Cyberattacks are prevailing attacks on critical infrastructures and due protection and effective response have become crucial in Industrial Control Systems (ICS). ICS cybersecurity is a prominent research topic after the sudden surge in Operational Technology (OT) environment attacks. The challenge of securing the ICS network exists because they are a combination of Information Technology (IT) and OT infrastructure, which means that we have to implement strategies that work for both. In this proposed work, we focus on mitigating the vulnerabilities of hardware assets or software assets by designing a automated vulnerability management approach for ICS. To provide comprehensive and effective mitigation, we map the individual vulnerabilities to attack tactics and techniques. This fosters a broader scope and highlights the damage that the vulnerability can have. It also gives us an adversary perspective to understand which vulnerabilities are to be prioritized. Every organization is bound to have weaknesses, but it is exceptionally crucial to mitigate the critical ones. With the help of the MITRE ATT &CK framework and the knowledge of attack groups that specifically target OT organizations, we curate a strategy that identifies reported vulnerabilities in the assets, prioritizes them and mitigates them with the help of patches, policies or controls.
Bluetooth Low Energy (BLE), a low-power wireless protocol, is widely used in industrial automation for monitoring field devices. Although the BLE standard defines advanced security mechanisms, there are known security attacks for BLE and BLE-enabled field devices must be tested thoroughly against these attacks. This article identifies the possible attacks for BLE-enabled field devices relevant for industrial automation. It also presents a framework for defining and executing BLE security attacks and evaluates it on three BLE devices. All tested devices are vulnerable and this confirms that there is a need for better security testing tools as well as for additional defense mechanisms for BLE devices.
With advancement in the concept of internet of things (IoT), many industrial applications today have migrated from wired to wireless communication protocols. The major requirements of industrial devices utilizing wireless technologies include high performance reliability similar to wired network, and longevity in terms of battery life. Wireless field devices that run on battery should be able to operate for long duration without frequent battery replacement. Industrial use-cases may have varied data rate requirements from very low data rates in the order of few kilo bits per second, to upwards of hundreds of kilo bits per second or may be in mega bits per second. Thus depending on the use-case one should select a suitable wireless technology that can address the requirements. While there exists a number of alternative technologies that offer very low data rate along with long battery life usage, the number of technologies offering medium to higher data rates along with long battery life are limited. WiFi or IEEE 802.11b/g standard is typically considered to be energy hungry solution, however due to the advancements in implementation technology, some of these radio devices exhibit very low power consumption during non-active states, and thus can be utilized in industrial use-cases that require long battery life along with medium to high data rates. In this paper, we have studied the suitability of WiFi as a candidate for low power industrial needs. Comparisons have been provided with IEEE 802.15.4 wireless technology as well.
The severity of cyber threats towards existing and future industrial systems has resulted in an increase of security awareness in the industrial automation domain. Compared to traditional informati ...
A growing concern of cyber threats towards industrial plants has prompted industrial practitioners to focus on secure communication solutions which can protect their systems from vulnerabilities and as well as their brand image. The security concerns and the solutions for industrial communication networks have become well-discussed topics in research communities. Despite a huge research effort in the area of industrial communication network security, there are several issues that need to be addressed properly such that a unified security solution can be adopted in the industrial domain. In this article, we aim to outline the research direction for industrial communication security. Though security is considered as an on-going process, the major issues that still need to be addressed are trust management for heterogeneous networks, managing network performance with security requirements, usable security and key management.
Remote health monitoring is one of the emerging IoT applications that has attracted the attention of communication and health sectors in recent years. We enable software defined networking in a wireless sensor network to provide easy reconfiguration and at run-time network management. In this way, we devise a multi-objective decision making approach that is implemented at the network intelligence to find the set of optimal paths that routes physiological data over a wireless medium. In this work, the main considered parameters for reliable data communication are path traffic, path consumed energy, and path length. Using multi-objective optimization technique within a case study, we find the best routes that provide reliable data communication.
Congestion control is a challenging issue in wireless sensor networks with limited channel bandwidth. Thus, many protocols have been designed to provide a distributed traffic control during packet forwarding. However, all these approaches are applied to single-hop communication networks, ignoring the multi-hop restrictions. In this work, we take advantage of software defined networking paradigm by devising a controller node in such a way that it collects all the necessary information from wireless sensor network nodes. Thus, based on hop count and local traffic information, controller decides for possible flow path changes to evenly distribute the traffic. The evaluations revealed that the SDN-TAP outperforms conventional routing protocols by reducing packet loss rate up to 46%.
A key aspect of realizing the future smart grid communication solution is a balanced approach between the network performance and the network security during the network deployment. A high security communication flow path is not useful when the network path cannot support capacity and reachability requirements. The deployment phase in communication network can facilitate an optimal network path by focusing on both the network performance and the network security at the same time. In this paper, we describe a use case of smart grid application where security, network capacity and reachability needs to be optimal for successful network operation. We explain our proposed balancing approach of the network performance and the network security which can be useful for the optimal smart grid secure system design.
In an industrial plant, there is usually a mix of devices with different levels of security features and computation capabilities. If a mix of devices with various degrees of security features and capabilities communicate, the overall network dynamics with respect to security and network performance will be complex. A secure communication path with high latency and low bandwidth may not satisfy the operational requirements in a plant. Therefore, there is a need to assess the relation of security and network performance for overall plant operation. In this work we focus on identifying an optimal flow path between two devices in a multi-hop heterogeneous network. We propose a model and an algorithm to estimate and generate a network path identified by flow performance indicators of a heterogeneous communication network. Through an example, we show how the flow performance metrics change with security, capacity and reachability of the devices in the network.
