Asset scanning and discovery is the first and foremost step for organizations to understand what assets they have and what to protect. There is currently a plethora of free and commercial asset scanning tools specializing in identifying assets in industrial control systems (ICS). However, there is little information available on their comparative capabilities and how their respective features contrast. Nor is it clear to what depth of scanning these tools can reach and whether they are fit-for-purpose in a scaled industrial network architecture. We provide the first systematic feature comparison of free-to-use asset scanning tools on the basis of an ICS scanning taxonomy that we propose. Based on the taxonomy, we investigate scanning depths reached by the tools' features and validate our investigation through experimentation on Siemens, Schneider Electric, and Allen Bradley devices in a testbed environment.
翻译:资产扫描和发现是各组织了解其拥有哪些资产和需要保护哪些资产的首要步骤。目前有大量专门查明工业控制系统中资产的自由商业资产扫描工具(ICS),然而,关于这些工具的相对能力及其各自特点如何不同,目前几乎没有信息可资利用,不清楚这些工具的扫描深度如何,在规模较大的工业网络结构中是否适合用途。我们根据我们提议的ICS扫描分类法,对自由使用资产扫描工具进行首次系统特征比较。我们根据分类法,调查这些工具的特征所达到的扫描深度,并通过测试环境中的Siemens、Schneiderectric和Allen Bradley设备试验来验证我们的调查。