Method for monitoring illegal reading and writing of Siemens S7-PLC data
A technology of S7-PLC and Siemens, which is used in the field of monitoring illegal reading and writing of Siemens S7-PLC data, which can solve the problems of industrial control system security risks, long release cycle, and increased attack paths.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0031] The present invention will be further described below with reference to the drawings and embodiments. Such as figure 1 As shown, the method of the present invention includes the following steps:
[0032] S001: Set the switch to the working mode of bypass mirroring, and mirror all PLC communication traffic of Siemens S7-PLC;
[0033] S002: Analyze the mirrored PLC communication flow to determine whether the application layer protocol of the data packet in the PLC communication flow is the s7comm protocol, if yes, go to step S003, otherwise go to step S002; the specific steps of step S002 include:
[0034] S0021: Find whether the data packet contains the request connection identifier 0x11e00000000100c0010ac1020100c202, if it is, go to step S0022, otherwise go to step S0021, where 0xe0 represents a request to establish a PLC communication connection;
[0035] S0022: Find whether the data packet after the request connection identifier 0x11e00000000100c0010ac1020100c202 contains the...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 
