HITB2021£üAG¹«Ë¾¿Æ¼¼ÒéÌ⣺Going Deeper into Schneider Modicon PAC Security
2021-08-26
±±¾©Ê±¼ä8ÔÂ23-27ÈÕ£¬2021ÄêÈ«Çò¶¥¼¶ÐÅÏ¢Çå¾²¾Û»áHITBSECCONF2021 - SINGAPORE½ÓÄÉÐéÄâ·½·¨ÔÚÏßÉϾÙÐУ¬½öʱ¸ôÈý¸öÔ£¬AG¹«Ë¾¿Æ¼¼¸ñÎïʵÑéÊÒÌá½»µÄ¡¶Going Deeper into Schneider Modicon PAC Security¡·ÓÖÒ»´Î±»HITB SIN 2021Ö÷ÈüµÀÑ¡ÖС£8ÔÂ26ÈÕ£¬¸ñÎïʵÑéÊÒ¹¤¿ØÇå¾²Ñо¿Ô±¸ß½£ÔÚÏßÉÏÏòÈ«Çò¹ÛÖÚ½ÒÏþÁËÑݽ²¡£

Åä¾°ÏÈÈÝ
Ê©Ä͵ÂModicon M084ÊÇÌìÏÂÉϵÚһ̨ͶÈëÉÌÒµÉú²úµÄPLC£¨¿É±à³ÌÂß¼¿ØÖÆÆ÷£©£¬Ê©ÄÍµÂµçÆøÔÚPLCÑз¢ÓëÖÆÔìµÄõè¾¶ÉÏÔ½×ßÔ½Ô¶£¬ÏÖÔÚÒÑ¿ÉÕë¶ÔÖÖÖÖÓ¦Óó¡¾°Ìṩ²î±ðϵÁеÄPLC²úÆ·¡£ÎªÁËÒÔÒ»ÖÖ¾¼ÃµÄ·½·¨À´ÊµÏÖPLCºÍDCSÖ®¼äµÄ¿ØÖƹ¦Ð§£¬Ê©ÄÍµÂµçÆøÓÚ2010Äê×óÓÒÑз¢Á˹¤ÒµÀú³Ì×Ô¶¯»¯¿ØÖÆÆ÷Modicon PAC£¨M580¡¢M340¡¢MC80µÈ£©£¬¿ØÖÆÓþ߱¸Ç¿Ê¢µÄÁªÍø¹¦Ð§¡¢ÈßÓ๦ЧºÍÇå¾²ÐÔ£¬ÆÕ±éÓ¦ÓÃÔÚË®µç¡¢Ë®´¦Öóͷ£¡¢¹«ÓÃÊÂÒµµÈÐÐÒµ£¬ÄÇôÔÚÔÆÔÆÖ÷ÒªÒªº¦»ù´¡ÉèÊ©ÖÐʹÓõē¹¤Òµ´óÄÔ”ÕæµÄÇ徲ô£¿
ÒéÌâ½â¶Á
AG¹«Ë¾¿Æ¼¼¸ñÎïʵÑéÊÒһֱרעÓÚÑо¿ÔÚÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©ÖÐʹÓÓ¹¤Òµ´óÄÔ”µÄÇå¾²ÐÔ£¬¼Ì¡¶Breaking Siemens SIMATIC S7 PLC Protection Mechanism¡·ÒéÌâÖ®ºó£¬¸ñÎïʵÑéÊÒÓÖѡȡʩÄ͵ÂModicon PAC×÷ΪÑо¿¹¤¾ß£¬»áÉÏ£¬¸ñÎïʵÑéÊÒ¹¤¿ØÇå¾²Ñо¿Ô±¸ß½£¶ÔModicon PACϵÁеÄ˽ÓÐÐÒéUMASÃûÌá¢Ä£ºý²âÊÔ£¨Fuzz£©¹¤¾ßµÄ¹¹½¨¾ÙÐÐÁËÏÈÈÝ£¬²¢½â˵ÁËModicon PACϵÁÐÓ¦ÓÃÃÜÂë±£»¤»úÖÆµÄÈÆ¹ýÒªÁì¼°ÊÚȨÀú³ÌÖеÄÏà¹ØËã·¨¡£
¸ñÎïʵÑéÊÒ²»µ«Ñо¿¹¥»÷£¬¸üÖ÷ÕÅÌáǰչÍû¹¥»÷£¬²¢»ùÓڸù¥»÷Ìá³ö·ÀÓù²½·¥¡£±¾ÒéÌâÖУ¬¸ñÎïʵÑéÊÒÔÚÏêϸÆÊÎöÐæÅºÍÃÜÂëÈÆ¹ýÖ®ºó£¬Õ¹ÍûÁËÒ»ÖÖÕë¶ÔÆÕ¶ÉÄ£×Ólevel1²ã¼¶µÄÀÕË÷¹¥»÷£¬²¢´Ó¶à¸öά¶È³ö·¢¶ÔÆä¾ÙÐзÀÓù£ºÊ×ÏÈ£¬ÔÚÇå¾²·À»¤²úÆ·ÖГ֯ºÃ¹æÔòÍø”£¬½«Ãô¸Ð²Ù×÷µÄ¹¦Ð§ÂëÌí¼Óµ½Çå¾²²úÆ·µÄ¹æÔòÖУ»½ÓÏÂÀ´£¬´Ó¹¤³§µÄÔËάÖÎÀí²ãÃæ³ö·¢×öºÃÉí·ÝÉó²é¡¢ÐÐΪÉó²éµÈ£»Æä´Î£¬Òª½â¾öÎÊÌâÐèÒª´ÓȪԴ³ö·¢£¬Õкô¹¤¿Ø³§ÉÌ´ÓÔöÌíË«ÏòÊÚȨÈÏÖ¤»úÖÆ¡¢Ê¹ÓÃÔöÇ¿Ð͵ļÓÃÜËã·¨¡¢×èÖ¹ÐÅϢй¶¡¢ÔÚPLC²à¾ÙÐÐÊÚȨȷÈϵȷ½Ãæ°ü¹Ü²úÆ·µÄÇå¾²£»×îºó£¬ÍùÍùÊÇÏֽ׶δ󲿷ÖÈËËùºöÂԵģ¬Çå¾²µÄPLC±àÂëÒ²Êǹ¹½¨¹¤¿ØÇå¾²±Ø²»¿ÉÉÙµÄÒ»¸öϸ½Ú£¬ËäÈ»PLCµÄÇå¾²±àÂë²»¿ÉÍêÈ«µÖÓù¹¥»÷£¬¿ÉÊÇ¿ÉÒÔÔںܺéÁ÷ƽ×èÖ¹¹ýʧ»òÕß×ÊÖúÔ¤¾¯¹¥»÷¡¢ËÝÔ´¹¥»÷¡£Òò´Ë£¬¸ñÎïʵÑéÊÒÒ²ÔÚÒéÌâÖÐÕкô¸÷È˹Ø×¢Õⲿ·ÖÄÚÈÝ£¬ÕùÈ¡Â䵨µ½Ã¿¸öPLCµÄ±à³ÌÖС£ÎªÁËÄܹ»Èøü¶àµÄÈËÏàʶµ½PLCÇå¾²±àÂëµÄÏêϸÄÚÈÝ£¬ºóÐø¸ñÎïʵÑéÊÒ½«»áÐû²¼¡¶Top_20_Secure_PLC_Coding_Practices_V1.0¡·µÄÖÐÎÄ·Òë°æ±¾£¬¾´Çë¹Ø×¢¡£
HITB×÷Ϊ¹ú¼Ê¹«ÈϵÄ×î¾ßÓ°ÏìÁ¦µÄÐÅÏ¢Çå¾²¾Û»á£¬ÏÖÔÚÒѳÉΪȫÇòÊ®´óÇå¾²·å»áÖ®Ò»£¬Ò²ÊÇÅ·ÖÞ¹æÄ£×î´ó¡¢Ë®Æ½×î¸ßµÄÐÅÏ¢Çå¾²¾Û»á¡£´ó»áÿÄêÔÚºÉÀ¼°¢Ä·Ë¹Ìص¤ºÍÐÂ¼ÓÆÂ¾ÙÐУ¬ËùÓвλáµÄ±¨¸æ¶¼Ðè¾ÓÉͶ¸åÓë¹ûÕæÆÀÑ¡µÈ³ÌÐò£¬ÆäÈÎÃü±ÈÀýµÍÓÚ10%£¬ÉîÊÜÐÅÏ¢Çå¾²Ïà¹ØÁìÓòµÄѧÕßÓë´ÓÒµÖ°Ô±µÄ½Ó´ý¡£

