At present, the international cyberspace confrontation is becoming more and more intense, and incidents such as the Ukrainian blackout, the Iranian Stuxnet virus, and the Russian-Ukrainian cyber war show that the power system is becoming the main target of cyber warfare. China's electric power industrial control system focuses on border protection, and the endogenous protection means of the system are insufficient to effectively respond to various supply chain and APT attacks that continue to emerge, while the application of new technologies such as 5G and the Internet of Things has further expanded the exposure of attacks. At the same time, the Cybersecurity Law, Classified Protection 2.0, and Critical Information Infrastructure Protection put forward new requirements for independent and controllable, safe and credible, and domestic substitution. Therefore, it is urgent to carry out research on the key technologies of endogenous defense of power industry control threats, and further improve the detection and response ability of the system itself to cope with high-level threats. This report mainly introduces our related work in accordance with the ontology protection ideas of "hardware trust, system immunity, service controllability, and threat response".
Industrial control system is the core link of industrial production and manufacturing, and industrial control safety has become an important guarantee for the safety of critical infrastructure and an important guarantee for national security. The safety elements of the industrial control system include policy, management, technology, programs, talents and services, and it is necessary to build an industrial control safety system from the safety elements. From the level of industrial control safety market, in order to enable security personnel to cope with the increasingly complex security situation and offensive and defensive technologies, it is necessary to adapt the construction and development of industrial control safety personnel skills and equipment to the innovation of safety theory through range training and testing.
With the advancement of digital transformation in the industrial field, industrial enterprises have gradually shifted from the production and manufacturing of traditional production workshops to digital industrialization and production digitalization, and data, as a digital element with production benefits, has become the key to digital development.
At the same time, with the increase in the demand for cloud, data interaction and circulation (and even cross-border transmission) on business systems, the security management and security protection problems at the data level in the industrial field are gradually increasing, and the form of industrial data security is complex and severe.
This practical report on data security management and operation in the industrial field puts forward some thinking and practice paths on how to carry out targeted protection of massive industrial data, promote the safe and orderly flow of data in the industrial field, ensure the safe use of business applications, and timely discover potential data risks and deal with them in a timely manner.