
- Home
高级 检索
Chinese
English



1.西安电子科技大学陕西省网络与系统安全重点实验室,陕西 西安 710126
2.西安电子科技大学计算机科学与技术学院,陕西 西安 710126
3.西安电子科技大学网络与信息安全学院,陕西 西安 710126
4.军事科学院系统工程研究院,北京,100091
5.华为技术有限公司,广东 深圳 518129
Received:12 June 2026,
Revised:2026-08-22,
Accepted:24 August 2026,
移动端阅览
Zhang Zhiwei, Tang Guiyuan, Shen Yulong, et al. Survey on deterministic endogenous security defense techniques for industrial Internet[J/OL]. Journal on Communications, 2026.
Zhang Zhiwei, Tang Guiyuan, Shen Yulong, et al. Survey on deterministic endogenous security defense techniques for industrial Internet[J/OL]. Journal on Communications, 2026. DOI: 10.11959/j.issn.1000-436x.TXXB260345.
针对工业互联网严苛运行约束与传统外挂式静态边界防护范式间存在的结构性失配问题,开展确定性内生安全防御研究。围绕系统内在的实体、行为、结构与环境四类确定性,提出了确定性内生安全防御范式;系统综述内生身份管理、任务行为确保、未知攻击研判、主动安全防御与安全效能评测五类关键使能技术,构建了涵盖理论基础、体系模型与四维立体化技术架构的内生安全防御体系。对比分析揭示了现有内生安全实践在跨路线协同与场景适配上的共性瓶颈;在智能制造与工业5G场景中分析表明,所提架构能够支撑从理论机制到工程防护的转化,以系统内在确定性对抗威胁不确定性,为解决工业互联网安全跨域联动与动态演化瓶颈提供可行路径。
To address the structural mismatch between strict operational constraints of the Industrial Internet and the conventional bolt-on
static-perimeter security paradigm
research on deterministic endogenous security defense was conducted. A deterministic endogenous security defense paradigm was proposed based on four categories of intrinsic determinism: entity
behavior
structure
and environment. Five key enabling technologies were systematically surveyed: endogenous identity management
task-behavior assurance
unknown-attack inference
active security defense
and security effectiveness evaluation. These were used to construct an endogenous security defense architecture covering prerequisites
system models
and four-dimensional technical implementation. The common bottlenecks of existing endogenous security practices in cross-path coordination and scenario adaptation were revealed through comparative analysis. Scenario analyses in intelligent manufacturing and industrial 5G illustrate that the proposed architecture can support the translation from theoretical mechanisms into engineering protection by leveraging intrinsic system determinism to counter threat uncertainty
thereby providing a viable path to addressing the cross-domain coordination and dynamic-evolution bottlenecks of industrial Internet security.
刘奇旭 , 肖聚鑫 , 谭耀康 , 等 . 工业互联网流量分析技术综述 [J ] . 通信学报 , 2024 , 45 ( 8 ): 221 - 237 .
LIU Q X , XIAO J X , TAN Y K , et al . Survey of industrial Internet traffic analysis technology [J ] . Journal on Communications , 2024 , 45 ( 8 ): 221 - 237 .
中共中央 . 中共中央关于制定国民经济和社会发展第十五个五年规划的建议 [EB/OL ] . ( 2025-10-28 )[ 2026-05-28 ] . https://www.news.cn/politics/20251028/08920d9f557c432e99459f8f468504db/c.html https://www.news.cn/politics/20251028/08920d9f557c432e99459f8f468504db/c.html .
全国人民代表大会 . 中华人民共和国国民经济和社会发展第十五个五年规划纲要 [EB/OL ] . ( 2026-03-13 )[ 2026-05-28 ] . https://www.gov.cn/yaowen/liebiao/202603/content_7062633.htm https://www.gov.cn/yaowen/liebiao/202603/content_7062633.htm .
李强 . 政府工作报告: 2026年3月5日在第十四届全国人民代表大会第四次会议上 [EB/OL ] . ( 2026-03-05 )[ 2026-05-28 ] . https://www.gov.cn/yaowen/liebiao/202603/content_7062625.htm https://www.gov.cn/yaowen/liebiao/202603/content_7062625.htm .
