Improving Network Security Monitoring for Industrial Control Systems

被引:0
|
作者
Cruz, Tiago [1 ]
Barrigas, Jorge [1 ]
Proenca, Jorge [1 ]
Graziano, Antonio [2 ]
Panzieri, Stefano [3 ]
Lev, Leonid [4 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, CISUC, DEI, Coimbra, Portugal
[2] Selex ES, Rome, Italy
[3] Univ Rome Tre, Dip Informat & Automaz, Rome, Italy
[4] Israel Elect Corp Ltd, Haifa, Israel
来源
PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM) | 2015年
关键词
Industrial Control Systems; Critical Infrastructure Protection; SCADA; Programmable Logic Controllers;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Programmable Logic Controller (PLC) technology plays an important role in the automation architectures of several critical infrastructures such as Industrial Control Systems (ICS), controlling equipment in contexts such as chemical processes, factory lines, power production plants or power distribution grids, just to mention a few examples. Despite their importance, PLCs constitute one of the weakest links in ICS security, frequently due to reasons such as the absence of secure communication mechanisms, authenticated access or system integrity checks. While events such as the Stuxnet worm have raised awareness for this problem, industry has slowly reacted, either due to reliability or cost concerns. This paper introduces the Shadow Security Unit, a low-cost device deployed in parallel with a PLC or Remote Terminal Unit (RTU), being capable of transparently intercepting its communications control channels and physical process I/O lines to continuously assess its security and operational status. The proposed device does not require significant changes to the existing control network, being able to work in standalone or integrated within an ICS protection framework.
引用
收藏
页码:878 / 881
页数:4
相关论文
共 50 条
  • [31] Tracing security requirements in industrial control systems using graph databases
    Awais Tanveer
    Chandan Sharma
    Roopak Sinha
    Matthew M. Y. Kuo
    Software and Systems Modeling, 2023, 22 : 851 - 870
  • [32] A logic-based framework for the security analysis of Industrial Control Systems
    Lemaire L.
    Vossaert J.
    Jansen J.
    Naessens V.
    Automatic Control and Computer Sciences, 2017, 51 (2) : 114 - 123
  • [33] Impact of Network Infrastructure Parameters to the Effectiveness of Cyber Attacks Against Industrial Control Systems
    Genge, B.
    Siaterlis, C.
    Hohenadel, M.
    INTERNATIONAL JOURNAL OF COMPUTERS COMMUNICATIONS & CONTROL, 2012, 7 (04) : 674 - 687
  • [34] A Spiking One-Class Anomaly Detection Framework for Cyber-Security on Industrial Control Systems
    Demertzis, Konstantinos
    Iliadis, Lazaros
    Spartalis, Stefanos
    ENGINEERING APPLICATIONS OF NEURAL NETWORKS, EANN 2017, 2017, 744 : 122 - 134
  • [35] Empirical Study of PLC Authentication Protocols in Industrial Control Systems
    Ayub, Adeen
    Yoo, Hyunguk
    Ahmed, Irfan
    2021 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2021), 2021, : 383 - 397
  • [36] A survey of network intrusion detection methods for industrial control systems
    Zhang W.-A.
    Hong Z.
    Zhu J.-W.
    Chen B.
    Kongzhi yu Juece/Control and Decision, 2019, 34 (11): : 2277 - 2288
  • [37] Software Defined Networking Opportunities for Intelligent Security Enhancement of Industrial Control Systems
    Sainz, Markel
    Iturbe, Mikel
    Garitano, Inaki
    Zurutuza, Urko
    INTERNATIONAL JOINT CONFERENCE SOCO'17- CISIS'17-ICEUTE'17 PROCEEDINGS, 2018, 649 : 577 - 586
  • [38] Using Datasets from Industrial Control Systems for Cyber Security Research and Education
    Lin, Qin
    Verwer, Sicco
    Kooij, Robert
    Mathur, Aditya
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2019), 2020, 11777 : 122 - 133
  • [39] Dynamic Security Analysis of Embedded Systems' Firmwares (Network and Distributed System Security (NDSS) Symposium). A Forensic I/O Recorder for Industrial Control Systems Using PLCs and OPC UA
    Karagiozidis, Alexios
    Gergeleit, Martin
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [40] HAMIDS: Hierarchical Monitoring Intrusion Detection System for Industrial Control Systems
    Ghaeini, Hamid Reza
    Tippenhauer, Nils Ole
    CPS-SPC'16: PROCEEDINGS OF THE 2ND ACM WORKSHOP ON CYBER-PHYSICAL SYSTEMS SECURITY & PRIVACY, 2016, : 101 - 109