DocumentCode
2588304
Title
Generating configuration for missing traffic detector and security measures in industrial control systems based on the system description files
Author
Hadeli, Hadeli ; Schierholz, Ragnar ; Braendle, Markus ; Tuduce, Cristian
Author_Institution
Ind. Software Syst. Program, ABB Switzerland Ltd., Baden, Switzerland
fYear
2009
fDate
11-12 May 2009
Firstpage
503
Lastpage
510
Abstract
Nowadays, industrial control systems operators are trying to fulfill requirements from upcoming standards and regulation regarding cyber security issues. However, addressing such security requirements by implementing security measures is not a trivial task. Moreover, the creation and maintenance of the configuration for the security measures is prone to error. This research shows that it is possible to derive configuration file(s) to setup different security measures based on the input from system description files. In addition, we highlight an important anomaly in industrial control systems, namely the missing/tardiness of expected traffic. In this paper, we show how the proposed system works by taking IEC 61850 SCD files and generating configuration files for security measures such as firewall and IDS/IPS. Additionally, current IDS/IPS only raise an alert when unexpected traffic appears in the system. They do not alert on the disappearance of the expected traffic. In fact, this type of anomaly is as critical as the other type of anomaly. Thus, we address this anomaly as well in our research.
Keywords
industrial control; telecommunication security; telecommunication traffic; IDS-IPS; IEC 61850 SCD file; anomaly detection; cyber security issue; industrial control system; missing traffic detector; system description file; Communication system security; Computer industry; Data security; Detectors; IEC standards; Industrial control; Information security; Intrusion detection; Prototypes; Traffic control; control systems; intrusion detection; security;
fLanguage
English
Publisher
ieee
Conference_Titel
Technologies for Homeland Security, 2009. HST '09. IEEE Conference on
Conference_Location
Boston, MA
Print_ISBN
978-1-4244-4178-5
Type
conf
DOI
10.1109/THS.2009.5168079
Filename
5168079
Link To Document