The White House . National strategy for advanced manufacturing [EB/OL ] . ( 2022-10-07 )[ 2026-05-28 ] . https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/10/National-Strategy-for-Advanced-Manufacturing-10072022.pdf https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/10/National-Strategy-for-Advanced-Manufacturing-10072022.pdf .
Plattform Industrie 4.0 . 2030 Vision for Industrie 4.0 [EB/OL ] . ( 2019 )[ 2026-05-28 ] . https://www.plattform-i40.de/IP/Redaktion/EN/Downloads/Publikation/Vision-2030-for-Industrie-4.0.html https://www.plattform-i40.de/IP/Redaktion/EN/Downloads/Publikation/Vision-2030-for-Industrie-4.0.html .
Directorate-General for Research and Innovation . Industry 5 . 0 : towards a sustainable, human-centric and resilient European industry[EB/OL ] . ( 2021-01-05 )[ 2026-05-28 ] . https://research-and-innovation.ec.europa.eu/knowledge-publications-tools-and-data/publications https://research-and-innovation.ec.europa.eu/knowledge-publications-tools-and-data/publications .
FEDERAL BUREAU OF INVESTIGATION , CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY , NATIONAL SECURITY AGENCY , et al . Iranian-affiliated cyber actors exploit programmable logic controllers across US critical infrastructure: A A26 - 097 A[R/OL ] . ( 2026-04-07 )[ 2026-07-20 ] . https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
国家互联网应急中心 . 关于国家授时中心遭受美国国家安全局网络攻击事件的技术分析报告 [R/OL ] . ( 2025-10-19 )[ 2026-05-28 ] . https://www.cert.org.cn/publish/main/49/2025/20251019142622914870997/20251019142622914870997_.html https://www.cert.org.cn/publish/main/49/2025/20251019142622914870997/20251019142622914870997_.html .
DRAGOS Inc . 2026 OT cybersecurity year in review [R/OL ] . Hanover : Dragos , 2026 [ 2026-05-28 ] . https://www.dragos.com/ot-cybersecurity-year-in-review https://www.dragos.com/ot-cybersecurity-year-in-review .
STOUFFER K , PEASE M , TANG C Y , et al . Guide to operational technology (OT) security: NIST SP 800-82 Rev. 3 [R ] . Gaithersburg : National Institute of Standards and Technology , 2023 .
黄涛 , 王郅伟 , 刘家池 , 等 . 工控协议安全研究综述 [J ] . 通信学报 , 2024 , 45 ( 6 ): 60 - 74 .
HUANG T , WANG Z W , LIU J C , et al . Survey on industrial control protocol security research [J ] . Journal on Communications , 2024 , 45 ( 6 ): 60 - 74 .
冯涛 , 鲁晔 , 方君丽 . 工业以太网协议脆弱性与安全防护技术综述 [J ] . 通信学报 , 2017 , 38 ( S2 ): 185 - 196 .
FENG T , LU Y , FANG J L . Survey on vulnerability and technology of industrial Ethernet protocol [J ] . Journal on Communications , 2017 , 38 ( S2 ): 185 - 196 .
邬江兴 . 论网络空间内生安全问题及对策 [J ] . 中国科学: 信息科学 , 2022 , 52 ( 10 ): 1929 - 1937 .
WU J X . Cyberspace’s endogenous safety and security problem and the countermeasures [J ] . Scientia Sinica(Informationis) , 2022 , 52 ( 10 ): 1929 - 1937 .
邬江兴 . 网络空间拟态防御研究 [J ] . 信息安全学报 , 2016 , 1 ( 4 ): 1 - 10 .
WU J X . Research on cyber mimic defense [J ] . Journal of Cyber Security , 2016 , 1 ( 4 ): 1 - 10 .
罗兴国 , 仝青 , 张铮 , 等 . 拟态防御技术 [J ] . 中国工程科学 , 2016 , 18 ( 6 ): 69 - 73 .
LUO X G , TONG Q , ZHANG Z , et al . Mimic defense technology [J ] . Strategic Study of CAE , 2016 , 18 ( 6 ): 69 - 73 .
ROSE S , BORCHERT O , MITCHELL S , et al . Zero trust architecture: NIST SP 800-207 [R ] . Gaithersburg : National Institute of Standards and Technology , 2020 .
