Telecommunication networks based on commonplace technologies (such as Ethernet) often constitute a vulnerable attack vector against modern critical infrastructures (CIs), particularly for supervisory control and data acquisition (SCADA) systems, which rely on them for monitoring and controlling physical components. This paper presents a unique platform that encompasses a range of capabilities, from cyber-attack detection to mitigation strategies, through interdependency and risk evaluation. The platform is made of two main components: a cyber-attack detection subsystem and a risk assessment framework. Both blocks are innovative from research point of view and they have been developed and customized to fit the CIs’ features, that are completely different from telecommunication networks. This platform has been tested on a hybrid environment testbed, made of virtual and real components, within the scope of the EU FP7 CockpitCI and EU H2020 ATENA projects. The case study corresponds to a medium voltage power grid controlled by a SCADA control center, where the platform has been validated with optimal results in terms of detection capabilities and time response.
The cloud computing paradigm is gaining more and more momentum, to the extent that it is no more confined to its initial application domains, i.e. use by enterprises and businesses that are simply willing to lower costs or to increase computing capacity in a flexible manner. In particular, increasing interest is recently being paid to the dramatic potentials that the use of cloud computing technology by critical infrastructure (CI) operators might bring about, in terms of benefits for the society at large. Since accidental or deliberate damage to a CI may result in devastating consequences, this mandates for dependable and trustworthy security mechanisms in cloud platforms. In this paper, we present a distributed application for real-time monitoring of a Power Grid. The application, which is called PoGriMon, is deployed on top of the SecureCloud platform, a security-enhanced IaaS solution that exploits the Intel Software Guard eXtension (SGX) technology. PoGriMon has been designed based on the requirements of the SCADA network of the Israeli Electric Corporation (IEC), and it is currently being validated in a realistic setup also provided by IEC.
As Supervisory Control and Data Acquisition (SCADA) and Industrial and Automation Control System (IACS) architectures became more open and interconnected, some of their remotely controlled processes also became more exposed to cyber threats. Aspects such as the use of mature technologies and legacy equipment or even the unforeseen consequences of bridging IACS with external networks have contributed to this situation. This situation prompted the involvement of governmental, industrial and research organizations, as well as standardization entities, in order to create and promote a series of recommendations and standards for IACS cyber-security. Despite those efforts, which are mostly focused on prevention and mitigation, existing literature still lacks attack descriptions that can be reused to reproduce and further research specific use cases and scenarios of security incidents, useful for improving and developing new security detection strategies. In this paper, we describe the implementation of a set of attacks targeting a SCADA hybrid testbed that reproduces an electrical grid for energy distribution (medium and high voltage). This environment makes use of real SCADA equipment to faithfully reproduce a real operational deployment, providing a better insight into less evident SCADA- and device-specificities.
SCADA protocols for Industrial Control Systems (ICS) are vulnerable to network attacks such as session hijacking. Hence, research focuses on network anomaly detection based on meta--data (message sizes, timing, command sequence), or on the state values of the physical process. In this work we present a class of semantic network-based attacks against SCADA systems that are undetectable by the above mentioned anomaly detection. After hijacking the communication channels between the Human Machine Interface (HMI) and Programmable Logic Controllers (PLCs), our attacks cause the HMI to present a fake view of the industrial process, deceiving the human operator into taking manual actions. Our most advanced attack also manipulates the messages generated by the operator's actions, reversing their semantic meaning while causing the HMI to present a view that is consistent with the attempted human actions. The attacks are totaly stealthy because the message sizes and timing, the command sequences, and the data values of the ICS's state all remain legitimate. We implemented and tested several attack scenarios in the test lab of our local electric company, against a real HMI and real PLCs, separated by a commercial-grade firewall. We developed a real-time security assessment tool, that can simultaneously manipulate the communication to multiple PLCs and cause the HMI to display a coherent system--wide fake view. Our tool is configured with message-manipulating rules written in an ICS Attack Markup Language (IAML) we designed, which may be of independent interest. Our semantic attacks all successfully fooled the operator and brought the system to states of blackout and possible equipment damage.
This paper presents a distributed intrusion detection system (DIDS) for supervisory control and data acquisition (SCADA) industrial control systems, which was developed for the CockpitCI project. Its architecture was designed to address the specific characteristics and requirements for SCADA cybersecurity that cannot be adequately fulfilled by techniques from the information technology world, thus requiring a domain-specific approach. DIDS components are described in terms of their functionality, operation, integration, and management. Moreover, system evaluation and validation are undertaken within an especially designed hybrid testbed emulating the SCADA system for an electrical distribution grid.
