Title :
Improving network security monitoring for industrial control systems
Author :
Cruz, Tiago ; Barrigas, Jorge ; Proenca, Jorge ; Graziano, Antonio ; Panzieri, Stefano ; Lev, Leonid ; Simoes, Paulo
Author_Institution :
DEI-CISUC, Univ. of Coimbra, Coimbra, Portugal
Abstract :
Programmable Logic Controller (PLC) technology plays an important role in the automation architectures of several critical infrastructures such as Industrial Control Systems (ICS), controlling equipment in contexts such as chemical processes, factory lines, power production plants or power distribution grids, just to mention a few examples. Despite their importance, PLCs constitute one of the weakest links in ICS security, frequently due to reasons such as the absence of secure communication mechanisms, authenticated access or system integrity checks. While events such as the Stuxnet worm have raised awareness for this problem, industry has slowly reacted, either due to reliability or cost concerns. This paper introduces the Shadow Security Unit, a low-cost device deployed in parallel with a PLC or Remote Terminal Unit (RTU), being capable of transparently intercepting its communications control channels and physical process I/O lines to continuously assess its security and operational status. The proposed device does not require significant changes to the existing control network, being able to work in standalone or integrated within an ICS protection framework.
Keywords :
computer network reliability; computer network security; industrial control; invasive software; programmable controllers; telecommunication channels; ICS protection framework; ICS security; PLC technology; RTU; Stuxnet worm; authenticated access; automation architecture; chemical process; communications control channels; factory line; industrial control system; network security monitoring; power distribution grid; power production plant; programmable logic controller technology; remote terminal unit; secure communication mechanism; shadow security unit; system integrity check; Correlation; Monitoring; Process control; Protocols; Real-time systems; SCADA systems; Security; Critical Infrastructure Protection; Industrial Control Systems; Programmable Logic Controllers; SCADA;
Conference_Titel :
Integrated Network Management (IM), 2015 IFIP/IEEE International Symposium on
Conference_Location :
Ottawa, ON
DOI :
10.1109/INM.2015.7140399