韦国华 , 李挥 , 白永杰 , 等 . 天地一体化内生安全多标识网络体系 [J ] . 天地一体化信息网络 , 2020 , 1 ( 2 ): 66 - 72 .
WEI G H , LI H , BAI Y J , et al . Space-terrestrial integrated multi-identifier network with endogenous security [J ] . Space-Integrated-Ground Information Networks , 2020 , 1 ( 2 ): 66 - 72 .
秦中元 , 胡爱群 . 可信计算系统及其研究现状 [J ] . 计算机工程 , 2006 , 32 ( 14 ): 111 - 113 .
QIN Z Y , HU A Q . Trusted computing system and its current research [J ] . Computer Engineering , 2006 , 32 ( 14 ): 111 - 113 .
邬江兴 . 网络空间拟态防御原理: 广义鲁棒控制与内生安全 [M ] . 北京 : 科学出版社 , 2018 .
WU J X . Principles of cyberspace mimic defense: generalized robust control and endogenous security [M ] . Beijing : Science Press , 2018 .
胡爱群 , 方兰婷 , 李涛 . 基于仿生机理的内生安全防御体系研究 [J ] . 网络与信息安全学报 , 2021 , 7 ( 1 ): 11 - 19 ..
HU A Q , FANG L T , LI T . Research on bionic mechanism based en-dogenous security defense system [J ] . Chinese Journal of Network and Information Security , 2021 , 7 ( 1 ): 11 - 19 ..
JAJODIA S , GHOSH A K , SWARUP V , et al . Moving target defense: creating asymmetric uncertainty for cyber threats [M ] . New York : Springer , 2011 .
方滨兴 , 时金桥 , 王忠儒 , 等 . 人工智能赋能网络攻击的安全威胁及应对策略 [J ] . 中国工程科学 , 2021 , 23 ( 3 ): 60 - 66 .
FANG B X , SHI J Q , WANG Z R , et al . AI-enabled cyberspace attacks: security risks and countermeasures [J ] . Strategic Study of CAE , 2021 , 23 ( 3 ): 60 - 66 .
THEODOROPOULOS T , ROSA L , BENZAID C , et al . Security in cloud-native services: a survey [J ] . Journal of Cybersecurity and Privacy , 2023 , 3 ( 4 ): 758 - 793 .
WARD R , BEYER B . BeyondCorp: a new approach to enterprise security [J ] . ; login: , 2014 , 39 ( 6 ): 6 - 11 .
奇安信战略咨询规划部 , 奇安信行业安全研究中心 . 内生安全: 新一代网络安全框架体系与实践 [M ] . 北京 : 人民邮电出版社 , 2021 .
Gartner . Implement a continuous threat exposure management (CTEM) program [R/OL ] . Stamford : Gartner Inc. , 2025 [ 2026-05-28 ] . https://www.gartner.com/en/documents/6884566 https://www.gartner.com/en/documents/6884566 .
中兴通讯股份有限公司 . 2030+ 网络内生安全愿景白皮书 [R ] . 深圳 : 中兴通讯 , 2021 [2026-05-28 ] . https://www.zte.com.cn.
王刚 , 胡鑫 , 吴昊 , 等 . 网络生态系统动态演化 [M ] . 西安 : 西安电子科技大学出版社 , 2019 .
WANG G , HU X , WU H , et al . Dynamical evolution of cyber eco-system [M ] . Xi'an : Xidian University Press , 2019 .
ROSS R , PILLITTERI V , GRAUBART R , et al . Developing cyber-resilient systems: a systems security engineering approach: NIST SP 800-160 Vol. 2 Rev. 1 [R ] . Gaithersburg : National Institute of Standards and Technology , 2021 .
KALOROUMAKIS P E , SMITH M J . Toward a knowledge graph of cybersecurity countermeasures [R ] . McLean : The MITRE Corporation , 2020 .
Gartner . What Is a Digital Immune System and Why Does It Matter? [EB/OL ] . Stamford : Gartner Inc. , 2022 [ 2026-05-28 ] . https://www.cdotrends.com/story/17584/what-digital-immune-system-and-why-does-it-matter https://www.cdotrends.com/story/17584/what-digital-immune-system-and-why-does-it-matter .
中国联通研究院 , 中国联通网络安全研究院 , 下一代互联网宽带业务应用国家工程研究中心 . 中国联通基于5G/5G-A网络的天地一体化安全白皮书 [R/OL ] . 北京 : 中国联通 , 2023 [ 2026-05-28 ] . http://221.179.172.81/images/20231129/96001701241780061.pdf http://221.179.172.81/images/20231129/96001701241780061.pdf .
薛向阳 , 邹宏 , 赵进 , 等 . 数据基础设施抗测绘理论与技术发展研究 [J ] . 中国工程科学 , 2025 , 27 ( 1 ): 72 - 87 .
XUE X Y , ZOU H , ZHAO J , et al . Advance in anti-surveying-and-mapping theory and technologies for data infrastructure [J ] . Strategic Study of CAE , 2025 , 27 ( 1 ): 72 - 87 .
KEPHART J O , CHESS D M . The vision of autonomic computing [J ] . Computer , 2003 , 36 ( 1 ): 41 - 50 .
FISHER K . HACMS: high assurance cyber military systems [J ] . ACM SIGAda Ada Letters , 2012 , 32 ( 3 ): 51 - 52 .
VMware Inc . Protecting applications with VMware NSX [R/OL ] . Palo Alto : VMware Inc. , 2023 [ 2026-05-28 ] . https://www.vmware.com/docs/protecting-applications-with-vmware-nsx-advanced-load-balancer https://www.vmware.com/docs/protecting-applications-with-vmware-nsx-advanced-load-balancer .
郑建华 . 新形势下密码研究的思考 [J ] . 网络安全和信息化 , 2018 , ( 10 ): 38 .
ZHENG J H . Thinking about cryptography research under the new situation [J ] . Cybersecurity & Informatization , 2018 ( 10 ): 38 .
华为技术有限公司 . 6G: 无线通信新征程白皮书 [R/OL ] . 深圳 : 华为技术有限公司 , 2022 [ 2026-05-28 ] . https://www.huawei.com/cn/huaweitech/future-technologies/6g-white-paper https://www.huawei.com/cn/huaweitech/future-technologies/6g-white-paper .
冯登国 . 机密计算发展现状与趋势 [J ] . 信息安全研究 , 2024 , 10 ( 1 ): 2 - 5 .
FENG D G . The status and trends of confidential computing [J ] , Journal of Information Security Research , 2024 , 10 ( 1 ): 2 - 5 .
NING H , FARHA F , ULLAH A , et al . Physical unclonable function: architectures, applications and challenges for dependable security [J ] . IET Circuits , Devices & Systems, 2020 , 14 ( 4 ): 407 - 424 .
闫高丽 , 付雪 , 王禹 , 等 . 面向射频指纹信号分析与智能识别的研究综述 [J ] . 南通大学学报(自然科学版) , 2025 , 24 ( 2 ): 1 - 21 .
YAN G L , FU X , WANG Y , et al . A survey on radio frequency fingerprint signal analysis and intelligent identification [J ] . Journal of Nantong University(Natural Science Edition) , 2025 , 24 ( 2 ): 1 - 21 .
WANG Q H , KANG M Y , YUAN L F , et al . On the application of channel characteristic-based physical layer authentication in industrial wireless networks [J ] . KSII Transactions on Internet and Information Systems , 2021 , 15 ( 6 ): 2255 - 2281 .
SHEN G X , ZHANG J Q , MARSHALL A , et al . Deep learning-powered radio frequency fingerprint identification: methodology and case study [J ] . IEEE Communications Magazine , 2023 , 61 ( 9 ): 170 - 176 .
ZHAO X W , LI D X , LI H . Practical three-factor authentication protocol based on elliptic curve cryptography for industrial Internet of Things [J ] . Sensors , 2022 , 22 ( 19 ): 7510 .
SHRUTI , RANI S , SAH D K , et al . Attribute-based encryption schemes for next generation wireless IoT networks: a comprehensive survey [J ] . Sensors , 2023 , 23 ( 13 ): 5921 .
YANG W C , WANG S , CUI H , et al . A review of homomorphic encryption for privacy-preserving biometrics [J ] . Sensors , 2023 , 23 ( 7 ): 3566 .