Programmable Logic Controller (PLC) technology plays an important role in the automation architectures of several critical infrastructures such as Industrial Control Systems (ICS), controlling equipment in contexts such as chemical processes, factory lines, power production plants or power distribution grids, just to mention a few examples.Despite their importance, PLCs constitute one of the weakest links in ICS security, frequently due to reasons such as the absence of secure communication mechanisms, authenticated access or system integrity checks. While events such as the Stuxnet worm have raised awareness for this problem, industry has slowly reacted, either due to reliability or cost concerns.This paper introduces the Shadow Security Unit, a low-cost device deployed in parallel with a PLC or Remote Terminal Unit (RTU), being capable of transparently intercepting its communications control channels and physical process I/O lines to continuously assess its security and operational status. The proposed device does not require significant changes to the existing control network, being able to work in standalone or integrated within an ICS protection framework.
Home Automation is becoming more and more common in everyday life. In order to permit a remote control of domestic devices a bridge between the Internet network and the Home Network is necessary. This function is commonly operated by the Smart Home gateway which thus results a critical point for the security of the network. Recently several general purpose devices exist that are capable of connecting both to the Home Network and the Internet network, leading to have additional, dynamic and unpredictable, bridges between the two networks. This possibility makes such devices additional attack vectors for the Smart Home. In this work we show the risks resulting from such devices. By using an emulated scenario we also demonstrate the implementation of a real attack exploiting a general purpose device connected to both the Internet and the Home Network. Preliminary experimental results are presented confirming the success of our attack.
In today's light-weight vehicles, the strength of spot welds plays an important role in overall product integrity, reliability and customer satisfaction. Naturally, there is a need for a quick and reliable technique to inspect the quality of the welds. In the past, the primary quality control tests for detecting weld defects are the destructive chisel test and peel test [ 1]. The non-destructive evaluation (NDE) method currently used in industry is based on ultrasonic inspection [2, 3, 4]. The technique is not always successful in evaluating the nugget size, nor is it effective in detecting the so-called "cold" or "stick" welds. Therefore, it is necessary to develop a precise and reliable noncontact NDE method for spot welds.There have been numerous studies in predicting the weld nugget size by considering the spot-weld process [5, 6]. In a forward problem, we are provided with known material model, well-defined boundary conditions, and specific loading conditions - mechanical as well as thermal. For an ill-posed problem [7, 8], some of the known settings may be absent and a set of experimental data is made available for solving the problem. The objective of this study is to investigate the feasibility of an inverse problem technique to determining the weld nugget size using a finite element scheme incorporating experimental measurements on the surface of the weld coupons. In the technique, a mathematical model is formulated to solve the ill-posed inverse problem in which the solution sought is required to satisfy both the experimental measurement and the theoretical foundation of the problem. To demonstrate the efficiency and accuracy of the numerical scheme, several two-dimensional examples are presented. Sensitivity to the solution algorithm from the experimental data is also discussed.
SCADA systems constitute the nervous systems of Power grids. They rely on SCADA communication links which are dependent upon Telco networks and represent one of the major channels of mutual propagation of disturbances and adverse events between Power grids and Telco networks. Power grids and Telco networks have a heavy impact on daily life and are typically referred as Critical Infrastructures (CIs), since their correct operation is essential for the everyday life of our modern society. Dependent (bi) directional relationships and reciprocal influences among CIs are named (inter) dependencies. CIs interdependencies are largely due to increased CI reliance on Information and Communication Technology (ICT). In this paper, we refer to the Fault Isolation and System Reconfiguration (FISR) service of a SCADA system. FISR detects and isolates faults in Power distribution grid and then reconfigures the grid in order to supply again isolated power customers. In delivering FISR service, SCADA system, Telco network and Power grid are interdependent and act as a whole heterogeneous network. Focusing on FISR service, we compute dependability indicators (such as source-destination connectivity and reliability) and performance indicators (such as packet round trip time, node throughput and packet dynamical paths). Both indicators impact FISR response time which in turn impact the QoS to power grid customers.
In this paper, a finite element methodology is given in which finite element models of a three-weld Al-Cu plate is created with support and loading conditions emulating those seen in an optical lab. Harmonic response is sought for the models under the presumption that various defective welds are present. The numerical results are carefully examined to determine the guideline frequency range so the actual optical experiment can be carried out more efficiently.
In the last few years we have witnessed a strong interest in the protection of Critical Infrastructures (CIs) such as power distribution networks, power plants, refineries, water distribution, transportation systems, hospitals and telecommunication networks. Despite their relevance for public safety and security, these infrastructures are highly exposed to a large number of threats, including natural hazards, component failures, criminal actions and terrorism. Several research projects address this topic. Many of them focus on building CI simulators for preventive analysis of system vulnerabilities, while others try to proactively strengthen partial sections of the CIs (such as fault tolerant components or secure control networks). Nevertheless, despite their positive results, those projects seldom provide mechanisms to assess, in real time, the risk level associated with each of the services provided by the addressed CI. Moreover, they do not take into account the high level of interdependency between heterogeneous CIs (power distribution failures, for instance, have a direct impact on telecommunication networks, which also affect other critical infrastructures and so on) or, when they do, they have to make compromises at the level of scalability, performance, or privacy of sensitive information. In this paper we present a CI alerting system that takes a step further, when compared to those approaches, by estimating in real time the risk level associated with each service provided by the CI (i.e. the current likelihood of service degradation or service shutdown induced on a given CI by "undesired" events occurred in that CI and/or in other interdependent CIs).
