کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
275098 1429496 2014 10 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Evaluation of the ability of the Shodan search engine to identify Internet-facing industrial control devices
ترجمه فارسی عنوان
ارزیابی توانایی موتور جستجوی Shodan برای شناسایی دستگاه های کنترل صنعتی با استفاده از اینترنت
کلمات کلیدی
سیستم های کنترل صنعتی؛ Shodan؛ پیامدهای امنیتی؛ تسکین دهنده
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی

The Shodan computer search engine has received significant attention due to its ability to identify and index Internet-facing industrial control system components. Industrial control systems are employed in numerous critical infrastructure assets, including oil and gas pipelines, water distribution systems, electrical power grids, nuclear plants and manufacturing facilities. The ability of malicious actors to identify industrial control devices that are accessible over the Internet is cause for alarm. Indeed, Shodan provides attackers with a powerful reconnaissance tool for targeting industrial control systems.This paper investigates the functionality of the Shodan computer search engine. In the experiments, four Allen-Bradley ControlLogix programmable logic controllers were deployed in an Internet-facing configuration to evaluate the indexing and querying capabilities of Shodan: all four programmable logic controllers were indexed and identified by Shodan within 19 days. This paper also describes a potential mitigation strategy that employs service banner manipulation to limit the exposure to Shodan queries.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: International Journal of Critical Infrastructure Protection - Volume 7, Issue 2, June 2014, Pages 114–123
نویسندگان
, , , ,