近年来,针对工控系统的攻击越来越多,工业控制系统应用大多涉及国计民生,其安全问题不容忽视。我国工控系统中现场PLC、终端、RTU等控制设备大部分使用国外的控制组件,对于未知的逻辑炸弹和后门基本没有安全防护能力。为此,本文以拟态技术为基础,提出了一种通用的拟态安全处理机架构,采用基于状态保存的两步清洗技术和高可靠判决策略,使得符合该架构规范的应用程序均能借助拟态处理架构防护操作系统、处理机和外围器件可能出现己知或未知的后门/漏洞,最后的仿真验证结果验证了该系统可以有效地抵御多种类型的攻击。
Over the last years, attacks targeting ICSs, most of which largely concern national welfare and the people's livelihood, are prevailing and should not be neglected. In our country, the vital pieces in ICSs such as PLCs, terminals, RTUs and so on mostly come from abroad. Without independency or control over these pieces, we cannot achieve protection against unknown logic bombs or backdoors. Based on Mimic Technology, this paper presents a new general architecture of mimic security processor. This processor uses status-based two-step cleanout method and high-reliable arbitration method. APPs that conform to this architecture can protect the operating system, the processor and other modules from known or unknown backdoors/vulnerabilities. The simulations at the end prove mimic security processor can defend multi types of attacks.