DocumentCode :
3035502
Title :
Virtual Private Groups for Protecting Critical Infrastructure Networks
Author :
O´Brien, Richard C., Jr. ; Payne, Charles N.
Author_Institution :
Adventium Labs. LLC, Minneapolis, MN
fYear :
2009
fDate :
3-4 March 2009
Firstpage :
118
Lastpage :
123
Abstract :
In an era when critical infrastructure networks are increasingly less isolated and more accessible from open networks, including the Internet, the air-gap security that these critical networks once enjoyed no longer exists. Malicious individuals can exploit this network connectivity, in conjunction with security weaknesses in widely used, homogeneous, COTS (commercial off-the-shelf) products, to penetrate deep within an organization´s critical networks. Such an attack on SCADA (Supervisory Control And Data Acquisition) and Process Control networks could have devastating consequences. This paper describes an approach, Virtual Private Groups (VPGs), for creating and managing a virtual air-gap between these networks and the environments in which they may operate. After a brief description of the security issues that confront these networks, we describe our approach for addressing them. Many of the ideas presented here are the result of work done while implementing a version of VPGs directed towards critical infrastructure networks. In the process of doing that work we made a number of advances in managing policy for VPG and related mechanisms.
Keywords :
Internet; local area networks; security of data; telecommunication security; virtual private networks; critical infrastructure network protection; security; virtual air-gap; virtual private groups; Air gaps; Authentication; Communication system traffic control; Cryptography; Data security; Distributed control; IP networks; Peer to peer computing; Process control; Protection; Critical Infrastructure Protection; Security and Trustworthiness; Security of Operational Systems;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Conference For Homeland Security, 2009. CATCH '09. Cybersecurity Applications & Technology
Conference_Location :
Washington, DC
Print_ISBN :
978-0-7695-3568-5
Type :
conf
DOI :
10.1109/CATCH.2009.14
Filename :
4804433
Link To Document :
بازگشت