The next-generation electrical power system is focusing on reliable, automated, and secure power grid by using information and communication technology (ICT). To realize the new generation of power grid, the communication network is a decisive piece of the entire smart grid. Communication infrastructure in smart grids is a combination of both wired and wireless technologies. The salient features of wireless technology makes it attractive but the easy access to the radio medium in wireless communication increases the risk of security attacks. Consequently, the concern for cyber security has become an important issue to be addressed in a smart grid network. Intrusion detection and response to these intrusions in a timely manner is a way to improve system integrity. In this paper, we focus on a medium access control (MAC) layer intrusion detection system for wireless networks in smart grids. We propose a multi-level intrusion detection response system (IDRS) framework based on the perception of defense-in-depth. Through a simple simulation study, we verify the working of our proposed framework.
An efficient key management system is required to support cryptography.Most key management systems use either pre-installed shared keys or install initial security parameters using out-of-band channels.These methods create an additional burden for engineers who manage the devices in industrial plants.Hence, device deployment in industrial plants becomes a challenging task in order to achieve security.In this work, we present a device deployment framework that can support key management using the existing trust towards employees in a plant.This approach reduces the access to initial security parameters by employees; rather it helps to bind the trust of the employee with device commissioning.Thus, this approach presents a unique solution to the device deployment problem.Further, through a proof-of-concept implementation and security analysis using the AVISPA tool, we present that our framework is feasible to implement and satisfies our security objectives.
In industrial plants, there is a mix of devices with different security features and capabilities. If there is a mix of devices with various degree of security levels, then this will create independent islands in a network with similar levels of security features. However, the industrial plant is interconnected for the purpose of reducing cost of monitoring with a centralized control center. Therefore, the different islands also need to communicate with each other to improve the asset management efficiency in a plant. In this work we aim to focus on the trustworthiness assessment of devices in industrial plant networks in term of node value. We study the behavior of industrial plant networks when devices with various degrees of security features communicate. We aim to identify network properties which influence the overall network behavior. From the study, we have found that the communication path, the order of different communication paths and the number of specific types of nodes affect the final trustworthiness of devices in the network.
Industrial plants are heterogeneous networks with different computation and communication capabilities along with different security properties. The optimal operation of a plant requires a balance between communication capabilities and security features. A secure communication data flow with high latency and low bandwidth does not provide the required efficiency in a plant. Therefore, we focus on assessing the relation of security, capacity and timeliness properties of an industrial network for overall network performance.
The security in industrial automation domain using cryptography mechanisms is being discussed in both industry and academia. An efficient key management system is required to support cryptography for both symmetric key and public/private key encryption. The key management should ensure that the device is verified before distributing the initial key parameters to devices. The software/firmware used in the device comes from manufacturers, therefore the initial authenticity of the device can be easily verified with the help of manufacturers. Mobile telecommunication is an industrial segment where wireless devices are being used for a long time and the security of the wireless device management has been considered through a standard driven approach. Therefore, it is interesting to analyse the security authentication mechanisms used in mobile communication, specified in Long-Term-Evolution (LTE) standard. This paper analyses the initial device authentication using public key infrastructure in LTE standard, and discusses if, where and how the studied solutions can be tailored for device authenticity verification in industrial plant automation systems.
Industrial networks have a mix of devices with different security properties. If a mix of devices with various degrees of security features and capabilities communicate, the overall network dynamics with respect to device trust and security of message exchange will be complex. Therefore, there is a need to understand the trust and risk probabilities of devices in a heterogeneous network. This is required for heterogeneous network where the network configuration has to be made based on how trustworthy they are. In this work we focus on assessing security risks for devices and message exchanges. We define the term assurance value to denote the resilience of a device to security attacks. We study the behavior of a communication network when devices with various degrees of security features exchange messages. We aim to identify the network security properties based on the network architecture. From the study, we propose a model to estimate and predict network security properties in a heterogeneous communication network.
The severity of cyber threats towards existing and future industrial systems has resulted in an increase of security awareness in the industrial automation domain. Compared to traditional information security, industrial communication systems have different performance and reliability requirements. The safety and availability requirements can also sometimes conflict with the system security design of plants. For instance, it is not acceptable to create a secure system which may take up additional time to establish security and as a consequence disrupt the production in plants. Similarly, a system which requires authentication and authorization procedures before any emergency action may not be suitable in industrial plants.Therefore, there is a need for improvement of the security workflow in industrial plants, so that the security can be realized in practice. This also leads to the requirement of secure device deployment and secure data communication inside the industrial plants. In this thesis, the focus is on the initial trust establishment in industrial devices. The initial trust establishment is the starting point for enabling a secure communication infrastructure. Reusability analysis with financial sectors has been considered as the reuse of security solutions from this adjacent application domain can be a simple and an effective way to achieve the desired system security. Through this analysis, the reusability features have been identified and workflows have been proposed which can be used to bootstrap initial trust in the industrial process control devices and manage security workflow. A proof-of-concept implementation to prove the feasibility of the device deployment workflow has also been provided.