Ê©ÄÍµÂµçÆø£¨Schneider Electric£©ÊÇ·¨¹úÒ»¼Ò¿ç¹úÆóÒµ£¬½¨ÉèÓÚ1836Ä꣬ÊÇÌìÏÂ×î´óÄÜÔ´ÖÎÀí¹«Ë¾¡¢ÓÅ»¯½â¾ö¼Æ»®¹©Ó¦ÉÌÖ®Ò»£¬Ö÷Òª²úÆ·°üÀ¨¶Ï·Æ÷¡¢´«¸ÐÆ÷¡¢¿ØÖÆÆ÷µÈ£¬Îª¸÷¹úÄÜÔ´ÉèÊ©¡¢¹¤Òµ¡¢Êý¾ÝÖÐÐļ°ÍøÂç¡¢´óÂ¥ÌṩÕûÌå½â¾ö¼Æ»®¡£ÔÚÄÜÔ´¡¢»ù´¡ÉèÊ©¡¢¹¤ÒµÀú³Ì¿ØÖÆ¡¢Â¥Óî×Ô¶¯»¯¡¢Êý¾ÝÖÐÐÄÓëÍøÂçµÈÊг¡£¬½Ô´¦ÓÚÌìÏÂÁìÏÈְλ¡£

AG¹«Ë¾ÔÆ







