• DocumentCode
    466374
  • Title

    Data Object Based Security for DNP3 Over TCP/IP for Increased Utility Commercial Aspects Security

  • Author

    Mander, Todd ; Nabhani, Farhad ; Wang, Lin ; Cheung, Richard

  • Author_Institution
    Univ. of Teesside, Middlesbrough
  • fYear
    2007
  • fDate
    24-28 June 2007
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Potential effectiveness of cyber-attacks against utility networks using protocol DNP3 would increase rapidly, when DNP3 is employed over TCP/IP, because attacks succeed on the Internet can be used against DNP3. This becomes a critical concern for DNP3 since an outstation may be accessed from multiple masters of external networks. However, commercial Internet security does not provide applicable security since they were not designed specifically for DNP3. This paper proposes a new efficient cyber-security specifically designed for DNP3 at its interface with TCP/IP to augment utility commercial security capability. Rule-based security is implemented for the proposed cyber-security for DNP3 over TCP/IP using the function codes, data objects, and data sets from DNP3 data link layer and application layer. The rule-based security is implemented on a connection basis so that detailed security rules are specifically defined for each connection to the device.
  • Keywords
    Internet; distribution networks; power engineering computing; power system security; telecommunication security; transport protocols; DNP3 application layer; DNP3 data link layer; Internet security; TCP/IP; cyber attacks; data object-based security; distributed network protocol; power system automation; power system communication; power system security; rule-based security; utility computer networks; Communication system security; Computer networks; Computer security; Data communication; Data security; IP networks; Internet; Power system security; TCPIP; Transport protocols; Computer network management; Computer network security; Computer networks; Power system communication; Power system security; Protocols; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Power Engineering Society General Meeting, 2007. IEEE
  • Conference_Location
    Tampa, FL
  • ISSN
    1932-5517
  • Print_ISBN
    1-4244-1296-X
  • Electronic_ISBN
    1932-5517
  • Type

    conf

  • DOI
    10.1109/PES.2007.386243
  • Filename
    4276009