云边协同工业控制系统内生网络安全防护
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP309

基金项目:

国家重点研发计划项目(2022YFB3104300)


Research on Endogenous Cybersecurity Protection for Cloud-side Collaborative Industrial Control System
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    为进一步增加工业控制系统安全稳定运行,针对企业云边协同工业控制系统面临在自主可控、未知攻击抵御、持续稳定运行等3个主要方面的风险等,对现有工业控制系统网络安全防护体系架构进行提升与改进。在网络安全纵深防御的主流防护架构基础上,按照“支撑器件-设备-系统-评估”改进思路,融入自主可控的内生安全技术,重新进行设计动态异构、多模裁决、四重化控制等关键组件架构设计,实现拟态MCU、安全性PLC、安全性DCS关键支撑器件,构建新型工业控制系统安全隔离网关,云边缘智能平台,最终实现构建云边协同新型工业控制系统智能防护系统。按照真实石油石化生产场景搭建数字孪生测试平台,引入真实生产数据,采用网络安全有效性量化评估和攻击验证评估两方面开展测试。其中有效性量化评估测试符合率为100%,攻击验证评估测试攻击防御成功率达到99%。相比改进前的传统防御模式系统得到了明显的防护能力提升。基于内生安全的新型工业控制系统安全防护设计,在前网络安全形势下,系统防护能力得到了明显的提升,为大型国有企业的工业控制系统安全改进提供了一种可行且先进高效的方案。

    Abstract:

    In the field of cloud-edge collaborative industrial control system protection for petroleum and petrochemical enterprises, systems generally face risks of autonomous control, unknown attacks, and sustained stable operation. Enterprises urgently need to improve the design and evaluation of existing industrial control system cybersecurity protection architectures, and enhance key technologies and components to ensure the safe and stable operation of their industrial control systems. Based on the mainstream protection architecture of Defense-in-Depth network security , in accordance with the improvement idea of "support components-equipment-system-evaluation", we integrate the technologies of Endogen ous Cybersecurity based on self-controllable, redesign the architecture of key components such as dynamic heterogeneity, multi-mode arbitration, and quadruple control, realize the key supporting components of mimetic MCU, safety PLC, and safety DCS, build a new type of industrial control system security isolation gateway and cloud-edge intelligent platform, and finally realize the construction of a new type of industry-al control system intelligent protection system with cloud-edge collaboration. A digital twin testing platform was built based on real-world petroleum and petrochemical production scenarios, incorporating real production data. Testing was conducted using both quantitative cybersecurity effectiveness assessments and attack verification assessments. The effectiveness quantitative assessment achieved a 100% compliance rate, while the attack verification assessment achieved a 99% attack defense success rate. Compared to the traditional defense model before the improvements, the system''s protection capabilities have been significantly improved. The new industrial control system security protection design based on Endogenous Cybersecurity has significantly improved the system protection capability under the current network security situation, providing a feasible, advanced and efficient solution for the security improvement of industrial control systems in the petroleum and petrochemical industries.

    参考文献
    相似文献
    引证文献
引用本文

董之光,帅训波,柏东明,等. 云边协同工业控制系统内生网络安全防护[J]. 科学技术与工程, 2026, 26(24): 10484-10493.
Dong Zhiguang, Shuai Xunbo, Bai Dongming, et al. Research on Endogenous Cybersecurity Protection for Cloud-side Collaborative Industrial Control System[J]. Science Technology and Engineering,2026,26(24):10484-10493.

复制
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-11-19
  • 最后修改日期:2026-06-16
  • 录用日期:2026-01-21
  • 在线发布日期: 2026-09-02
  • 出版日期:
×
2026年会通知 | “技术经济学驱动智能经济生态构建与治理变革”——中国技术经济学会第三十三届学术年会(2026)会议通知暨征文启事(第一轮)
亟待确认版面费归属稿件,敬请作者关注