Title :
Securing modbus transactions using hash-based message authentication codes and stream transmission control protocol
Author :
Hayes, G. ; El-Khatib, Khalil
Author_Institution :
Univ. of Ontario Inst. of Technol., Oshawa, ON, Canada
Abstract :
Traditionally supervisory control and data acquisition (SCADA) networks were physically isolated, providing some inherent level of security; yet, as these networks slowly converged with both corporate intranets and the Internet, their security continually eroded. The gradual evolution of SCADA systems has introduced many novel and previously unknown security risks. During the advent of SCADA technologies, a heavy focus was put on providing system robustness, safety, and reliability. Because of this, widely deployed SCADA protocols like Modbus and DNP3 provide no inherent security controls. In this paper, we will propose a novel Modbus alternative capable of providing secure, backward-compatible Modbus message transmission using stream control transmission protocol and hash-based message authentication code technologies. This proposed protocol improvement ensures the availability and integrity of Modbus messages while providing a robust and secure mutual authentication mechanism. Improvements upon the legacy Modbus protocol aim to mitigate common SCADA protocol attack vectors.
Keywords :
Internet; SCADA systems; computer network security; cryptographic protocols; intranets; message authentication; DNP3; Internet; Modbus message transmission; Modbus transaction security; SCADA protocol; corporate intranet; hash-based message authentication code; hash-based message authentication code technologies; legacy Modbus protocol; stream control transmission protocol; supervisory control and data acquisition network; Authentication; Availability; Computer crime; Protocols; Robustness; SCADA systems; Cryptography; Hash-Based Authentication Code; Industrial Control Security; Industrial Networks; Modbus; Network Security; Stream Transmission Control Protocol;
Conference_Titel :
Communications and Information Technology (ICCIT), 2013 Third International Conference on
Conference_Location :
Beirut
Print_ISBN :
978-1-4673-5306-9
DOI :
10.1109/ICCITechnology.2013.6579545