Techniques for Enhancing Security in Industrial Control Systems

Author:

Varadharajan Vijay1ORCID,Tupakula Uday2ORCID,Karmakar Kallol Krishna1ORCID

Affiliation:

1. Advanced Cyber Security Engineering Research Centre, The University of Newcastle, Australia

2. Advanced Cyber Security Engineering Research Centre, The University of Newcastle, Australia and University of New England, Australia

Abstract

Increasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of Information Technology (IT) systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation’s security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) that can enhance the capability to secure industrial control systems. We have designed such an SDN/NFV enabled security architecture and developed a Control System Security Application (CSSA) in SDN Controller for enhancing security in ICS by achieving real time situational awareness and dynamic policy-driven decision making across the network infrastructure. In particular, CSSA can be used for establishing secure path for end-to-end communication between devices and also deal against certain specific attacks namely denial of service attacks, from unpatched vulnerable control system components and securing the communication flows from the legacy devices that do not support any security functionality. We also discuss how CSSA provides reliable paths for safety critical messages in control systems. We discuss the prototype implementation of the proposed architecture and the results obtained from our analysis.

Publisher

Association for Computing Machinery (ACM)

Subject

Artificial Intelligence,Control and Optimization,Computer Networks and Communications,Hardware and Architecture,Human-Computer Interaction

Reference60 articles.

1. Maxat Akbanov, Vassilios G. Vassilakis, Ioannis D. Moscholios, and Michael D. Logothetis. 2018. Static and dynamic analysis of WannaCry ransomware. In Proc. IEICE Inform. and Commun. Technol. Forum ICTF, Vol. 2018.

2. Digital twin: A comprehensive survey of security threats;Alcaraz Cristina;IEEE Communications Surveys & Tutorials,2022

3. Policy enforcement system for secure interoperable control in distributed smart grid systems;Alcaraz Cristina;Journal of Network and Computer Applications,2016

4. Journal of Information Security and Applications 2020 52 Measuring cyber-physical security in industrial control systems via minimum-effort attack strategies

5. Assessing lightweight virtualization for security-as-a-service at the network edge;Boudi Abderrahmane;IEICE Transactions on Communications,2019

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3