LIANG Y J , SAMTANI S , GUO B , et al . Behavioral biometrics for continuous authentication in the Internet-of-Things era: an artificial intelligence perspective [J ] . IEEE Internet of Things Journal , 2020 , 7 ( 9 ): 9128 - 9143 .
XIE N , LI Z X , TAN H J . A survey of physical-layer authentication in wireless communications [J ] . IEEE Communications Surveys & Tutorials , 2020 , 23 ( 1 ): 282 - 310 .
AL-NAJI F H , ZAGROUBA R . A survey on continuous authentication methods in Internet of Things environment [J ] . Computer Communications , 2020 , 163 : 109 - 133 .
RAGOTHAMAN K , WANG Y , RIMAL B . Access control for IoT: A survey of existing research, dynamic policies and future directions [J ] . Sensors , 2023 , 23 ( 4 ): 1805 .
WANG W Z , HUANG H K , YIN Z M , et al . Smart contract token-based privacy-preserving access control system for industrial Internet of Things [J ] . Digital Communications and Networks , 2023 , 9 ( 2 ): 337 - 346 .
KANG H Z , LIU G , WANG Q , et al . Theory and application of zero trust security: a brief survey [J ] . Entropy , 2023 , 25 ( 12 ): 1595 .
TRABELSI R , FERSI G , JMAIEL M . Access control in Internet of Things: a survey [J ] . Computers & Security , 2023 , 135 : 103472 .
LIU I H , CHOU P W , CHEN N Y , et al . Identifying Industrial Control Systems Anomalies Operation Based on Finite-State Machines [J ] . Journal of Advances in Artificial Life Robotics , 2025 , 4 ( 3 ): 146 - 149 .
HUSSAIN M , FIDGE C , FOO E . Discovering a data interpreted Petri net model of industrial control systems for anomaly detection [J ] . Expert Systems with Applications , 2023 , 230 : 120511 .
GHAEINI H R , ANTONIOLI D , BRASSER F , et al . State-aware anomaly detection for industrial control systems [C ] // Proceedings of the 33rd Annual ACM Symposium on Applied Computing . New York : ACM , 2018 : 1620 - 1628 .
ZHAO X , ZHANG L , CAO Y , et al . Anomaly detection approach in industrial control systems based on measurement data [J ] . Information , 2022 , 13 ( 10 ): 450 .
ZHANG Y , LIU J , WANG Z , et al . MICHC-NN: An Offline Industrial Control Anomaly Detection Algorithm Based on Maximum Information Coefficient [J ] . IEEE Internet of Things Journal , 2026 .
ALY A , MANSOUR E , YOUSSEF A . OCR-APT: Reconstructing APT stories from audit logs using subgraph anomaly detection and LLMs [C ] // Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security . 2025 : 261 - 275 .
QI J , LUAN Z , HUANG S , et al . LogMoE: Lightweight Expert Mixture for Cross-System Log Anomaly Detection [C ] // 2025 40th IEEE/ACM International Conference on Automated Software Engineering . IEEE , 2025 : 330 - 341 .
FERRAIOLO D F , SANDHU R , GAVRILA S , et al . Proposed NIST standard for role-based access control [J ] . ACM Transactions on Information and System Security (TISSEC) , 2001 , 4 ( 3 ): 224 - 274 .
HU V C , FERRAIOLO D , KUHN R , et al . Guide to attribute based access control (abac) definition and considerations (draft) [R ] . NIST special publication , 2013 , 800(162): 1-54.
International Society of Automation . ISA/IEC 62443 Series of Standards [EB/OL ] . [ 2026-06-08 ] . https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards .
ETXEZARRETA X , GARITANO I , ZURUTUZA U , et al . Software-defined networking approaches for intrusion response in industrial control systems: a survey [J ] . International Journal of Critical Infrastructure Protection , 2023 , 42 : 100615 .
CASELLI M , ZAMBON E , KARGL F . Specification mining for intrusion detection in networked control systems [C ] // Proceedings of the 25th USENIX Security Symposium . Berkeley : USENIX Association , 2016 : 791 - 806 .
FENG C , PALLETI V R , MATHUR A , et al . A systematic framework to generate invariants for anomaly detection in industrial control systems [C ] // Proceedings of the 26th Network and Distributed System Security Symposium . Reston : Internet Society , 2019 : 1 - 15 .
