论文标题
与工业控制系统对比的分类学资产发现工具
A Taxonomy for Contrasting Industrial Control Systems Asset Discovery Tools
论文作者
论文摘要
资产扫描和发现是组织了解其拥有的资产和保护的第一步。目前有大量的免费和商业资产扫描工具,专门识别工业控制系统(ICS)中的资产。但是,几乎没有有关其比较功能以及各自功能对比的信息。扫描这些工具可以达到哪些深度以及它们是否适合在规模的工业网络体系结构中适合使用。我们根据我们建议的ICS扫描分类法提供了首个自由使用资产扫描工具的系统功能比较。基于分类法,我们研究了工具特征所达到的扫描深度,并通过对测试台环境中的西门子,施耐德电气和艾伦·布拉德利设备进行实验来验证我们的研究。
Asset scanning and discovery is the first and foremost step for organizations to understand what assets they have and what to protect. There is currently a plethora of free and commercial asset scanning tools specializing in identifying assets in industrial control systems (ICS). However, there is little information available on their comparative capabilities and how their respective features contrast. Nor is it clear to what depth of scanning these tools can reach and whether they are fit-for-purpose in a scaled industrial network architecture. We provide the first systematic feature comparison of free-to-use asset scanning tools on the basis of an ICS scanning taxonomy that we propose. Based on the taxonomy, we investigate scanning depths reached by the tools' features and validate our investigation through experimentation on Siemens, Schneider Electric, and Allen Bradley devices in a testbed environment.