Security Challenges in Control Network Protocols: A Survey

被引:66
作者
Volkova, Anna [1 ]
Niedermeier, Michael [1 ]
Basmadjian, Robert [1 ]
de Meer, Hermann [1 ]
机构
[1] Univ Passau, Dept Comp Sci & Math, Comp Networking Lab, D-94032 Passau, Germany
关键词
Control systems; network protocols; network security; INTRUSION DETECTION; SYSTEM; ATTACKS; DESIGN;
D O I
10.1109/COMST.2018.2872114
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the ongoing adoption of remotely communicating and interacting control systems harbored by critical infrastructures, the potential attack surface of such systems also increases drastically. Therefore, not only the need for standardized and manufacturer-agnostic control system communication protocols has grown, but also the requirement to protect those control systems' communication. There have already been numerous security analyses of different control system communication protocols; yet, these have not been combined with each other sufficiently, mainly due to three reasons: First, the life cycles of such protocols are usually much longer than those of other Internet and communication technologies, therefore legacy protocols are often not considered in current security analyses. Second, the usage of certain control system communication protocols is usually restricted to a particular infrastructure domain, which leads to an isolated view on them. Third, with the accelerating pace at which both control system communication protocols and threats against them develop, existing surveys are aging at an increased rate, making their re-investigation a necessity. In this paper, a comprehensive survey on the security of the most important control system communication protocols, namely Modbus, OPC UA, TASE.2, DNP3, IEC 60870-5-101, IEC 60870-5-104, and IEC 61850 is performed. To achieve comparability, a common test methodology based on attacks exploiting well-known control system protocol vulnerabilities is created for all protocols. In addition, the effectiveness of the related security standard IEC 62351 is analyzed by a pre- and post-IEC 62351 comparison.
引用
收藏
页码:619 / 639
页数:21
相关论文
共 74 条
[1]   Proposal of a Secure Modbus RTU Communication with Adi Shamir's Secret Sharing Method [J].
Adamko, Eva ;
Jakaboczki, Gabor ;
Szemes, Peter Tamas .
INTERNATIONAL JOURNAL OF ELECTRONICS AND TELECOMMUNICATIONS, 2018, 64 (02) :107-114
[2]   Securing DNP3 Broadcast Communications in SCADA Systems [J].
Amoah, Raphael ;
Camtepe, Seyit ;
Foo, Ernest .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2016, 12 (04) :1474-1485
[3]  
[Anonymous], 2014, INNOVATIVE SMART GRI
[4]  
[Anonymous], WSEAS T SYST CONTROL
[5]  
[Anonymous], SAND20013252 SAND NA
[6]  
[Anonymous], TRISRL0401 U LOUISV
[7]  
[Anonymous], TP0616344ENN EUR AG
[8]  
[Anonymous], 2016, P 3 BUILDING SIMULAT
[9]  
[Anonymous], TC57WG15 IEC
[10]  
[Anonymous], PUBLIC KEY CRYPTOGRA