Industrial 4 information security [Peng Yue Industrial Safety (167)]

【摘要】18世纪第一次工业革命的到来发明了蒸汽机,从此机械代替了传统的手工劳动,19世纪第二次工业革命的到来,电力被人类广泛的应用,20世纪第三次工业革命的到来信息技术逐渐的走向人类的生活。三次工业革命的养成极大的改变了人类的生产生活。随着当代社会经济和科学技术的不断的发展进步,互联网和智能化生产的出现将人类带入了工业4.0时代也被称为第四次工业革命。工业4.0的出现收到了人们广泛的关注,尤其是工业4.0的信息安全问题。本文将对工业4.0的发展及信息安全问题进行详细的阐述。
【关键词】工业革命;工业4.0;科学技术;互联网;智能化生产;信息安全
工业4.0和之前的三次工业革命还有所差异,第一次工业革命主要是应用蒸汽机生产制造,第二次工业革命是电力的发展,第三次工业革命是信息技术的应用,而第四次工业革命主要是对电力,信息技术进行实时性的管理,从而增加效益并且有益于整个的资源应用于整个的网络,再加上智能化辅助系统的帮助下,改变之前人工监督的模式,机器智能化管理来完成具体的工作,从而把工人解放出来来专心的研究发明新的技术,促进工业的发展进步。
工业4.0涉及到以下几个领域:标准化及参考架构,管理较为复杂的系统,全面宽频的基础设施,安全和保障,设计及组织,培训和持续职业的发展,规章制度以及资源利用效率的管理。工业4.0涉及到诸多的领域,可见工业4.0的信息安全问题不容忽视。
1德国工业4.0计划

上海银监局开8张罚单 四家银行被罚逾千万 https://www.chinanews.com/fortune/2017/05-04/8215215.shtml

本文主要介绍的是工业4.0及其信息安全问题。那么首先介绍一下什么是工业4.0呢?工业4.0也就是第四次工业革命,前三次工业革命的完成给人类的日常的生产生活带来了诸多的便利,在新时代经济实力以及科学技术的快速发展的背景下,互联网和智能化生产制造逐渐的走向人们的生活标志着人类将进入一个新的工业革命!德国为了在新的革命到来走在其他国家的前面,德国国内许多的顶尖的公司以及企业大力的支持国家制定工业4.0战略,德国的政府在2013的工业博览会上正式的提出工业4.0战略。德国在制定工业4.0战略前,认真的分析了之前各国的工业革命发展中的问题以及他们的发展优势,工业4.0战略可以说综合了各国的工业革命的优势,德国像借此机会提高本国的综合实力,提升国际竞争力,推动本国工业制造的发展进步。
湖南黄金(002155)有色金属黑马股,后势精准大解析

