• DocumentCode
    717115
  • Title

    Improving network security monitoring for industrial control systems

  • Author

    Cruz, Tiago ; Barrigas, Jorge ; Proenca, Jorge ; Graziano, Antonio ; Panzieri, Stefano ; Lev, Leonid ; Simoes, Paulo

  • Author_Institution
    DEI-CISUC, Univ. of Coimbra, Coimbra, Portugal
  • fYear
    2015
  • fDate
    11-15 May 2015
  • Firstpage
    878
  • Lastpage
    881
  • Abstract
    Programmable Logic Controller (PLC) technology plays an important role in the automation architectures of several critical infrastructures such as Industrial Control Systems (ICS), controlling equipment in contexts such as chemical processes, factory lines, power production plants or power distribution grids, just to mention a few examples. Despite their importance, PLCs constitute one of the weakest links in ICS security, frequently due to reasons such as the absence of secure communication mechanisms, authenticated access or system integrity checks. While events such as the Stuxnet worm have raised awareness for this problem, industry has slowly reacted, either due to reliability or cost concerns. This paper introduces the Shadow Security Unit, a low-cost device deployed in parallel with a PLC or Remote Terminal Unit (RTU), being capable of transparently intercepting its communications control channels and physical process I/O lines to continuously assess its security and operational status. The proposed device does not require significant changes to the existing control network, being able to work in standalone or integrated within an ICS protection framework.
  • Keywords
    computer network reliability; computer network security; industrial control; invasive software; programmable controllers; telecommunication channels; ICS protection framework; ICS security; PLC technology; RTU; Stuxnet worm; authenticated access; automation architecture; chemical process; communications control channels; factory line; industrial control system; network security monitoring; power distribution grid; power production plant; programmable logic controller technology; remote terminal unit; secure communication mechanism; shadow security unit; system integrity check; Correlation; Monitoring; Process control; Protocols; Real-time systems; SCADA systems; Security; Critical Infrastructure Protection; Industrial Control Systems; Programmable Logic Controllers; SCADA;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management (IM), 2015 IFIP/IEEE International Symposium on
  • Conference_Location
    Ottawa, ON
  • Type

    conf

  • DOI
    10.1109/INM.2015.7140399
  • Filename
    7140399