A Study of Information Security for Computerized Process Control
製造業,如石化工廠,其製造流程隨著科技的進步而電腦化,而負責監控製造流程的系統,在石化業界則通稱為製程控制系統。企業往往透過製程的改善方案,來達到降低生產成本以及提升產品的品質。製程改善方案的進行需要充分的資訊與技術來支持,使得製程控制網路(Process Control Network)與製程資訊系統(Process Information System)所在的製程資訊網路(Process Information Network)以及企業內部網路(Intranet)的連接逐漸成為趨勢。由於各個網路的相連接,製程控制系統處於電腦病毒、蠕蟲、駭客以及其他惡意程式攻擊的威脅。製程控制系統依照操作員的指令控制生產流程,維持工廠在安全的操作條件下運轉,製程控制系統可以說是工廠運轉的核心。製程控制系統如果發生了駭客攻擊或是電腦病毒感染等資訊安全事件,其影響將有可能是製程重要資訊外洩、監控製程的主機或工作站當機、甚至有可能是造成整個製程控制系統癱瘓而危害到工廠之運轉,更嚴重的狀況可能是造成環境污染、工廠爆炸、或生命財產損傷的工安事件。因此,強化製程控制系統的資訊安全機制,確保工廠操作的可靠性以及安全性,是企業必須重視的課題。
In manufacturing industrial, for example, petrochemical plant, the promotion of technology makes manufacturing process computerization to be possible. The systems which control the manufacturing process are called Process Control System. Enterprises introduce the projects of process improvement to reduce the operation cost and enhance the product quality. It is necessary to have comprehensive information and technology to support the success of project for process improvement. Thus, it is a trend to setup the connections among Process Control Network, Process Information Network and Intranet. Due to the connections among networks, Process Control System is facing the threats of computer viruses, worms, attackers, and other malicious codes. Process Control System controls the manufacturing process base on the instructions issued from operators to maintain plant operations in a safe condition. Process Control System is the kernel of process operations. If Process Control System is being attacked or infected by computer viruses, the impacts would be the disclosure of critical business information, the failure of servers/workstations for monitoring process, or Process Control System fails totally that result in the plant operations with risky. The worst case would be an incident about pollution of environment, explosion, properties destroyed, or life lost. Therefore, enterprise should focus on reinforcing the information security mechanism of Process Control System to ensure plant operations reliably and safely.
The objectives of this study are: a) To realize the challenges and threats that Process Control System is facing by the way of literature review. b) To discuss information security management related issues and resolutions of Process Control System base on physical, network, and servers respectively. c) To discuss the efficiency of the model of information security management that has been implemented in the enterprise. d) To make this study as a reference for related industries.
