西門子數位工廠,將在台灣推出城市基礎建設數位化,而可程式化邏輯控制器(PLC)是現代工業控制系統(ICS)中的一個重要的設備,專門應用在監控和數據蒐集(SCADA)系統,讓使用者方便管理應用遠端設備,但如果資訊安全做的不好,則可能會影響PLC的正常運行,會導致重大損害,輕微的話則可能是工廠的設備功能壞掉,嚴重的話會影響到人們的正常生活。雖然有許多的SCADA系統安全文獻中提到,大部分現有的工業控制系統運作作業,都集中在PLC與現場設備之間的通訊,因此本文將提出PLC與SCADA系統之間的通訊安全性分析,並且詳細探討攻擊個案討論關於PLC內部安全性之問題,以及提出各種防禦的方式及比較來保護SCADA系統的安全。
The Siemens digital plant will introduce urban infrastructure digitalization in Taiwan, and programmable logic controller (PLC) is an important device in modern industrial control systems (ICS), specifically for monitoring and data collection (SCADA) systems. It is convenient for the user to manage the remote device of the application. However, if the information security is not good, it may affect the normal operation of the PLC, which may cause significant damage. If it is slight, the function of the factory equipment may be broken. If it is serious, it will affect the serious People's normal life. Although there are many SCADA system safety documents mentioned, most of the existing industrial control system operations are concentrated on the communication between PLC and field devices. Therefore, this paper will propose the communication security analysis between PLC and SCADA system. In detail, the attack case discusses the internal security of the PLC, and proposes various defense methods and comparisons to protect the security of the SCADA system.