针对工控安全形势日益严峻,工控终端在操作系统层面缺乏全面的安全防护体系,无法适应安全新局势这一问题,文章通过研究面向工控的自主可控安全操作系统关键技术,在工控安全操作系统NARIsecOS基础上,提出了内核完整性保护方案,并对部分工作进行了形式化验证。通过这一技术的研究,可以保证工控终端操作系统的安全,进而在操作系统层面使工控终端具备免疫病毒木马、抵御黑客攻击的能力。安全操作系统在工控终端上的研究应用将有助于抵御大部分的工控安全威胁。
Industrial security situation is increasingly serious, and in the industrial security systems, there isn't a comprehensive security system at the operating system level for industrial control terminal, which is unable to adapt to the security situation under the new situation. To effectively solve the above problems, this paper studied the key technologies of the self controlled safe operating system for industrial control, proposed a kernel integrity protection program based on NARIsecOS, carried out formal verification of part of the work. Using this technology, the safety of industrial control terminal operating system can be guaranteed, and industrial control terminal with the ability of Trojan virus immunity and against hacker attacks at the operating system level can be made. Research and application of security operating system will withstand most of the industrial control security threats.