全(quan)方位地(di)發(fa)現制(zhi)造業(ye)(ye)工(gong)業(ye)(ye)互(hu)聯網(wang)中的(de)(de)風險和(he)威脅(xie)。通過自動發(fa)現技(ji)術能夠快(kuai)速發(fa)現企業(ye)(ye)網(wang)絡(luo)中的(de)(de)物聯網(wang)設備,可以大大減少網(wang)絡(luo)管理員的(de)(de)維護(hu)工(gong)作量。通過精(jing)準的(de)(de)權(quan)限控(kong)制(zhi)和(he)基于(yu)設備行為(wei)的(de)(de)分析(xi),將風險和(he)威脅(xie)控(kong)制(zhi)到(dao)最低。
Industry status
據(ju)不完全(quan)(quan)統(tong)(tong)計,我(wo)國(guo)工(gong)(gong)(gong)業(ye)(ye)互(hu)聯(lian)(lian)網(wang)(wang)(wang)聯(lian)(lian)盟 82 家工(gong)(gong)(gong)業(ye)(ye)企(qi)業(ye)(ye)的(de) ICS、SCADA 等(deng)工(gong)(gong)(gong)控系統(tong)(tong), 28.05%都出現(xian)過(guo)漏洞,其中,23.2%是高(gao)危漏洞。制造業(ye)(ye)工(gong)(gong)(gong)業(ye)(ye)控制系統(tong)(tong)和平臺(tai)的(de)安(an)(an)全(quan)(quan)隱患日趨突出,工(gong)(gong)(gong)業(ye)(ye)網(wang)(wang)(wang)絡安(an)(an)全(quan)(quan)產品和服務(wu)適應(ying)性不高(gao),工(gong)(gong)(gong)業(ye)(ye)互(hu)聯(lian)(lian)網(wang)(wang)(wang)安(an)(an)全(quan)(quan)保(bao)障(zhang)意識及能力亟待(dai)強化。這些物聯(lian)(lian)網(wang)(wang)(wang)終端(duan)所面臨的(de)安(an)(an)全(quan)(quan)威脅,除(chu)傳統(tong)(tong)計算機病毒(du)外,還包括(kuo)木馬、間諜軟(ruan)件(jian)、劫持攻(gong)擊(ji)、釣魚郵件(jian)、釣魚網(wang)(wang)(wang)站(zhan)等(deng)。綜合考慮物聯(lian)(lian)網(wang)(wang)(wang)終端(duan)本身及其所面臨的(de)安(an)(an)全(quan)(quan)威脅特(te)點,需從(cong)硬件(jian)、接入、操作系統(tong)(tong)、業(ye)(ye)務(wu)應(ying)用(yong)等(deng)方面著手,采取(qu)適當的(de)安(an)(an)全(quan)(quan)防(fang)護措施,確保(bao)物聯(lian)(lian)網(wang)(wang)(wang)終端(duan)安(an)(an)全(quan)(quan)乃至物聯(lian)(lian)網(wang)(wang)(wang)整網(wang)(wang)(wang)安(an)(an)全(quan)(quan)。
Solution
以(yi)聯(lian)軟科(ke)技UniNID網絡智能(neng)(neng)防御系(xi)統為基(ji)礎的《制(zhi)(zhi)造業(ye)物(wu)聯(lian)網設備管(guan)控解(jie)決方案(an)》,能(neng)(neng)很好解(jie)決制(zhi)(zhi)造業(ye)物(wu)聯(lian)網設備安全管(guan)控問題。該方案(an)包括:
發現網絡中的物(wu)聯網設(she)備:通過系(xi)統自動(dong)發現部署在網絡中的物(wu)聯網設(she)備,并收集設(she)備的IP、MAC、設(she)備類型(xing)、接入位置等信息;
網(wang)絡(luo)節點(dian)身(shen)(shen)份(fen)認(ren)證機制:在物(wu)聯網(wang)通信網(wang)絡(luo)中引入(ru)身(shen)(shen)份(fen)認(ren)證機制,利用關(guan)鍵網(wang)絡(luo)節點(dian)對邊緣感知節點(dian)的身(shen)(shen)份(fen)進行認(ren)證,從而防止(zhi)和杜(du)絕虛假(jia)節點(dian)接入(ru)到網(wang)絡(luo)中,以(yi)確保通信網(wang)絡(luo)節點(dian)安全;
實(shi)施精準的(de)權限控制(zhi):針對已經發現的(de)物聯網設備實(shi)現動態網絡權限控制(zhi),僅允許(xu)物聯網設備訪問必(bi)要的(de)網絡資源;
發(fa)現可能性的(de)(de)威脅:在了解(jie)網(wang)(wang)絡中(zhong)已(yi)連(lian)接的(de)(de)物聯網(wang)(wang)設備基(ji)本狀況后,可以對這些(xie)設備的(de)(de)流量進(jin)行(xing)分析并(bing)跟蹤(zong),對安(an)全攻擊實時監控(kong),對物聯網(wang)(wang)安(an)全風險進(jin)行(xing)趨勢預測,為后續的(de)(de)物聯網(wang)(wang)安(an)全風險治理奠(dian)定基(ji)礎(chu)。
Customer value