中国电力 ›› 2017, Vol. 50 ›› Issue (5): 71-77.DOI: 10.11930/j.issn.1004-9649.2017.05.071.07

• 安全专栏 • 上一篇    下一篇

从乌克兰停电事故看电力信息系统安全问题

李保杰1, 刘岩2, 李洪杰1, 何维晟1, 曾祥峰1, 陈硕1   

  1. 1. 西安交通大学 电力设备电气绝缘国家重点实验室,陕西 西安 710049;
    2. 国网乌鲁木齐供电公司,新疆 乌鲁木齐 830011
  • 收稿日期:2017-01-05 出版日期:2017-05-20 发布日期:2017-05-26
  • 作者简介:李保杰(1994—),男,河南新乡人,硕士研究生,从事电力系统安全研究。E-mail:libaojie@stu.xjtu.edu.cn
  • 基金资助:
    国家自然科学基金资助项目(51577147)

Enlightenment on the Security of Cyber Information System Under Smart Grid from Ukraine Blackout

LI Baojie1, LIU Yan2, LI Hongjie1, HE Weisheng1, ZENG Xiangfeng1, CHEN Shuo1   

  1. 1. State Key Lab. of Electrical Insulation for Power Equipment, Xian Jiaotong University, Xian 710049, China;
    2. State Grid Urumqi Electric Power Supply Company, Urumqi 830011, China
  • Received:2017-01-05 Online:2017-05-20 Published:2017-05-26
  • Supported by:
    This work is supported by the National Natural Science Foundation of China (No. 51577147).

摘要: 在1年之内,2015-12-23和2016-12-18,乌克兰电网系统遭受了两起由黑客入侵而引发的严重停电事故,其中,前一起被认为是世界上首起公开的针对电网基础设施的网络信息攻击事件。回顾了2015年停电事故的全过程,推演分析网络攻击的手法和效果,并归纳了网络攻击的通用框架。在2020年初步建设智能电网背景下,考虑到中国电网的信息安全系统也面临严峻的威胁和挑战,提出了包括从信息化战争视角提高对网络安全的思想重视水平、重审物理隔离、协同平衡系统安全与信息开放的几点思考,以及开展有效的安全演习、推进核心设备国产化等关于构建坚强的信息安全防御体系的几点建议。

关键词: 电网, 电力系统安全, 大停电事故, 网络攻击, 信息能源系统, 安全防御体系, 黑色能量, 智能电网

Abstract: On December 23, 2015 and December 16, 2016, the Ukrainian power grid suffered twice serious power outages originated from the malicious code. The first outage was considered as the first public cyber-attack against grid infrastructures in the world. The blackout process, techniques and effects of the 2015 cyber-attack accident are reproduced in the paper, and a general attack framework is then summarized. Considering the critical threats and challenges faced by the cyber information system of China power grid, this paper proposes some ponders and suggestions based on the overall objective of the preliminary construction of Chinese Smart Grid in 2020. The ponders include raising the attention level of cyber security from information war aspect, reassessing the physical isolation method and coordinating cyber security with information open. The suggestions on construction of a strong cyber information security defense system include conducting effective security exercises, promoting localization of core equipment system and others.

Key words: power grid, power system security, blackout, cyber attack, information system, defense hierarchy, black energy, smart grid

中图分类号: