• DocumentCode
    2588304
  • Title

    Generating configuration for missing traffic detector and security measures in industrial control systems based on the system description files

  • Author

    Hadeli, Hadeli ; Schierholz, Ragnar ; Braendle, Markus ; Tuduce, Cristian

  • Author_Institution
    Ind. Software Syst. Program, ABB Switzerland Ltd., Baden, Switzerland
  • fYear
    2009
  • fDate
    11-12 May 2009
  • Firstpage
    503
  • Lastpage
    510
  • Abstract
    Nowadays, industrial control systems operators are trying to fulfill requirements from upcoming standards and regulation regarding cyber security issues. However, addressing such security requirements by implementing security measures is not a trivial task. Moreover, the creation and maintenance of the configuration for the security measures is prone to error. This research shows that it is possible to derive configuration file(s) to setup different security measures based on the input from system description files. In addition, we highlight an important anomaly in industrial control systems, namely the missing/tardiness of expected traffic. In this paper, we show how the proposed system works by taking IEC 61850 SCD files and generating configuration files for security measures such as firewall and IDS/IPS. Additionally, current IDS/IPS only raise an alert when unexpected traffic appears in the system. They do not alert on the disappearance of the expected traffic. In fact, this type of anomaly is as critical as the other type of anomaly. Thus, we address this anomaly as well in our research.
  • Keywords
    industrial control; telecommunication security; telecommunication traffic; IDS-IPS; IEC 61850 SCD file; anomaly detection; cyber security issue; industrial control system; missing traffic detector; system description file; Communication system security; Computer industry; Data security; Detectors; IEC standards; Industrial control; Information security; Intrusion detection; Prototypes; Traffic control; control systems; intrusion detection; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Technologies for Homeland Security, 2009. HST '09. IEEE Conference on
  • Conference_Location
    Boston, MA
  • Print_ISBN
    978-1-4244-4178-5
  • Type

    conf

  • DOI
    10.1109/THS.2009.5168079
  • Filename
    5168079