

gkong 工控参考 2023-07-11





In a report released by Honeywell based on cybersecurity threat data collected from hundreds of industrial facilities globally, the severity of threats detected to operational technology (OT) systems has risen by significant amounts over a 12-month period.


The findings from the latest Honeywell Industrial USB Threat Report show that the total amount of threats posed by USB removable media to industrial process control networks remains consistently high, with 45% of locations detecting at least one inbound threat. Over the same time period, the number of threats specifically targeting OT systems nearly doubled from 16 to 28%, while the number of threats capable of causing a loss of view or other major disruption to OT systems more than doubled, from 26 to 59%.

这份最新的《霍尼韦尔工业USB威胁报告》显示,USB可移动媒介对工业过程控制网络构成的威胁总数一直保持较高水平,其中45%的位置检测到至少一个入站威胁。在同一时期,专门针对OT系统的威胁数量几乎翻了一番,从16%增加至28%,而能够对OT系统造成视觉丧失或其他重大破坏的威胁数量翻了一番以上,从26%增至59% 。

The report shows that 1 in 5 of all threats was designed specifically to leverage USB removable media as an attack vector, and more than half the threats were designed to open backdoors, establish persistent remote access or download additional malicious payloads. These findings are indicative of more coordinated attacks, likely attempting to target air-gapped systems used in most industrial control environments and critical infrastructure.


“USB-borne malware continues to be a major risk for industrial operators,” said Eric Knapp, director of Cybersecurity Research and engineering fellow, Honeywell Connected Enterprise, Cybersecurity. “What’s surprising is that we’re seeing a much higher density of significant threats that are more targeted and more dangerous. This isn’t a case of accidental exposure to viruses through USB – it’s a trend of using removable media as part of more deliberate and coordinated attacks.”

“USB传播的恶意软件仍然是工业运营商的主要风险,”霍尼韦尔网络安全公司网络安全研究部主任兼工程研究员Eric Knapp说道。“令人惊讶的是,我们看到的重大威胁密度更高,目标更明确,也更危险。这不是一个通过USB意外感染病毒的案例,而是一种趋势,也就是使用可移动介质作为更加蓄意和协调攻击的一部分。”

The Honeywell Industrial USB Threat Report examines data collected from Honeywell’s Secure Media Exchange (SMX) technology, which is designed to scan and control removable media, including USB drives. As the second most prevalent attack vector into industrial control and automation systems, USB devices play an important role in attacks that target OT systems. In recent years, such attacks have included Disttrack, Duqu, Ekans, Flame, Havex, Industroyer, USBCulprit and others.


To reduce the risk of USB-related threats, Honeywell recommends that organizations implement a blend of OT cybersecurity software products and services such as Honeywell’s Secure Media Exchange (SMX), the Honeywell Forge Cybersecurity Suite, people training and process changes.

为了降低USB相关威胁的风险,霍尼韦尔建议各组织结合OT网络安全软件产品和服务,例如霍尼韦尔的安全媒体交换(SMX)、霍尼韦尔Forge Cybersecurity网络安全套件进行人员培训和流程变更。

SMX provides operators with unprecedented control and visibility into the more secure use of USB technology with the latest in advanced threat detection capability for critical infrastructure and facilities. The Honeywell Forge Cybersecurity Suite can monitor for vulnerabilities such as open ports or the presence of USB security controls to strengthen endpoint and network security, and it helps ensure better cybersecurity compliance.

SMX为操作员提供了前所未有的控制和可视性,使他们能够更安全地使用USB技术,并为关键基础设施和设施提供最新的高级威胁检测功能。霍尼韦尔Forge Cybersecurity网络安全套件可以监视漏洞,例如开放端口或USB安全控制的存在,以增强端点和网络安全性,并帮助确保更好的网络安全合规性。


蹲点调查 | 无灯工厂、柔性生产、人才升级 当中小企业“恋”上工业互联网ABB发布2020年第二季度业绩,运动控制表现出色1353个专业通过工程教育认证,涉及自动化等21个工科专业类
从智能流水线迈向“未来工厂” | 这所大学工业4.0学习工厂长啥样?卷烟厂包装机胶辊改电子齿轮控制初探当前国内工业传感器面临的矛盾与问题|5点发展建议
工业互联网“大象”现在仅摸到“耳朵”近期,一批外企布局的“新基建”项目加速落地埃夫特科创板上市,未来将发力工业通用蓝海市场去年我国产业数字化增加值规模达28.8万亿元打破低端“魔咒”,国产PLC“后浪”发力中高端市场五年合作告终,美的与安川合资的机器人公司宣布解散收购 ASEM后,罗克韦尔自动化推出全新系列工业PC

