★ 關玲,楊繼武 濟南熱電集團有限公司
★ 原穎平,魏磊 北京網御星云信息技術有限公司
摘要:近年來,全球工業控制系統網絡安全態勢日益復雜嚴峻,世界范圍內針對工業控制系統的入侵、病毒、木馬攻擊等行為大幅增長。頻發的惡性安全事故,對人員、設備、公共安全環境等造成嚴重危害。特別是震驚世界的伊朗核電站“震網”病毒事件,再次給全球工業界控制系統的信息安全問題敲響了警鐘,加強工業控制系統的信息安全防護已經成為廣泛共識,相關標準、技術、方案和設備日趨完善。本文通過對熱源廠現場的實際網絡安全調研和風險評估,總結出熱源廠的整體安全風險,梳理出現場的安全需求,并結合國家相關行業標準以及政策法規,通過針對熱源廠網絡安全設計和主機安全設計加強了該廠的整體安全能力,對整個市政供熱行業起到了示范效應,可在同行業進行復制推廣。
關鍵詞:關鍵基礎設施;熱源廠;工業互聯網;網絡安全
Abstract: In recent years, the global industrial control system network security situation has become increasingly complex and severe, and the intrusion, virus, Trojan horse attack and other behaviors against industrial control systems all over the world have increased significantly. Frequent malignant safety accidents cause serious harm to personnel, equipment and public safety environment. In particular, the "Earthquake Network" virus incident of Iran's nuclear power plant, which shocked the world, once again sounded an alarm for the information security of the global industrial control system. It has become a broad consensus to strengthen the information security protection of industrial control system, the relevant standards,technologies, schemes and equipment are becoming more and more perfect. Based on the actual network security investigation and risk assessment of the heat source plant site, this paper summarizes the overall security risks of the heat source plant and combs out the security needs of the site. Combined with relevant national industry standards, policies and regulations, this paper strengthens the overall security capacity of the plant through the network security design and host security design of the heat source plant, it has played a demonstration effect on the whole municipal heating industry and can be replicated and popularized in the same industry.
Key words: Critical infrastructure; Heat source plant; Industrial Internet; Network security
摘自《自動化博覽》2022年1月刊暨《工業控制系統信息安全專刊(第八輯)》