Thread Content
With the development of automation and information technology, DCS systems are currently usually connected to PHD data acquisition systems, which poses a risk of external viruses invading the system. Let’s discuss how to configure the network between the DCS and PHD systems in order to prevent such virus intrusions.
Ensure one-way transmission of underlying data, with the use of gateways and firewalls.
Neither the management network nor the control network is connected to the external network; it only needs to be connected to external magnetic media devices. Even with a firewall in place, it’s of no use if it isn’t updated regularly.
Physically separated, dual network cards. However, no terminal shall use mobile storage devices or be connected to the external network.
Add application servers; through the third network card of these servers, insert a firewall in between and connect it to PHD.
This post was last edited by Hardmen on 2010-6-9 at 15:28. The common approach is to install a firewall and then strengthen application management. I would like to put forward a suggestion here; let’s see if it’s feasible. Anyway, as I said, our managers didn’t pay any attention to me; haha. Since we often need to copy data from engineer stations or servers, this increases the risk of virus infections. Therefore, I suggest adding a computer dedicated to scanning removable storage devices; use legitimate Kaspersky antivirus software, and update the virus database weekly via the wireless network card. The cost isn’t high, right? .
DCS is strictly separated from the management network. Grant read-only permissions for OPC data collection to the management network.
O(∩_∩)O Haha~ Thanks; using burning is also a method. Assuming the server is clean, you can distribute data from it in the form of burned discs, but what if you want to copy something to the server? Can it be guaranteed at this point that your CD is virus-free? Isn’t antivirus software still needed, right? Thank you again
The simplest way is to have the OPC server exist as a separate node in your system; it remains transparent to you, and usually there are no operations that you can perform on it Of course, if you decide to get entangled with engineers, then sorry – prepare to face disaster!