Software Enabled Security Architecture for Counteracting Attacks in Control Systems

06/27/2020
by   Uday Tupakula, et al.
0

Increasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of IT systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation's security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) that can enhance the capability to secure industrial control systems. We have designed such an SDN/NFV enabled security architecture and developed a Control System Security Application (CSSA) in SDN Controller for enhancing security in ICS against certain specific attacks namely denial of service attacks, from unpatched vulnerable control system components and securing the communication flows from the legacy devices that do not support any security functionality. In this paper, we discuss the prototype implementation of the proposed architecture and the results obtained from our analysis.

READ FULL TEXT

page 1

page 2

page 6

research
10/22/2020

Strengthening SDN Security: Protocol Dialecting and Downgrade Attacks

Software-defined networking (SDN) has become a fundamental technology fo...
research
06/27/2020

Software Enabled Security Architecture and Mechanisms for Securing 5G Network Services

The 5G network systems are evolving and have complex network infrastruct...
research
02/07/2019

VirtuWind - An SDN- and NFV-based Architecture for Softwarized Industrial Networks

VirtuWind proposes the application of Software Defined Networking (SDN) ...
research
11/14/2019

Detecting Safety and Security Faults in PLC Systems with Data Provenance

Programmable Logic Controllers are an integral component for managing ma...
research
10/26/2020

Easing the Conscience with OPC UA: An Internet-Wide Study on Insecure Deployments

Due to increasing digitalization, formerly isolated industrial networks,...
research
01/06/2021

Designing Actively Secure, Highly Available Industrial Automation Applications

Programmable Logic Controllers (PLCs) execute critical control software ...
research
04/24/2019

Security Analysis of Near-Field Communication (NFC) Payments

Near-Field Communication (NFC) is a modern technology for short range co...

Please sign up or login with your details

Forgot password? Click here to reset