...
首页> 外文期刊>IFAC PapersOnLine >Experimentation environment for industrial control systems cybersecurity: On-site and remote training
【24h】

Experimentation environment for industrial control systems cybersecurity: On-site and remote training

机译:工业控制系统网络安全的实验环境:现场和远程培训

获取原文
           

摘要

The digital transformation of industries implies the need of new training efforts. In this context, cybersecurity of industrial control systems (ICS) poses specific challenges. The current practice of ICS cybersecurity training is generally restricted to the isolated management of industrial and network devices or extensive use of network traffic emulation/simulation, providing the students a limited understanding of the problem. For that reason, in this paper, we present an approach based on the replication of a simple industrial control system. For that purpose, a control cabinet, which covers the lowest levels of the automation pyramid, and a set of virtual machines (VMs) are used. The aim is to provide a flexible experimentation environment where all elements can be reconfigured. Through the deployment of the appropriate network structure, students can carry out device configurations or assume different roles in the industrial control system, from the points of view of automation or security. The experimentation environment is also designed to provide a comprehensive remote access to hardware, software and communication networks in a reliable way (flexibility), without posing a threat to the security and safety of the environment (isolation) or requiring time-consuming maintenance (easy recovery of VMs and equipment). Through the architecture defined, students can reach the VMs used in each task, which are isolated from the outer network and can be easily managed and maintained. Finally, some educational activities are presented, where the proposed approach is used for training of students with different backgrounds.
机译:行业的数字化转型意味着需要进行新的培训。在这种情况下,工业控制系统(ICS)的网络安全构成了特殊的挑战。 ICS网络安全培训的当前实践通常限于对工业和网络设备的隔离管理或对网络流量仿真/模拟的广泛使用,从而使学生对问题的理解有限。因此,在本文中,我们提出了一种基于简单工业控制系统的复制方法。为此,使用了覆盖自动化金字塔最低层的控制柜和一组虚拟机(VM)。目的是提供一个灵活的实验环境,在其中可以重新配置所有元素。通过部署适当的网络结构,学生可以从自动化或安全性的角度进行设备配置或在工业控制系统中扮演不同的角色。实验环境还旨在以可靠的方式(灵活性)提供对硬件,软件和通信网络的全面远程访问,而不会对环境的安全性和安全性造成威胁(隔离)或需要耗时的维护(轻松)虚拟机和设备的恢复)。通过定义的体系结构,学生可以访问每个任务中使用的VM,这些VM与外部网络隔离,并且可以轻松地进行管理和维护。最后,介绍了一些教育活动,其中所建议的方法用于培训具有不同背景的学生。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号