Indicators of Quality of Service (QoS) of Fault Isolation and System Restoration (FISR) service, delivered by SCADA system are computed, discussed and correlated to quality indicators of power supplied to customers. In delivering FISR service, SCADA system, Telco network and Power grid act as a whole heterogeneous network. While SCADA system and Telco network can be well represented by means of discrete event simulators. To represent a Power grid a continuous simulator is typically required. In the paper, to compute QoS of FISR, SCADA system, Telco network and Power grid have been represented by a unique model by means of a discrete event simulator.
This paper illustrates the activities under development within the FP7 EU MICIE project. The project is devoted to design and implement an on-line alerting system, able to evaluate, in real time, the level of risk of interdependent Critical Infrastructures (CIs). Such a risk is generated by undesired events and by the high level of interconnection of the different infrastructures. Heterogeneous models are under development to perform short term predictions of the Quality of Service (QoS) of each CI according to the QoS of the others, to the level of interdependency among the Infrastructures, and according to the undesired events identified in the reference scenario.
In this demonstration we present the MICIE platform for on-line risk assessment in scenarios with heterogeneous interdependent Critical Infrastructures (CIs) such as power distribution networks, power plants, refineries, water distribution networks, transportation systems and telecommunication networks. These CIs are highly exposed to a large number of threats, including natural hazards, component failures and intentional attacks. Moreover, the increasing interdependence between CIs amplifies the effects of such threats and adds novel challenges to risk assessment tools. In this context, MICIE is the first systematic approach to integrate CI interdependence factors in on-line risk assessment, addressing both the development of on-line risk assessment models and the development of an information sharing platform for continuous exchange of relevant risk information between interdependent CIs.
Well-adhered microcrystalline diamond (MCD) coatings have been deposited on WC-Co substrates by the microwave plasma enhanced chemical vapor deposition (MPECVD) method. A multi-interlayer system Cr/CrN/Cr was deposited on the cemented carbide substrate before diamond deposition to act as a diffusion barrier. The interlayer-coated substrate was shortly peened by friable diamond powders with an average size of 150 mu m to roughen the surface. Diamond coatings deposited on short peened substrates show higher nucleation density and stronger adhesion properties. The X-ray diffraction (XRD) pattern showed that an additional carbide compound layer (Cr3C2 and Cr7C3) was formed during the CVD diamond deposition to work as an intermediate bonding layer for better adhesion. Rockwell indentation tests with a load of 1470 N were conducted to investigate the coating's adhesion. No delamination outside of the indentation zone was observed for the diamond coating deposited on the roughened sample. Electron probe microanalysis (EPMA) results showed that the delamination in the indentation zone occurred mainly at the diamond/Cr interface and very little Co (less than 1 wt.%) was detected on the Cr failure surface. This suggests that during the CVD process Co/C inter-diffusion was successfully prevented by the Cr/CrN/Cr buffer layers. (c) 2006 Elsevier B.V. All rights reserved.
Residual stresses in diamond films grown on WC–Co substrates have been investigated by Raman spectroscopy, x-ray diffraction (XRD), and curvature methods. Microcrystalline diamond films were deposited at 650−700 °C in a conventional hydrogen–methane environment by the microwave plasma-enhanced chemical vapor deposition technique. The film thickness, measured from cross-sectional micrographs taken by scanning electron microscopy, changed from 1.5 to 16.5 μm as the growth time increased from 1 to 12 h. The type and the magnitude of the total residual stress obtained from curvature and XRD measurements agreed very well in all of the samples and changed from tensile to compressive as film thickness increased. However, Raman spectroscopy results showed that all films exhibited compressive stress due to the domain size effect. Different methane fractions, varying from 1% to 3%, have been utilized for diamond growth, and the total residual stress increased as more methane was included.
High quality well-adhered microcrystalline diamond coatings have been produced by the microwave plasma enhanced chemical vapor deposition (MPECVD) technique on cemented carbide substrates. A multi-interlayer system Cr/CrN/Cr was deposited on the WC-Co substrate before diamond deposition to work as a diffusion barrier. The coated substrate was peened with friable diamond powder to roughen the surface resulting in high nucleation density. Adherent diamond film has been successfully deposited on the substrate at temperature around 700°C with 1.0 % CH4 in Hydrogen plasma. The surface morphology and film structure has been studied by Scanning Electron Microscopy (SEM) and X-Ray diffraction technique. The adhesion of the diamond film has been evaluated by Rockwell indentation tests.
Lianxiang Yang (杨连祥)合作论文数Department of Mechanical Engineering, School of Engineering and Computer Science, Oakland University4