IBM收购Sanovi Technologies以扩展混合云灾难恢复服务

2工业4.0的安全问题在之前的工业发展过程中工业安全问题不被人们重视,许多的病毒恶意的软件对工业系统的安全造成了极大的威胁,人们才逐渐的重视工业发展过程中的信息安全问题,尤其是2010年伊朗由于忽视工业控制系统的安全遭到震网病毒的攻击迫害造成了巨大的损失,此事件发生后各国都开始意识到工业发展中信息安全的重要性,并逐渐的采取措施积极的解决工业控制系统安全问题隐患。我国也发出了一些相应的声明,明确的讲述了工业安全的重要性,习近平书记还成立了网络安全和信息化领导小组,指出我国工业信息安全是十分严峻和艰巨的,我国把工业信息安全列入国家发展的最高战略之一,可见我国对工业信息安全的重视。
工业4.0能否顺利的进行和工业信息安全的控制是分不开的,信息安全是工业4.0顺利发展的前提保障。工业4.0的安全问题主要包含两个方面是:①对人及环境的安全;;②设备和其产品的安全,尤其是对工业生产过程中的关键数据及其操作模式的保护,防止恶意的访问和错误的操作。
自从工业第三次工业革命之后,人们把信息技术和机电结合在一起,对其安全性的要求越来越高,但是到目前为止一些工业3.0时代的信息安全问题和生产操作过程中出现的安全问题还未得到很好的解决方案,工业4.0时代的到来对信息安全的要求更高除了以往的安全问题以外,工业4.0还有一些额外的安全要求。工业4.0把人,机器,网络,智能化结合在一起形成一个有机整体,是一个具有高度网络化的系统结构,在系统生产过程中会产生一些高密准确的时间数据和信息交换,工业4.0的安全问题对于整个工业4.0的发展具有非常重要的意义,工业4.0除了在运营安全外,网络的安全以及防止第三方网站的恶意访问也是工业4.0面临着巨大的挑战。
3解决工业4.0信息安全问题的措施3.1提高信息安全意识
提高信息安全意识是任何信息安全问题的第一要素,提高企业和员工的工业信息安全的意识同样是工业4.0信息安全问题的第一要素。工业4.0的安全问题涉及到很多方面,在智能化生产过程中由于员工和企业的安全意识薄弱,缺乏标准的安全保障操作,导致工业现有的基础设备的安全隐患不能及时的被发现解决,直到安全问题造成巨大的损失才追悔莫及。所以提高工人和企业的工业安全意识是解决工业安全问题的首要任务,工业4.0的整个的生产链条比较的长,涉及到很多的部门,只有人们的安全意识提高,各部门通力合作才能很好的解决工业4.0的信息安全问题。3.2加强基础设施保障
基础设施保障主要从以下几点进行安全防范:①边界防护,工业边界防火墙通过对工业专有协议的深度解析,智能学习工控操作指令和参数建立网络和通讯“白环境”,阻止来自3、2、等层之间的越权访问,病毒、蠕虫恶意软件扩散和入侵攻击,保护控制系统安全运行。②工控网络安全审计,网络异常检测、网络攻击检测、关键事件监测均是工控网络安全审计的有效手段。3.3采用数据和操作模式加密技术

