arrow
Return

Critical State-Based Filtering System for Securing SCADA Network Protocols

delete2012-10-01
delete78
PRE
AI
I
Igor Nai Fovino *
A
Alessio Coletta
M
Marcelo Masera
DOI:10.1109/TIE.2011.2181132delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The security of System Control and Data Acquisition (SCADA) systems is one of the most pressing subjects in industrial systems, particularly for those installations actively using the public network in order to provide new features and services. In this paper, we present an innovative approach to the design of filtering systems based on the state analysis of the system being monitored. The aim is to detect attacks composed of a set of SCADA commands that, while licit when considered in isolation on a single-packet basis, can disrupt the correct behavior of the system when executed in particular operating states. The proposed firewall detects these complex attacks thanks to an internal representation of the controlled SCADA system. Furthermore, we detail the design of the architecture of the firewall for systems that use the ModBus and DNP3 protocols, and the implementation of a prototype, providing experimental comparative results that confirm the validity of the proposed approach.
Keywords:
Critical state analysis
cyber security
firewall
SCADA systems
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Industrial Electronics cover
IEEE Transactions on Industrial Electronics
IF:
7.2
Papers:
1.8W
Citations:
9.8W

Organization

U
University of Insubria
Scholars:
6.8K
Papers: 6.0K
Citations: 6.5K
E
European Commission Joint Research Centre
Scholars:
6.7K
Papers: 5.9K
Citations: 8