 您的位置 :首页 >> 期刊查询>> 专题研究  >>正文

文章标题: 配电自动化终端信息安全风险测评方法研究
发表期次: 2015 年 12 期
作者名: 林永峰 陈 亮 张国强
作者单位: 国网天津市电力公司电力科学研究院,天津 300384
关键词: 配电自动化;信息安全;测评;实验平台;漏洞
中文摘要:     为解决配电自动化终端由于自身的复杂性、设计缺陷以及病毒、木马等威胁导致的信息安全问题,从系统层、通信层、配置层分析配电终端可能存在的信息安全风险,提出包括配置核查、漏洞扫描、渗透测试、风险值计算等在内的一整套信息安全测评方法,及规范化的测评工作流程。通过抽象配电自动化系统网络与业务模型,给出搭建测试实验平台方法,为开展配电终端信息安全测评与漏洞检测提供实验环境。该方法已应用于实际工作中,能够有效解决配电终端存在的信息安全隐患。

Research of Distribution Automation Terminal Information Security Risk Evaluation Methods

LIN Yong-feng,CHEN Liang,ZHANG Guo-qiang
(The Electric Power Research Institute of State Grid Tianjin Electric Power Company,Tianjin 300384,China)
Abstract:In order to solve the information security attacks of distribution automation terminal caused by its own complexity,design flaws as well as viruses,Trojans and other threats,this paper analyzed the information security risk which may exist in distribution automation terminal from the system layer,communication layer and distribution layer,presented a set of distribution automation terminal information security evaluation methods,including configuration checking,vulnerability scanning,penetration testing,risk value calculating,and standardization work flow of evaluation.By distributing automation system network and business models,the paper put forward a method to build the test platform,which provided the experimental environment for developing information security evaluation and vulnerability detection of automation terminal. The method has been applied in practical work to solve the information security risks existing in distribution automation terminal.
Key words:distribution automation;information security;evaluation;experimental platform;vulnerability

设为首页 | 加入收藏 | 联系我们  | 我要留言

地址:天津市河西区体院北环湖中道9号 邮编:300060
编辑部:022-23015608 广告部:022-23016582 传真:022-23015614

津公网安备 12010302001660号

津ICP备12003767号   Email:zdhyyb@vip.sina.com   咨询:刘先生 
Copyright 2023 zdhyyb.com, All Rights Reserved  版权所有 自动化与仪表网