DocumentCode :
1943431
Title :
TCP veto: A novel network attack and its Application to SCADA protocols
Author :
Hagen, J.T. ; Mullins, Barry E.
Author_Institution :
Electr. & Comput. Eng. Dept., Air Force Inst. of Technol., Wright-Patterson AFB, OH, USA
fYear :
2013
fDate :
24-27 Feb. 2013
Firstpage :
1
Lastpage :
6
Abstract :
TCP veto is a detection-resistant variation of the TCP connection hijacking attack. While not limited to SCADA protocols, Modbus TCP, the Ethernet Industrial Protocol (EtherNet/IP), and the Distributed Network Protocol (DNP3) each meet the necessary assumptions of the attack. Experimental results reveal that the integrity of messages transmitted using each of the three SCADA protocols are vulnerable to TCP veto. Additionally, TCP veto produces up to 600 times less network traffic during its attack than connection hijacking. This work underscores the vulnerability of current SCADA protocols that communicate over TCP/IP to network attack. A method to definitively identify TCP veto requires a detection system to perform deep packet inspection on every TCP packet of a monitored connection. Methods for mitigating the attack through message authentication include implementing DNP3 with Secure Authentication, tcpcrypt, or Internet Protocol Security (IPsec).
Keywords :
SCADA systems; computer network security; control engineering computing; local area networks; message authentication; transport protocols; DNP3; Distributed Network Protocol; EtherNet/IP; Ethernet Industrial Protocol; IPsec; Internet Protocol Security; Modbus TCP; SCADA protocol vulnerability; Secure Authentication; TCP connection hijacking attack; TCP packet; TCP veto; TCP/IP; connection monitoring; deep packet inspection; detection-resistant variation; message authentication; message integrity; message transmission; network attack; network traffic; tcpcrypt; Authentication; IP networks; Payloads; Protocols; Servers; Storms; Cyberspace; IP networks; Intrusion detection; Message authentication; Network security; SCADA systems; TCPIP;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Innovative Smart Grid Technologies (ISGT), 2013 IEEE PES
Conference_Location :
Washington, DC
Print_ISBN :
978-1-4673-4894-2
Electronic_ISBN :
978-1-4673-4895-9
Type :
conf
DOI :
10.1109/ISGT.2013.6497785
Filename :
6497785
Link To Document :
بازگشت