资源描述:
《OPC Security WP2.pdf》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、OPCSecurityWhitePaper#2OPCExposedintrinsicallysecurepobox178#5–7217Lantzvillerdlantzville,bcPREPAREDBY:canadav0r2h0DigitalBondoffice250.390.1333fax250.390.3899BritishColumbiaInstituteofTechnologywww.byressecurity.comByresResearchNovember13,2007DigitalBondOPCSecurityWP2(Version1-3c).docsuite
2、1301580sawgrasscorppkwysunrise,FL33323office954.315.4633www.digitalbond.comRevisionHistoryRevisionDateAuthorsDetails0.7May15,2006E.Byres,MFranz,Draftinternalreviewversion1.0May31,2006E.Byres,J.Carter,MDraftforcontrolledpublicreviewFranz1.1August31,2006E.Byres,M.Franz2ndDraftforcontrolledpub
3、licreview1.2February9,2007E.Byres,D.Peterson3rdDraftforcontrolledpublicreview1.3May16,2007E.Byres,D.PetersonPublicReleaseVersion1.3aJune8,2007TypofixedinSection2.5.4andaddedrequiredvulnerability1.3bAugust27,2007Minorgrammaticalerrorscorrected1.3cNovember13,2007GrammaticalerrorcorrectedinAck
4、nowledgementsTheGroupforAdvancedInformationTechnology(GAIT)attheBritishColumbiaInstituteofTechnology(BCIT),DigitalBond,andByresResearchwouldliketothankallthevendorsandendusersthatgenerouslysupportedoureffortsthroughnumerousinterviewsandbyprovidinguswithdocumentsthatcouldonlybedescribedasext
5、remelysensitive.Unfortunatelywecannotnameyouforobvioussecurityreasons,butweappreciateyourtime,trustandencouragement.Severalpeoplestoodoutintheircontributionsandadviceforthisdocumentthatwewouldliketoacknowledge.FirstareBillCotterofMSMUGandChipLeeofISA-wethankyouforallyourhelpinmakingtheusers
6、urveyspossible.WewouldalsoliketothankRalphLangnerforprovidingthefourexamplescenariosforthisreportandlotsofusefulinformationonOPCvulnerabilities.FinallywewouldliketothankEvanHand,formerlyofKraftFoodsLimited,forhisvisionandsupport.Withouthim,thisprojectneverwouldhavebeenpossible.DisclaimerDep
7、loymentorapplicationofanyoftheopinions,suggestionsorconfigurationincludedinthisreportarethesoleresponsibilityofthereaderandareofferedwithoutwarranteeofanykindbytheauthors.OPCSecurityWP2(Version1-3c).dociiNovember2007TableofContentsExecutiveSummary.......