ZHANG B , GAO Y , YU C , et al . TAPAS: An Efficient Online APT Detection with Task-guided Process Provenance Graph Segmentation and Analysis [C ] // 34th USENIX Security Symposium . 2025 : 607 - 624 .
SINGHAL A , OU X . Security risk analysis of enterprise networks using probabilistic attack graphs: NISTIR 7788 [R ] . Gaithersburg : National Institute of Standards and Technology , 2011 .
UNGER S , ARZOGLOU E , HEINRICH M , et al . Cybersecurity risk assessment in OT systems using attack graphs [J ] . International Journal of Information Security , 2026 , 25 ( 1 ): 34 .
SAHU A , DAVIS K . Inferring adversarial behaviour in cyber-physical power systems using a Bayesian attack graph approach [J ] . IET Cyber‐Physical Systems: Theory & Applications , 2023 , 8 ( 2 ): 91 - 108 .
POOLSAPPASIT N , DEWRI R , RAY I . Dynamic security risk management using Bayesian attack graphs [J ] . IEEE Transactions on Dependable and Secure Computing , 2011 , 9 ( 1 ): 61 - 74 .
HOLGADO P , VILLAGRÁ V A , VAZQUEZ L . Real-time multistep attack prediction based on hidden markov models [J ] . IEEE Transactions on Dependable and Secure Computing , 2017 , 17 ( 1 ): 134 - 147 .
SHEN Y , MARICONTI E , VERVIER P A , et al . Tiresias: Predicting security events through deep learning [C ] // Proceedings of the 2018 ACM SIGSAC conference on computer and communications security . 2018 : 592 - 605 .
DENG A L , HOOI B . Graph neural network-based anomaly detection in multivariate time series [C ] // Proceedings of the 35th AAAI Conf on Artificial Intelligence . Palo Alto : AAAI Press , 2021 , 35 ( 5 ): 4027 - 4035 .
GIRALDO J , URBINA D , CARDENAS A , et al . A survey of physics-based attack detection in cyber-physical systems [J ] . ACM Computing Surveys , 2018 , 51 ( 4 ): 1 - 36 .
Dong F , Wang L , Nie X , et al . DISTDET: A Cost-Effective distributed cyber threat detection system [C ] // 32nd USENIX Security Symposiu . 2023 : 6575 - 6592 .
LI X , JIANG X , WAN H , et al . TeRed: Normal Behavior-Based Efficient Provenance Graph Reduction for Large-Scale Attack Forensics [J ] . IEEE Transactions on Information Forensics and Security , 2025 .
XU L , ZHAO Z , ZHAO D , et al . TraceCluster: A Lightweight and Adaptive Clustering-based Subgraph Attention Network for APT Detection in Provenance Graphs [J ] . IEEE Transactions on Information Forensics and Security , 2026 .
FANG P , GAO P , LIU C , et al . Back-propagating system dependency impact for attack investigation [C ] // Proceedings of the 31st USENIX Security Symposium . Berkeley : USENIX Association , 2022 : 2461 - 2478 .
JIANG B , BILOT T , EL MADHOUN N , et al . ORTHRUS: Achieving High Quality of Attribution in Provenance-based Intrusion Detection Systems [C ] // 34th USENIX Security Symposium . 2025 : 7173 - 7192 .
LI J , ZHANG R , LIU J . ProvGRP: A Context-Aware Provenance Graph Reduction and Partition Approach for Facilitating Attack Investigation [J ] . Electronics , 2024 , 13 ( 1 ): 100 .
LI Z , ZENG J , CHEN Y , et al . AttacKG: Constructing technique knowledge graph from cyber threat intelligence reports [C ] // European symposium on research in computer security . Cham : Springer International Publishing , 2022 : 589 - 609 .
KURNIAWAN K , EKELHART A , KIESLING E , et al . KRYSTAL: knowledge graph-based framework for tactical attack discovery in audit data [J ] . Computers & Security , 2022 , 121 : 102828 .
WANG L , WU D . Seccontrol: Bridging the gap between security tools and sdn controllers [C ] // International Conference on Security and Privacy in Communication Systems . Cham : Springer International Publishing , 2017 : 11 - 31 .
