水道システムへのサイバー攻撃対策を研究し解決策を提示(As Water Systems Face Cyberattacks, Georgia Tech Research Points to Solutions)

2026-08-06 ジョージア工科大学

ジョージア工科大学(Georgia Tech)の研究チームは、上下水道などの水インフラを標的としたサイバー攻撃の脅威が高まる中、その脆弱性と対策を分析した。水処理施設では、ポンプやバルブ、薬品注入設備などを制御する産業用制御システム(ICS)やSCADAがデジタル化・ネットワーク化されており、不正アクセスやランサムウェアによる運転妨害、水質管理への影響が懸念されている。研究では、技術的な防御策だけでなく、運用管理、リスク評価、職員教育、インシデント対応計画などを組み合わせた多層的なサイバーセキュリティ対策の重要性を指摘した。また、小規模水道事業者では人材や予算不足が課題であり、標準化されたセキュリティ指針や官民連携による支援体制の整備が不可欠としている。本成果は、安全で持続可能な水供給を実現するため、重要インフラのレジリエンス強化に向けた実践的な指針を提供するものである。

<関連情報>

猟犬を解き放て!アクティブネットワークデータを用いた現場展開型PLCの自動推論と経験的セキュリティ評価 Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network Data

Ryan Pickren,Animesh Chotaray,Frank Li,Saman Zonouz,Raheem Beyah
CCS ’24: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security  Published: 09 December 2024
DOI:https://doi.org/10.1145/3658644.3690195

Abstract

Surveying field-deployed Industrial Control System (ICS) equipment has numerous security applications, including attack-surface management and measuring the adoption of vulnerability patches. However, discovering real-world devices using massive Internet-scale scan datasets is tedious and error-prone. We introduce PLCHound, a novel ICS asset discovery solution designed to automatically reveal elusive ICS devices hiding in network data collected by Internet-scale scanners such as Censys or Shodan. Our solution systematically uncovers indirect evidence of controllers using subtle network-based indicators and temporally-resistant signatures that are often overlooked in prior work. We present PLCHound‘s architecture, experimentally verify its accuracy, and explore the security advantages of enhanced device discovery. We also use PLCHound to perform the largest comprehensive examination of the publicly-reachable population of ICS devices by popular vendors. Our results reveal that the industry-accepted estimations and latest published papers undercount the true number of public devices by up to 37x. We also find that 95.88% of devices expose protocols that cause them to be remotely vulnerable to recent critical CVEs.

1604情報ネットワーク
ad
ad
Follow
ad
タイトルとURLをコピーしました