http://kadhoai.com.cn 2026-04-26 17:38:40 來源:賽迪智庫信息安全研究所博士
我國工業控製係統安全存在多個薄弱環節,主要有:對(dui)工(gong)控(kong)係(xi)統(tong)安(an)全(quan)問(wen)題(ti)認(ren)識(shi)不(bu)足(zu),工(gong)控(kong)係(xi)統(tong)核(he)心(xin)關(guan)鍵(jian)產(chan)品(pin)被(bei)國(guo)外(wai)壟(long)斷(duan),檢(jian)測(ce)手(shou)段(duan)和(he)檢(jian)測(ce)平(ping)台(tai)缺(que)乏(fa)等(deng)。為(wei)保(bao)障(zhang)我(wo)國(guo)工(gong)控(kong)係(xi)統(tong)和(he)關(guan)鍵(jian)基(ji)礎(chu)設(she)施(shi)安(an)全(quan),我們應該從以下幾方麵著手:
第一,高度重視我國工控係統安全,營造良好氛圍。將工業控製係統提升到國家安全戰略高度,在政府相關文件、信息化規劃、信xin息xi安an全quan規gui劃hua以yi及ji相xiang關guan規gui劃hua中zhong突tu出chu工gong業ye控kong製zhi係xi統tong的de重zhong要yao性xing,明ming確que在zai推tui進jin信xin息xi化hua建jian設she中zhong優you先xian保bao障zhang工gong業ye控kong製zhi係xi統tong安an全quan。提ti高gao各ge級ji領ling導dao以yi及ji全quan社she會hui對dui工gong控kong係xi統tong風feng險xian的de認ren識shi,加jia速su製zhi定ding工gong控kong係xi統tong安an全quan相xiang關guan政zheng策ce,推tui動dong工gong業ye控kong製zhi係xi統tong信xin息xi安an全quan防fang護hu體ti係xi建jian設she,重zhong點dian對dui可ke能neng危wei及ji生sheng命ming和he公gong共gong財cai產chan安an全quan的de工gong控kong係xi統tong加jia強qiang監jian管guan,加jia強qiang核he設she施shi、航空航天、先進製造、石油石化、油氣管網、電力係統、交通運輸、水利樞紐、城市設施等重要領域工控係統,以及物聯網應用、數字城市建設中的安全防護和管理,定期開展安全檢查和風險評估。
第(di)二(er),推(tui)廣(guang)國(guo)產(chan)工(gong)控(kong)係(xi)統(tong)核(he)心(xin)技(ji)術(shu)產(chan)品(pin),確(que)保(bao)我(wo)國(guo)工(gong)業(ye)控(kong)製(zhi)係(xi)統(tong)安(an)全(quan)可(ke)靠(kao)。追(zhui)蹤(zong)研(yan)究(jiu)工(gong)業(ye)控(kong)製(zhi)係(xi)統(tong)國(guo)際(ji)動(dong)態(tai),重(zhong)點(dian)研(yan)究(jiu)新(xin)型(xing)網(wang)絡(luo)攻(gong)擊(ji)的(de)主(zhu)要(yao)特(te)點(dian)和(he)趨(qu)勢(shi),分(fen)析(xi)針(zhen)對(dui)關(guan)鍵(jian)基(ji)礎(chu)設(she)施(shi)及(ji)控(kong)製(zhi)係(xi)統(tong)的(de)新(xin)型(xing)網(wang)絡(luo)威(wei)脅(xie)。加(jia)強(qiang)高(gao)端(duan)通(tong)用(yong)芯(xin)片(pian)、操作係統、數據庫等基礎技術攻關,支持國內企業基於國產芯片研發信息技術裝備、大型SCADA等控製設備和係統,加快國產技術和產品的應用推廣,加速國產工控係統核心技術產品替代國外產品。
第三,開展係統可靠性和安全性測試評估,構建工控係統安全測評體係。推廣國產化通用檢測設備應用,支持國內企業對高端、高速、高精度工控檢測設備的研發。建立國家級工控係統可靠性、安(an)全(quan)性(xing)測(ce)試(shi)評(ping)估(gu)平(ping)台(tai),對(dui)工(gong)控(kong)係(xi)統(tong)進(jin)行(xing)測(ce)試(shi),並(bing)對(dui)關(guan)鍵(jian)領(ling)域(yu)的(de)工(gong)控(kong)係(xi)統(tong),根(gen)據(ju)不(bu)同(tong)的(de)安(an)全(quan)等(deng)級(ji)進(jin)行(xing)網(wang)絡(luo)脆(cui)弱(ruo)性(xing)評(ping)估(gu)。建(jian)立(li)工(gong)控(kong)係(xi)統(tong)漏(lou)洞(dong)數(shu)據(ju)庫(ku),實(shi)行(xing)安(an)全(quan)風(feng)險(xian)和(he)漏(lou)洞(dong)通(tong)報(bao)製(zhi)度(du),收(shou)集(ji)並(bing)及(ji)時(shi)發(fa)布(bu)有(you)關(guan)漏(lou)洞(dong)、風險和預警信息。建立健全工控係統安全測評機製,形成工控係統安全性測試和評估的長效機製。
第四,加快研製工業控製係統國家標準,構建工業控製係統國家標準體係。參照國際電工委員會(IEC)工(gong)業(ye)控(kong)製(zhi)安(an)全(quan)的(de)國(guo)際(ji)標(biao)準(zhun),以(yi)及(ji)美(mei)國(guo)等(deng)國(guo)家(jia)的(de)相(xiang)關(guan)標(biao)準(zhun),在(zai)實(shi)踐(jian)中(zhong)逐(zhu)步(bu)研(yan)製(zhi)我(wo)國(guo)工(gong)業(ye)控(kong)製(zhi)係(xi)統(tong)國(guo)家(jia)標(biao)準(zhun),涵(han)蓋(gai)可(ke)靠(kao)性(xing)和(he)安(an)全(quan)性(xing)兩(liang)方(fang)麵(mian),構(gou)建(jian)工(gong)業(ye)控(kong)製(zhi)係(xi)統(tong)國(guo)家(jia)標(biao)準(zhun)體(ti)係(xi)。