节点文献

SECS/GEM标准攻击方法与实践

THE METHODOLOGY AND PRACTICE OF ATTACKING SECS/GEM STANDARD

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 谢雨轩; 伍鹏; 严明;

【Author】 Xie Yuxuan;Wu Peng;Yan Ming;School of Computer Science,Fudan University;Semiconductor Manufacturing International Corporation (Shanghai);Engineering Research Center of Cyber Security Auditing and Monitoring,Ministry of Education, Fudan University;

【机构】 复旦大学计算机科学技术学院; 中芯国际集成电路制造(上海)有限公司; 教育部网络信息安全审计与监控工程研究中心;

【摘要】 在目前的半导体生产环境中,普遍采用SECS/GEM标准实现计算机系统与生产机台的交互。然而,目前少有针对SECS/GEM标准的安全性研究。针对这种情况,设计拒绝服务、信息窃取、流量伪造三种威胁场景六个攻击实验。攻击实验模拟了与生产机器位于同一局域网下的攻击者的行为,从链路层、网络层、传输层、应用层四个攻击面着手,对采用SECS进行通信的生产网络和生产机器进行渗透和控制。实验结果表明,SECS/GEM标准的设计并没有将安全机制作为必要的因素,普遍缺乏内生的安全性,具有明显的脆弱性。

【Abstract】 SECS/GEM standard is widely-used in the contemporary semiconductor manufactory environment to deal with the communication between hosts and equipment. However, few works have been done with respect to the security issues of SECS/GEM standard. To fill the research gap, three threatening scenarios comprising deny of service, information theft, and traffic tampering and six attack experiments were designed. The attacking experiments simulated the behavior of an attacker who was in the same LAN as the manufactory equipment and tried to penetrate the network and to control the equipment in four different OSI layers including link layer, network layer, transport layer and application layer. The result shows that security mechanism is not included in the design of SECS/GEM standard and the standard is extremely insecure and fragile.

【基金】 工业与信息化部2019年工业互联网创新发展工程-工业企业网络安全综合防护平台项目。
  • 【文献出处】 计算机应用与软件 ,Computer Applications and Software , 编辑部邮箱 ,2025年07期
  • 【分类号】TP393.08
  • 【下载频次】10
节点文献中: 

本文链接的文献网络图示:

本文的引文网络