论文部分内容阅读
[据欧盟网络和信息安全局网站2013年12月6日报道]欧盟网络和信息安全局已经认定了一些有关补丁的最佳实践和建议,它们能够改进管理控制和数据采集(SCADA)系统(工业控制系统(ICS)的子系统)环境的安全状况,主要有以下几点:补偿性控制;通过给网络各分段增加深度防御,以创造可信区域,并使用访问控制来交流;通过删除不必要的功能硬化SCADA系统;使用一些技巧,如应用程序白名单和深度包检测技术;补丁管理程序和服务合同;资产所有者应该建立一个补丁管理服务协定,以界定供应商和客户在补丁管理流程中的责任;资产所有者应该随时进行自己的测试,这可以通过维护不同的系统来完
[According to the website of the European Union’s Internet and Information Security Agency, December 6, 2013] The European Union’s Office of Cyber Security and Information Security has identified some best practices and recommendations for patches that improve the management and control and data acquisition (SCADA) system, Control System (ICS) Subsystem) The environmental safety conditions are mainly as follows: Compensatory control; By adding a deep defense to each segment of the network to create a trustworthy zone and using access control to communicate; By deleting Necessary Features Hardening SCADA systems; Using techniques such as application whitelist and deep packet inspection techniques; Patch management procedures and service contracts; Asset owners should establish a patch management service agreement that defines the process for vendor and customer patch management In the responsibility; asset owners should carry out their own tests at any time, which can be done by maintaining different systems