案例说 | 大而不倒?集团客户风险分析

工业4.0是采用的是智能化生产,在其生产的过程中会产生很多的重要的数据,这些数据对整个的企业的发展起到至关重要的作用,这些关键的数据一旦被第三方恶意的软件访问窃取,其损失是无法估量呢。所以对工业生产过程中产生的关键数据和操作模式使用加密技术,阻止恶意软件的访问,提高工业信息的安全度。同时要以明确目标、收集最小化、数据最少化、利用/保留/揭露最低程度等国际通行四大原则为基准,让数据安全不因易用而牺牲安全。3.4注重身份认证与访问控制方案
工业4.0发展的过程中必须制定一个比较可靠访问控制方案,可以采取多维度身份认证和细粒度角色权限控制来进行访问控制多维度身份认证可以使用的技术手段有用户名+口令,设备和位置信息(IP地址,Mac地址),双重认证(手机短信/邮件)其他认证(生物唯一特征,指纹,声音,视频)等。与验证客户身份搭配的是访问控制服务(RAM),RAM设计了细粒度的访问控制,可根据授权需要,精确地允许或拒绝某个客户对特定的资源执行某项具体操作,并帮助用户达成集中式客户身份管理、集中式权限管理、统一访问控制、统一账单的服务目标。一个完善的身份认证与访问控制方案是信息安全的必备条件,且在工业4.0发展过程中尤为重要。
4结束语
工业4.0的出现会大大的改善人类的生产生活,在推动社会的进步和科学技术的发展方面发挥着重要的作用,所以各国应该高度重视工业4.0信息安全问题采取有效措施应对信息安全隐患确保工业4.0的顺利进行。
(来源:互联网,作者:赵子健,王丹斌)
温馨提醒:
现在关注“鹏越网络空间安全研究院”微信公众号,在对话框中输入“工控”、“培训”、“CTF” 、“物联网”、 “人工智能”、“招聘”等关键字,系统自动推送相应内容。今后我们还会推出更多方便搜索和阅读的服务,敬请期待!
点击下方”阅读原文“获得更多资讯:
长按二维码向我转账
受苹果公司新规定影响,微信 iOS 版的赞赏功能被关闭,可通过二维码转账支持公众号。
微信扫一扫关注该公众号
[Abstract] in eighteenth Century for the first time the industrial revolution is the invention of the steam engine, from the machine to replace the traditional manual labor, in nineteenth Century second the arrival of the industrial revolution, human power is applied widely, the advent of the information technology in twentieth Century of the third industrial revolution gradually to human life. The three industrial revolution has greatly changed the production and life of mankind. With the continuous development of contemporary social economy and science and technology, the emergence of the Internet and intelligent production will bring mankind into the industrial 4 era is also known as the industrial revolution of the fourth. The emergence of industrial 4 has received widespread attention, especially the industrial information security issues of 4. In this paper, the development of industrial 4 and information security issues are described in detail.
Industrial revolution; industry 4; science and technology; Internet; intelligent production; information security
The three industrial revolution before 4 and there are differences in the industry, the first industrial revolution is the application of the steam engine manufacturing, the second industrial revolution is the power of the development of the third industrial revolution is the application of information technology, and the fourth industrial revolution is the main power of information technology, real-time management, and increase the benefit and for the benefit of the entire application resources in the whole network, coupled with intelligent auxiliary system, change manual supervision mode, the machine intelligent management to complete the work, so the research workers free to concentrate on the invention of new technologies, promote industrial development and progress.
4 industry involves the following aspects: standardization and reference architecture, system management is complex, comprehensive broadband infrastructure, safety and security, design and organization, development training and continuing occupation, regulations and management efficiency of resource utilization. Industry 4 involves a lot of fields, we can see that the industrial 4 of information security issues can not be ignored.
1 German industrial 4 program
This paper mainly introduces the industrial 4 and its information security. So first of all, what is industry 4? Industrial 4 is the fourth industrial revolution, three times before the completion of the industrial revolution to human daily production and life has brought a lot of convenience, economic strength in the new era and the rapid development of science and technology under the background of the Internet and intelligent manufacturing gradually to people’s lives means that human beings will enter a the new industrial revolution! The new revolution in Germany in order to come ahead of other countries, many of the top German domestic companies and enterprises to vigorously support the national development strategy of industrial 4, the German government in 2013 Industrial Fair formally proposed industrial 4 strategy. In the development of German industry 4 strategy, careful analysis before the industrial revolution in the development of national problems and their development advantages, industrial 4 strategy can be said that the synthesis of the countries of the industrial revolution, Germany, like to take this opportunity to improve their overall strength, improve the international competitiveness, promoting the progress of domestic manufacturing industry.
Industrial safety and industrial development process of 2 industry 4 security issues before the problem is not taken seriously by people, threaten the safety of many viruses malicious software on the industrial system, people gradually pay attention to information security problems in the process of industrial development, especially in Iran in 2010 because of the neglect of the industrial control system security by the virus attacks the persecution caused huge losses after the incident, all countries began to realize the importance of information security industry development, and gradually take positive measures to solve the problems of industrial control system security problem. China has also made some corresponding statement, clear about the importance of industrial safety, Secretary Xi Jinping has also set up a network security and information technology leadership team, and points out that the information security industry in our country is very serious and difficult, China has one of the highest industrial information security strategy included in the National Development, so our attention to the information security industry.
Industrial 4 can be carried out smoothly and the control of industrial information security is inseparable, the information security industry is the prerequisite for the smooth development of the protection of the 4. The security problem of industrial 4 mainly includes two aspects: on human and environmental safety;; the equipment and the safety of their products, especially the protection of critical data in the industrial production process and its mode of operation, to prevent malicious access and wrong operation.
Since the industry of the third industrial revolution, the information technology and electromechanical together, increasingly high demand for its security, but the security problems appeared so far the process of information security problems in production and operation in some industrial age 3 has not been a good solution, 4 industrial era requirements the information security in addition to higher safety issues in the past, the 4 industry have some additional safety requirements. The 4 industrial people, machine, intelligent network, together to form an organic whole, is a highly networked system structure, system in the production process will produce some high accurate time data and information exchange, the security problem of industrial 4 has very important significance for the development of the whole industry 4 in addition, 4 in the industrial operation safety, network safety and prevent malicious access to third party websites is the 4 industry is facing a huge challenge.
3 to solve the problem of industrial 4 information security measures to improve information security awareness 3.1
To improve information security awareness is the first element of any information security issues, enhance the awareness of industrial and industrial information security industry is also the first element of the 4 information security issues. The security problem of industrial 4 involves many aspects, in the intelligent production process because of staff and enterprise safety awareness is weak, lack of standard security operation, security risks can not be led to the foundation of industrial equipment and timely solve the security problem is found, until the huge losses was too late to regret. So to improve the safety awareness of workers and enterprises is the primary task to solve the industrial safety problems, 4 of the whole industrial chain of production is relatively long, involving many departments, only by improving people’s safety consciousness, departments work together in order to solve the problem of information security industry 4. 3.2 strengthen infrastructure security

