技术来禁止关键机器,从读取来自不受信任的USB拇指驱动器上的常规机器的可能性文件来禁止关键机器。 我们的方法为任何恶意软件公开有限的攻击面,即使是基于零天的那些。 我们不要求用户更改他们使用可移动存储设备或进行身份验证的方式。 我们的方法可以用于断开连接的机器,不需要复杂的密钥管理。 我们描述了我们解决方案的架构,并对ICS上下文中的方法进行了全面的分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号