论文标题
软件启用了用于抵消控制系统中攻击的安全体系结构
Software Enabled Security Architecture for Counteracting Attacks in Control Systems
论文作者
论文摘要
越来越多的工业控制系统(IC)系统正在连接到互联网,以最大程度地降低运营成本并提供额外的灵活性。这些控制系统(例如电网,制造业和公用事业中使用的系统)连续运行,并且具有数十年来的寿命长,而不是像IT系统一样。这样的工业控制系统需要不间断且安全的操作。但是,它们可能容易受到各种攻击,因为对关键控制基础设施的成功攻击可能会对人类生命的安全以及一个国家的安全和繁荣产生毁灭性的后果。此外,可能会有一系列可以针对IC的攻击,并且不容易保护这些系统免受所有已知攻击,更不用的攻击了。在本文中,我们建议使用软件定义的网络(SDN)和网络功能虚拟化(NFV)提出一个启用软件的安全体系结构,以增强确保工业控制系统的能力。我们已经设计了SDN/NFV启用安全架构,并在SDN控制器中开发了控制系统安全应用程序(CSSA),以增强IC的安全性,以防止某些特定的攻击,即拒绝服务攻击,从未捕获的易受伤害的控制系统组件中,并从没有支持任何安全功能的传统设备中获得通信流。在本文中,我们讨论了所提出的体系结构的原型实施以及从我们的分析中获得的结果。
Increasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of IT systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation's security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) that can enhance the capability to secure industrial control systems. We have designed such an SDN/NFV enabled security architecture and developed a Control System Security Application (CSSA) in SDN Controller for enhancing security in ICS against certain specific attacks namely denial of service attacks, from unpatched vulnerable control system components and securing the communication flows from the legacy devices that do not support any security functionality. In this paper, we discuss the prototype implementation of the proposed architecture and the results obtained from our analysis.