• DocumentCode
    2267495
  • Title

    System configuration check against security policies in industrial networks

  • Author

    Cheminod, Manuel ; Durante, Luca ; Valenzano, Adriano

  • Author_Institution
    IEIIT, Turin, Italy
  • fYear
    2012
  • fDate
    20-22 June 2012
  • Firstpage
    247
  • Lastpage
    265
  • Abstract
    Awareness that networked embedded systems are vulnerable to cyber-threats has been constantly raising since some years ago. In the industrial arena recent severe attacks, such as the popular case of the Stuxnet worm, have completely debunked the myth of security of embedded devices based on their isolation. Indeed, the ever increasing dependence of many industrial systems on digital communication networks is causing the cyber-security requirements to become a priority in their planning, design, deployment and management. This paper deals with our experience in checking the conformance of a distributed industrial automation system, which includes several types of embedded devices, with respect to a set of security policies defined at the global system level. In particular, the focus of the paper is on the use of modeling techniques and semi-automated s/w tools to verify the configuration of devices and services with attention to the correct use of their security capabilities to support the desired set of policies.
  • Keywords
    computer network management; computer network security; digital communication; embedded systems; production engineering computing; Stuxnet worm; awareness; cyber-security requirement; cyber-threat vulnerability; device configuration; digital communication network; distributed industrial automation system; embedded device security; industrial network; industrial system; networked embedded system; security capability; security policy; service configuration; system configuration check; Access control; Actuators; Embedded systems; IP networks; Protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Industrial Embedded Systems (SIES), 2012 7th IEEE International Symposium on
  • Conference_Location
    Karlsruhe
  • Print_ISBN
    978-1-4673-2685-8
  • Electronic_ISBN
    978-1-4673-2683-4
  • Type

    conf

  • DOI
    10.1109/SIES.2012.6356591
  • Filename
    6356591