中文

拒绝服务攻击下实时工业设备架构分析

密码学与安全 2020-07-20 v1

摘要

越来越多的工业设备连接到基于 IP 的网络,这对于工业 4.0 的成功至关重要。然而,这种互联也导致了针对各类基于网络攻击的攻击面增加。最容易实施的攻击之一是 DoS 攻击,其中被攻击目标因高网络流量及相应 CPU 负载而过载。因此,被攻击设备无法再提供其常规服务。这对于在工业过程中执行实时操作的设备尤为关键。为防御 DoS 攻击,可在边界处限制网络流量(例如通过防火墙)或开发鲁棒的设备架构。本文分析了多种安全设备架构的概念,并针对其抵御 DoS 攻击的鲁棒性进行比较。此处特别关注工业控制器的控制过程在攻击期间的行为。为此,我们在不同网络负载与额外系统压力下,比较了单核与双核基于 Linux 的系统以及异构多核架构上的不同调度器。

关键词

引用

@article{arxiv.2007.08885,
  title  = {Analysis of Industrial Device Architectures for Real-Time Operations under Denial of Service Attacks},
  author = {Florian Fischer and Matthias Niedermaier and Thomas Hanka and Peter Knauer and Dominik Merli},
  journal= {arXiv preprint arXiv:2007.08885},
  year   = {2020}
}

备注

First published in the 22nd International Conference on Information and Communications Security (ICICS 2020)