Smart I/O Modules for Mitigating Cyber-Physical Attacks on Industrial Control Systems

被引:36
作者
Pearce, Hammond [1 ]
Pinisetty, Srinivas [2 ]
Roop, Partha S. [1 ]
Kuo, Matthew M. Y. [4 ]
Ukil, Abhisek [3 ]
机构
[1] Univ Auckland, Dept Elect Comp & Software Engn, Auckland 1010, New Zealand
[2] Indian Inst Technol Bhubaneswar, Bhubaneswar 752050, Odisha, India
[3] Univ Auckland, Dept Elect & Comp Syst Engn, Auckland 1010, New Zealand
[4] Auckland Univ Technol, Sch Engn Comp & Math Sci, Auckland 1010, New Zealand
关键词
Runtime; Security; Hardware; Monitoring; Control systems; Safety; Industries; Cyber-physical attacks; cyber-physical systems (CPSs); industrial control systems; security; runtime enforcement;
D O I
10.1109/TII.2019.2945520
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-physical systems (CPSs) are implemented in many industrial and embedded control applications. Where these systems are safety-critical, correct and safe behavior is of paramount importance. Malicious attacks on such CPSs can have far-reaching repercussions. For instance, if elements of a power grid behave erratically, physical damage and loss of life could occur. Currently, there is a trend toward increased complexity and connectivity of CPS. However, as this occurs, the potential attack vectors for these systems grow in number, increasing the risk that a given controller might become compromised. In this article, we examine how the dangers of compromised controllers can be mitigated. We propose a novel application of runtime enforcement that can secure the safety of real-world physical systems. Here, we synthesize enforcers to a new hardware architecture within programmable logic controller I/O modules to act as an effective line of defence between the cyber and the physical domains. Our enforcers prevent the physical damage that a compromised control system might be able to perform. To demonstrate the efficacy of our approach, we present several benchmarks, and show that the overhead for each system is extremely minimal.
引用
收藏
页码:4659 / 4669
页数:11
相关论文
共 34 条
  • [1] From Design to Invariants: Detecting Attacks on Cyber Physical Systems
    Adepu, Sridhar
    Mathur, Aditya
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C), 2017, : 533 - 540
  • [2] Argus: An Orthogonal Defense Framework to Protect Public Infrastructure against Cyber-Physical Attacks
    Adepu, Sridhar
    Shrivastava, Siddhant
    Mathur, Aditya
    [J]. IEEE INTERNET COMPUTING, 2016, 20 (05) : 38 - 45
  • [3] [Anonymous], 2014, IND CONTROL SYST
  • [4] [Anonymous], [No title captured]
  • [5] [Anonymous], 60255 IEC
  • [6] [Anonymous], [No title captured]
  • [7] [Anonymous], [No title captured]
  • [8] [Anonymous], 2005, Int. J. Inf. Secur., DOI DOI 10.1007/S10207-004-0046-8
  • [9] The synchronous languages 12 years later
    Benveniste, A
    Caspi, P
    Edwards, SA
    Halbwachs, N
    Le Guernic, P
    De Simone, R
    [J]. PROCEEDINGS OF THE IEEE, 2003, 91 (01) : 64 - 83
  • [10] Bloem Roderick, 2015, Tools and Algorithms for the Construction and Analysis of Systems. 21st International Conference, TACAS 2015, held as part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2015. Proceedings: LNCS 9035, P533, DOI 10.1007/978-3-662-46681-0_51