SCADA (Supervisory Control and Data Acquisition) systems: Vulnerability assessment and security recommendations

被引:110
作者
Upadhyay, Darshana [1 ]
Sampalli, Srinivas [1 ]
机构
[1] Dalhousie Univ, Fac Comp Sci, Halifax, NS B3H 1W5, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
SCADA vulnerability; Firewalls; Critical infrastructure; Security mitigations; SCADA incidents; CYBER SECURITY; INTERNET;
D O I
10.1016/j.cose.2019.101666
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Growing dependency and remote accessibility of automated industrial automation systems have transformed SCADA (Supervisory Control and Data Acquisition) networks from strictly isolated to highly interconnected networks. This increase in interconnectivity between systems raises operational efficiency due to the ease of controlling and monitoring of processes, however, this inevitable transformation also exposes the control system to the outside world. As a result, effective security strategies are required as any vulnerability of the SCADA system could generate severe financial and/or safety implications. The primary task when identifying holes in the system is to have proper awareness of the SCADA vulnerabilities and threats. This approach will help to identify potential breaches or aspects in the system where a breach may occur. This paper describes various types of potential SCADA vulnerabilities by taking real incidents reported in standard vulnerability databases. A comprehensive review of each type of vulnerability has been discussed along with recommendations for the improvement of SCADA security systems. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:18
相关论文
共 86 条
[1]   OpenPLC: An IEC 61,131-3 compliant open source industrial controller for cyber security research [J].
Alves, Thiago ;
Morris, Thomas .
COMPUTERS & SECURITY, 2018, 78 :364-379
[2]   Embedding Encryption and Machine Learning Intrusion Prevention Systems on Programmable Logic Controllers [J].
Alves, Thiago ;
Das, Rishabh ;
Morris, Thomas .
IEEE EMBEDDED SYSTEMS LETTERS, 2018, 10 (03) :99-102
[3]  
American Petroleum Institute (API), 2003, SEC VULN ASS METH PE
[4]  
[Anonymous], 1164 API
[5]  
[Anonymous], 12 AGA
[6]  
[Anonymous], NIST SPECIAL PUBLICA
[7]  
[Anonymous], DEP HOM SEC CYB SEC
[8]  
[Anonymous], 2005, FIR DEPL SCAD PROC C
[9]  
[Anonymous], ICS CERT ANN VULN CO
[10]  
[Anonymous], AGA 12 2