DocumentCode :
2267495
Title :
System configuration check against security policies in industrial networks
Author :
Cheminod, Manuel ; Durante, Luca ; Valenzano, Adriano
Author_Institution :
IEIIT, Turin, Italy
fYear :
2012
fDate :
20-22 June 2012
Firstpage :
247
Lastpage :
265
Abstract :
Awareness that networked embedded systems are vulnerable to cyber-threats has been constantly raising since some years ago. In the industrial arena recent severe attacks, such as the popular case of the Stuxnet worm, have completely debunked the myth of security of embedded devices based on their isolation. Indeed, the ever increasing dependence of many industrial systems on digital communication networks is causing the cyber-security requirements to become a priority in their planning, design, deployment and management. This paper deals with our experience in checking the conformance of a distributed industrial automation system, which includes several types of embedded devices, with respect to a set of security policies defined at the global system level. In particular, the focus of the paper is on the use of modeling techniques and semi-automated s/w tools to verify the configuration of devices and services with attention to the correct use of their security capabilities to support the desired set of policies.
Keywords :
computer network management; computer network security; digital communication; embedded systems; production engineering computing; Stuxnet worm; awareness; cyber-security requirement; cyber-threat vulnerability; device configuration; digital communication network; distributed industrial automation system; embedded device security; industrial network; industrial system; networked embedded system; security capability; security policy; service configuration; system configuration check; Access control; Actuators; Embedded systems; IP networks; Protocols;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Industrial Embedded Systems (SIES), 2012 7th IEEE International Symposium on
Conference_Location :
Karlsruhe
Print_ISBN :
978-1-4673-2685-8
Electronic_ISBN :
978-1-4673-2683-4
Type :
conf
DOI :
10.1109/SIES.2012.6356591
Filename :
6356591
Link To Document :
بازگشت