CHAVEZ A R . Moving target defense to improve industrial control system resiliency [M ] // Industrial Control Systems Security and Resiliency: Practice and Theory . Cham : Springer International Publishing , 2019 : 143 - 167 .
ETXEZARRETA X , GARITANO I , ITURBE M , et al . Low delay network attributes randomization to proactively mitigate reconnaissance attacks in industrial control systems [J ] . Wireless Networks , 2024 , 30 ( 6 ): 5077 - 5091 .
JAVADPOUR A , JAFARI F , TALEB T , et al . A comprehensive survey on cyber deception techniques to improve honeypot performance [J ] . Computers & Security , 2024 , 140 : 103792 .
FRANCO J , ARIS A , CANBERK B , et al . A survey of honeypots and honeynets for Internet of things, industrial Internet of things and cyber-physical systems [J ] . IEEE Communications Surveys & Tutorials , 2021 , 23 ( 4 ): 2351 - 2383 .
MAESSCHALCK S , GIOTSAS V , GREEN B , et al . Don't get stung, cover your ICS in honey: how do honeypots fit within industrial control system security [J ] . Computers & Security , 2022 , 114 : 102598 .
ALT L , BEVERLY R , DAINOTTI A . Uncovering network tarpits with degreaser [C ] // Proceedings of the 30th Annual Computer Security Applications Conf . New York : ACM , 2014 : 156 - 165 .
GRIFFIOEN H , DOERR C . Could you clean up the Internet with a Pit of Tar? Investigating tarpit feasibility on Internet worms [C ] // 2023 IEEE Symposium on Security and Privacy . IEEE , 2023 : 2551 - 2565 .
LI Z , WEI X , LI C , et al . Generating detectors from anomaly samples via negative selection for network intrusion detection [J ] . Scientific Reports , 2025 , 15 ( 1 ): 36456 .
KIM Y J , NAM W , LEE J . Multiclass anomaly detection for unsupervised and semi-supervised data based on a combination of negative selection and clonal selection algorithms [J ] . Applied Soft Computing , 2022 , 122 : 108838 .
FENG X , WU J , WU Y , et al . Blockchain and digital twin empowered trustworthy self-healing for edge-AI enabled industrial Internet of things [J ] . Information Sciences , 2023 , 642 : 119169 .
SUDHAKAR K , KUMAR A , ARCHANA R A , et al . Anomaly detection based self-healing mechanism using dynamic diffusion spatial-temporal graph convolutional network in industrial IoT [J ] . Knowledge-Based Systems , 2026 , 331 : 114812 .
Trusted Computing Group . TCG guidance for securing industrial control systems [R ] . Beaverton : Trusted Computing Group , 2022 .
BAI J , MA J F , WANG Y D , et al . Survey on application of trusted computing in industrial control systems [J ] . Electronics , 2023 , 12 ( 19 ): 4182 .
SUN R , ZHU Y , FEI J , et al . A survey on moving target defense: Intelligently affordable, optimized and self-adaptive [J ] . Applied Sciences , 2023 , 13 ( 9 ): 5367 .
LÓPEZ P B , PÉREZ M G , VASILOMANOLAKIS E , et al . Reactive cyber deception: Stealth-based adaptive redirection to on-demand honeypots with AI-driven data generation [J ] . Computer Networks , 2026 : 112203 .
International Organization for Standardization , International Electrotechnical Commission . ISO/IEC 15408-1:2026 Information security, cybersecurity and privacy protection: evaluation criteria for IT security: Part 1: Introduction and general model [S ] . Geneva : ISO , 2026 .
International Organization for Standardization . ISO/IEC/IEEE 29119-1:2022 Software and systems engineering — Software testing — Part 1: General concepts [S ] . Geneva : ISO , 2022 .
IEEE . IEEE Std 1012-2024: IEEE Standard for system, software, and hardware verification and validation [S ] . New York : IEEE , 2025 .
Joint Task Force . Security and privacy controls for information systems and organizations: NIST SP 800-53 Rev. 5 [R ] . Gaithersburg : National Institute of Standards and Technology , 2020 .
SCARFONE K , SOUPPAYA M , CODY A , et al . Technical guide to information security testing and assessment: NIST SP 800-115 [R ] . Gaithersburg : National Institute of Standards and Technology , 2008 .
