刘冬兰, 张昊, 卢思翰, 张方哲, 孙莉莉. 电力物联网设备安全检测系统设计与应用[J]. 山东电力技术, 2022, 49(9): 29-35.
引用本文: 刘冬兰, 张昊, 卢思翰, 张方哲, 孙莉莉. 电力物联网设备安全检测系统设计与应用[J]. 山东电力技术, 2022, 49(9): 29-35.
LIU Dong-lan, ZHANG Hao, LU Si-han, ZHANG Fang-zhe, SUN Li-li. Design and Application of Power Internet of Things Device Security Detection System[J]. Shandong Electric Power, 2022, 49(9): 29-35.
Citation: LIU Dong-lan, ZHANG Hao, LU Si-han, ZHANG Fang-zhe, SUN Li-li. Design and Application of Power Internet of Things Device Security Detection System[J]. Shandong Electric Power, 2022, 49(9): 29-35.

电力物联网设备安全检测系统设计与应用

Design and Application of Power Internet of Things Device Security Detection System

  • 摘要: 电力物联网设备正在越来越多的应用于电力系统,由于设备类型多样、复杂,因此目前尚未有对其进行安全检测的成熟解决方案。为解决这一现状,设计研发一种电力物联网设备安全检测系统,基于设备指纹识别、网络协议识别和固件安全性分析等关键技术,对电力物联网设备从漏洞情况、配置安全性和固件安全性角度进行综合安全分析,实现对设备安全性检测,自动化的系统设计大大提高了用户开展安全检测工作的效率。目前,该系统已积累了品牌库23 613条,固件库11条,协议库22条,漏洞库159 763条,威胁特征库1 028条。利用电力物联网设备安全检测系统对电力5G终端、5G CPE、5G边缘网关等六款设备进行安全检测,累计挖掘终端密钥泄露、配置错误、不安全的组件等安全风险274个。将研发的平台与业内知名漏洞扫描工具进行了对比分析,电力物联网设备安全检测系统具有较高的准确率和覆盖率。同时,将系统在3个典型电力业务场景进行试点验证,累计挖掘各类安全漏洞590个,有力保障了电力物联网终端本体安全性。

     

    Abstract: Power Internet of things(IoT)devices are more and more used in power system.Due to the diversity and complexity of equipment types,there is no mature solution for security detection.A security detection system for power IoT device was designed.Based on the key technologies such as equipment fingerprint identification,network protocol identification and firmware security analysis,comprehensive security analysis was conducted on power IoT devices from the perspectives of vulnerability,configuration security and firmware security,and the equipment security detection was realized.By means of automation,the efficiency of users’ safety detection was greatly improved.At present,the system has accumulated 23 613 brand libraries,11 firmware libraries,22protocol libraries,159 763 vulnerability libraries and 1 028 threat signature libraries. The power IoT device security detection system was used to carry out security detection on six devices such as power 5G terminal,5G CPE and 5G edge gateway,and a total of 274 security risks such as terminal key leakage,configuration error and insecure component were excavated. Compared the developed platform with well-known vulnerability scanning tools in the industry,the power IoT device security detection system has high accuracy and coverage.Meanwhile,the system was tested and verified in three typical power business scenarios,and a total of 590 security vulnerabilities were excavated,which effectively guarantes the security of power IoT terminal ontology.

     

/

返回文章
返回