Skip to main content
QUICK REVIEW

[论文解读] Cybersecurity Challenges in the Offshore Oil and Gas Industry: An Industrial Cyber-Physical Systems (ICPS) Perspective

Abubakar Sadiq Mohammed, Philipp Reinecke|arXiv (Cornell University)|Feb 23, 2022
Digital and Cyber Forensics被引用 4
一句话总结

本文通过工业网络物理系统(ICPS)的视角,分析了海上油气作业中的网络安全漏洞,识别了海底控制系统中的攻击面,并将中间人攻击(MITM)、拒绝服务(DoS)和欺骗等威胁映射到系统各层。研究指出,由于IT-OT系统集成,风险显著增加,并呼吁开发行业专用数据集以及改进入侵检测系统,以保障远程、数字化的海上资产安全。

ABSTRACT

The offshore oil and gas industry has recently been going through a digitalisation drive, with use of `smart' equipment using technologies like the Industrial Internet of Things (IIoT) and Industrial Cyber-Physical Systems (ICPS). There has also been a corresponding increase in cyber attacks targeted at oil and gas companies. Oil production offshore is usually in remote locations, requiring remote access and control. This is achieved by integrating ICPS, Supervisory, Control and Data Acquisition (SCADA) systems, and IIoT technologies. A successful cyber attack against an oil and gas offshore asset could have a devastating impact on the environment, marine ecosystem and safety of personnel. Any disruption to the world's supply of oil and gas (O\&G) can also have an effect on oil prices and in turn, the global economy. This makes it important to secure the industry against cyber threats. We describe the potential cyberattack surface within the oil and gas industry, discussing emerging trends in the offshore sub-sector, and provide a timeline of known cyberattacks. We also present a case study of a subsea control system architecture typically used in offshore oil and gas operations and highlight potential vulnerabilities affecting the components of the system. This study is the first to provide a detailed analysis on the attack vectors in a subsea control system and is crucial to understanding key vulnerabilities, primarily to implement efficient mitigation methods that safeguard the safety of personnel and the environment when using such systems.

研究动机与目标

  • 识别并分析由于数字化和IT-OT集成而扩大的海上油气作业网络攻击面。
  • 研究海上作业中典型海底控制系统架构中的漏洞。
  • 将已知的网络攻击类型(如MITM、DoS和欺骗)映射到ICPS基础设施的特定层级。
  • 突出在运行状态不断变化的动态、远程且人员极少的海上设施中,保障安全所面临的挑战。
  • 解决上游油气工业控制系统(ICS)环境中缺乏代表性数据集的问题,以支持高级威胁检测研究。

提出的方法

  • 对2013年至2023年间记录的上游油气资产网络攻击进行全面回顾,以识别趋势和攻击模式。
  • 提出一个典型海上海底控制系统架构的详细案例研究,分析其组件和通信层级。
  • 将潜在网络威胁(如MITM、DoS、欺骗)映射到ICPS架构的特定层级,包括传感器、控制器和通信协议。
  • 评估IT-OT融合对系统安全的影响,特别是通过采用Modbus-TCP、DNP3和IEC-60870–5-104等标准协议。
  • 讨论现有ICS数据集的局限性,并倡导创建反映实时传感器数据和动态运行状态的新一代行业专属数据集。
  • 提出利用基于真实良性和恶意ICS流量训练的入侵检测系统(IDS)和机器学习模型,以提升威胁检测能力。

实验结果

研究问题

  • RQ1在ICPS架构下,海上油气海底控制系统的主要网络攻击向量是什么?
  • RQ2IT与OT系统集成在多大程度上扩大了海上油气作业的攻击面?
  • RQ3上游油气行业记录的网络事件在多大程度上与海底控制系统中识别出的漏洞相吻合?
  • RQ4在运行状态不断变化的动态海上环境中,检测恶意活动面临哪些关键挑战?
  • RQ5为有效训练和验证上游油气行业高级入侵检测系统,需要什么样的数据集?

主要发现

  • 海上油气作业中IT与OT系统的集成显著扩大了攻击面,使系统更容易受到数据外泄和恶意软件注入等网络威胁的影响。
  • 由于通信协议不安全且缺乏端到端加密,海底控制系统易受中间人攻击(MITM)、拒绝服务攻击(DoS)和欺骗攻击的影响。
  • 近期针对上游油气资产的网络攻击越来越多地以数据外泄为目标,这与IT-OT集成和远程监控能力的提升同步发生。
  • 动态运行变化(如压力容器降额运行和资产寿命延长)使恶意配置更改的检测更加复杂,增加了未被察觉的入侵风险。
  • 目前严重缺乏公开的、具有代表性的上游油气工业控制系统(ICS)环境数据集,特别是能够捕捉实时传感器数据和动态工艺状态的数据集。
  • 开发领域专用的测试平台和数据集对于训练高精度入侵检测系统、提升海上ICPS的整体安全水平至关重要。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。