全国信息安全标准化技术委员会 . GB/T 28448-2019 信息安全技术 网络安全等级保护测评要求 [S ] . 北京 : 中国标准出版社 , 2019 .
National Information Security Standardization Technical Committee . GB/T 28448-2019 Information security technology — Evaluation requirement for classified protection of cybersecurity [S ] . Beijing : Standards Press of China , 2019 .
全国信息安全标准化技术委员会 . GB/T 36466-2018 信息安全技术 工业控制系统风险评估实施指南 [S ] . 北京 : 中国标准出版社 , 2018 .
National Information Security Standardization Technical Committee . GB/T 36466-2018 Information security technology — Implementation guide to risk assessment of industrial control systems [S ] . Beijing : Standards Press of China , 2018 .
STROM B E , APPLEBAUM A , MILLER D P , et al . MITRE ATT&CK: design and philosophy [R ] . McLean : The MITRE Corporation , 2018 .
BODEAU D J , GRAUBART R D , MCQUAID R M , et al . Cyber resiliency metrics, measures of effectiveness, and scoring: MTR180314 [R ] . Bedford : The MITRE Corporation , 2018 .
MATHUR A P , TIPPENHAUER N O . SWaT: a water treatment testbed for research and training on ICS security [C ] // Proceedings of the International Workshop on Cyber-physical Systems for Smart Water Networks . Piscataway : IEEE , 2016 : 31 - 36 .
ANTONIOLI D , TIPPENHAUER N O . MiniCPS: a toolkit for security research on CPS networks [C ] // Proceedings of the 1st ACM Workshop on Cyber-Physical Systems-Security and/or PrivaCy . New York : ACM , 2015 : 91 - 100 .
CONTI M , DONADEL D , TURRIN F . A survey on industrial control system testbeds and datasets for security research [J ] . IEEE Communications Surveys & Tutorials , 2021 , 23 ( 4 ): 2248 - 2294 .
YAMIN M M , KATT B , GKIOULOS V . Cyber ranges and security testbeds: scenarios, functions, tools and architecture [J ] . Computers & Security , 2020 , 88 : 101636 .
工业和信息化部 , 国家标准化管理委员会 . 工业互联网综合标准化体系建设指南(2021版) [R/OL ] . 2021[ 2026-07-21 ] .
国家市场监督管理总局 , 国家标准化管理委员会 . GB/T 44462.1—2024 工业互联网企业网络安全第1部分:应用工业互联网的工业企业防护要求 [S ] . 2024 .
国家市场监督管理总局 , 国家标准化管理委员会 . GB/T 44462.2—2024 工业互联网企业网络安全第2部分:平台企业防护要求 [S ] . 2024 .
国家市场监督管理总局 , 国家标准化管理委员会 . GB/T 44462.3—2024 工业互联网企业网络安全第3部分:标识解析企业防护要求 [S ] . 2024 .
国家市场监督管理总局 , 国家标准化管理委员会 . GB/T 44462.4—2026 工业互联网企业网络安全第4部分:数据防护要求 [S ] . 2026 .
工业和信息化部 . YD/T 6825.1—2026 工业互联网企业网络安全定级方法第1部分:应用工业互联网的工业企业 [S ] . 2026 .
工业和信息化部 . YD/T 6825.2—2026 工业互联网企业网络安全定级方法第2部分:平台企业 [S ] . 2026 .
工业和信息化部 . YD/T 6825.3—2026 工业互联网企业网络安全定级方法第3部分:标识解析企业 [S ] . 2026 .
工业和信息化部 . YD/T 6826—2026 应用工业互联网的工业企业网络安全防护能力评价方法 [S ] . 2026 .
INTERNATIONAL SOCIETY OF AUTOMATION . ANSI/ISA-62443-2-1-2024 Security for industrial automation and control systems—Part 2-1: Security program requirements for IACS asset owners [S ] . Research Triangle Park : ISA , 2024 .
INTERNATIONAL SOCIETY OF AUTOMATION . ISA-TR62443-2-2-2025 Security for industrial automation and control systems—Part 2-2: IACS security protection scheme [R ] . Research Triangle Park : ISA , 2025 .
0
Views
0
下载量
0
CSCD
Publicity Resources
Related Articles
Related Author
Related Institution
京公网安备11010602201714号