Critical State-Based Filtering System for Securing SCADA Network Protocols

被引:71
作者
Fovino, Igor Nai [1 ,4 ]
Coletta, Alessio [1 ,4 ]
Carcano, Andrea [2 ,4 ]
Masera, Marcelo [3 ,4 ]
机构
[1] Global Cyber Secur Ctr, I-00144 Rome, Italy
[2] Univ Insubria, I-21100 Varese, Italy
[3] European Commiss, Inst Energy, Brussels, Belgium
[4] Commiss European Communities, Joint Res Ctr, B-1049 Brussels, Belgium
关键词
Critical state analysis; cyber security; firewall; SCADA systems; BUILDING AUTOMATION; FAULT-DETECTION;
D O I
10.1109/TIE.2011.2181132
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security of System Control and Data Acquisition (SCADA) systems is one of the most pressing subjects in industrial systems, particularly for those installations actively using the public network in order to provide new features and services. In this paper, we present an innovative approach to the design of filtering systems based on the state analysis of the system being monitored. The aim is to detect attacks composed of a set of "SCADA" commands that, while licit when considered in isolation on a single-packet basis, can disrupt the correct behavior of the system when executed in particular operating states. The proposed firewall detects these complex attacks thanks to an internal representation of the controlled SCADA system. Furthermore, we detail the design of the architecture of the firewall for systems that use the ModBus and DNP3 protocols, and the implementation of a prototype, providing experimental comparative results that confirm the validity of the proposed approach.
引用
收藏
页码:3943 / 3950
页数:8
相关论文
共 27 条
[1]  
Carcano A., 2008, P 3 INT WORKSH CRIT
[2]  
Chandia R., 2007, P 1 INT C CRIT INFR
[3]   Be secure [J].
Creery, Adam A. ;
Byres, E. J. .
IEEE INDUSTRY APPLICATIONS MAGAZINE, 2007, 13 (04) :49-55
[4]  
Cuppens F, 2002, P IEEE S SECUR PRIV, P202, DOI 10.1109/SECPRI.2002.1004372
[5]   Effects of intentional threats to power substation control systems [J].
Dondossola, Giovanna ;
Szanto, Judit ;
Masera, Marcelo ;
Fovino, Igor Nai .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2008, 4 (1-2) :129-143
[6]  
Fovino I.N., 2008, P 2 INT C CRIT INFR
[7]  
Fovino I. Nai, 2007, P 1 ANN IFIP WORK GR, P367
[8]   Emergent disservices in interdependent systems and system-of-systems [J].
Fovino, Igor Nai ;
Masera, Marcelo .
2006 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS, VOLS 1-6, PROCEEDINGS, 2006, :590-+
[9]  
Frank P M., 1987, Triennial World Congress of the International Federation of Automatic Control, V3, P63, DOI DOI 10.1016/S1474-6670(17)55353-7
[10]   Security in Building Automation Systems [J].
Granzer, Wolfgang ;
Praus, Fritz ;
Kastner, Wolfgang .
IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2010, 57 (11) :3622-3630