Infrastructure security mainly from the following points: the boundary protection, industrial boundary firewall after a thorough analysis on the industrial protocol, intelligent learning control instructions and parameters to establish network and communication environment, prevent from between 3 and 2, such as unauthorized access layer, virus, worm and malicious software diffusion attack, protection and control system for safe operation. Industrial network security audit, network anomaly detection, network attack detection, key event monitoring is an effective means of industrial network security audit. 3.3 data and operation mode encryption technology
The 4 industry is the use of intelligent production, in the production process will produce a lot of important data, these data on the development of enterprises play a crucial role, these key data once the malicious third party software access to steal, the loss is incalculable. Therefore, in the process of industrial production, the key data and the operation mode of the use of encryption technology to prevent access to malicious software, improve the safety of industrial information. At the same time, it is necessary to clear the objectives, to minimize the collection, data minimization, the use \/ retention \/ disclosure of the lowest level of the four international principles as the benchmark, so that data security is not easy to use at the expense of security. 3.4 focus on identity authentication and access control scheme
The process of industrial development in 4 must develop a more reliable access control scheme can take multiple dimensions of identity authentication and role access control to fine-grained access control technology of multi dimension authentication can use the user name and password, and device location information (IP address, Mac address), dual authentication (mobile phone SMS \/ email (the only other certification) biological characteristics, fingerprint, voice, video, etc.). Collocation and verify the identity of customers is the access control service (RAM), RAM design of fine-grained access control, according to the authorization, precisely to allow or deny a client performs a specific operation of specific resources, and help users achieve centralized customer identity management, unified management, centralized access service target control unified bill. A perfect identity authentication and access control scheme is an essential condition for information security, and is particularly important in the development of industrial 4.
4 concluding remarks
The 4 industry will greatly improve the production of human life, play an important role in promoting social development and the progress of science and technology, so all countries should attach great importance to the 4 industry information security problems and take effective measures to deal with the problems of information security industry to ensure smooth 4.
(source: Internet, author: Zhao Zijian, Wang Danbin)
Warm reminder:
Now focus on Pengyue Cyberspace Security Institute WeChat public number, in the dialog box input control, training, CTF, Internet of things and artificial intelligence and Recruitment keyword, send the corresponding content automatic push system. In the future we will introduce more convenient search and reading services, please look forward to!
Click below to read the text:
Long by two-dimensional code to me transfer
Affected by the new regulations of Apple Corp, WeChat iOS version of the feature is closed, can be transferred through the two-dimensional code to support public numbers.
人员是我们的各类信息系统和信息数据的使用者,所在在保障信息系统本身的安全性的同时,我们很重视人的安全因素,对新员工和新到岗人员要进行安全意识和安全操作培训,对在职人员坚持定期培训,以不断提高安全能力和水平。
WeChat sweep attention to the public number

信息安全的成功,对终端用户的依赖越来越大。信息安全管理也需要比以往任何时候更加关注终端用户的安全意识和安全行为。

猜您喜欢

百度承认旗下hao123暗藏恶意代码:向用户道歉
网络安全公益短片扫描二维码的安全风险
保密意识第一弹:准确定密并正确标识国家秘密
25岁男子坠楼身亡父亲抱子哭泣
FIFASOCCERBLOG WEBANTIVIRUSJH
信息安全基础测验