The Experts below are selected from a list of 104973 Experts worldwide ranked by ideXlab platform

Simon N. Foley - One of the best experts on this subject based on the ideXlab platform.

  • Getting Security Objectives Wrong: A Cautionary Tale of an industrial control system (Transcript of Discussion)
    Security Protocols XXV, 2017
    Co-Authors: Simon N. Foley
    Abstract:

    Simon Foley: This is work that evolved by accident. Last year I started a project on industrial control system security, and by way of educating myself about the kinds of things that can go wrong, I used Shodan to search for an existing industrial control system connected to the Internet. I gave my first version of this talk in March 2016, and have given it a couple of times in the interim. Each time I prepared for the talk, I revisited the ICS, and each time its configuration had changed. This talk is what I learned from that experience.

  • Getting Security Objectives Wrong: A Cautionary Tale of an industrial control system
    Security Protocols XXV, 2017
    Co-Authors: Simon N. Foley
    Abstract:

    We relate a story about an industrial control system in order to illustrate that simple security objectives can be deceptive: there are many things that can and do go wrong when deploying the system. Rather than trying to define security explicitly, this paper takes the position that one should consider the security of a system by comparing it against others whose security we consider to be acceptable: Alice is satisfied if her system is no less secure than Bob’s system.

Thomas Morris - One of the best experts on this subject based on the ideXlab platform.

  • industrial control system Traffic Data Sets for Intrusion Detection Research
    2017
    Co-Authors: Thomas Morris, Wei Gao
    Abstract:

    Supervisory control and data acquisition (SCADA) systems monitor and control physical processes associated with the critical infrastructure. Weaknesses in the application layer protocols, however, leave SCADA networks vulnerable to attack. In response, cyber security researchers have developed myriad intrusion detection systems. Researchers primarily rely on unique threat models and the corresponding network traffic data sets to train and validate their intrusion detection systems. This leads to a situation in which researchers cannot independently verify the results, cannot compare the effectiveness of different intrusion detection systems, and cannot adequately validate the ability of intrusion detection systems to detect various classes of attacks. Indeed, a common data set is needed that can be used by researchers to compare intrusion detection approaches and implementations. This paper describes four data sets, which include network traffic, process control and process measurement features from a set of 28 attacks against two laboratory-scale industrial control systems that use the MODBUS application layer protocol. The data sets, which are freely available, enable effective comparisons of intrusion detection solutions for SCADA systems.

  • virtualization of industrial control system testbeds for cybersecurity
    Proceedings of the 2nd Annual Industrial Control System Security Workshop on, 2016
    Co-Authors: Thiago Alves, Rishabh Das, Thomas Morris
    Abstract:

    With an immense number of threats pouring in from nation states and hacktivists as well as terrorists and cybercriminals, the requirement of a globally secure infrastructure becomes a major obligation. Most critical infrastructures were primarily designed to work isolated from the normal communication network, but due to the advent of the "Smart Grid" that uses advanced and intelligent approaches to control critical infrastructure, it is necessary for these cyber-physical systems to have access to the communication system. Consequently, such critical systems have become prime targets; hence security of critical infrastructure is currently one of the most challenging research problems. Performing an extensive security analysis involving experiments with cyber-attacks on a live industrial control system (ICS) is not possible. Therefore, researchers generally resort to test beds and complex simulations to answer questions related to SCADA systems. Since all conclusions are drawn from the test bed, it is necessary to perform validation against a physical model. This paper examines the fidelity of a virtual SCADA testbed to a physical test bed and allows for the study of the effects of cyber- attacks on both of the systems.

  • industrial control system cyber attacks
    ICS-CSR 2013 Proceedings of the 1st International Symposium on ICS & SCADA Cyber Security Research 2013, 2013
    Co-Authors: Thomas Morris
    Abstract:

    This paper presents a set of attacks against SCADA control systems. The attacks are grouped into 4 classes; reconnaissance, response and measurement injection, command injection and denial of service. The 4 classes are defined and each attack is described in detail. The response and measurement injection and command injection classes are subdivided into sub-classes based on attack complexity. Each attack described in this paper has been exercised against industrial control systems in a laboratory setting.

  • A Proposed Australian industrial control system Security Curriculum
    2013 46th Hawaii International Conference on System Sciences, 2013
    Co-Authors: Mark Branagan, Thomas Morris
    Abstract:

    The security of industrial control systems in critical infrastructure is a concern for the Australian government and other nations. There is a need to provide local Australian training and education for both control system engineers and information technology professionals. This paper proposes a postgraduate curriculum of four courses to provide knowledge and skills to protect critical infrastructure industrial control systems. Our curriculum is unique in that it provides security awareness but also the advanced skills required for security specialists in this area. We are aware that in the Australian context there is a cultural gap between the thinking of control system engineers who are responsible for maintaining and designing critical infrastructure and information technology professionals who are responsible for protecting these systems from cyber attacks. Our curriculum aims to bridge this gap by providing theoretical and practical exercises that will raise the awareness and preparedness of both groups of professionals.

  • An open virtual testbed for industrial control system security research
    International Journal of Information Security, 2012
    Co-Authors: Bradley Reaves, Thomas Morris
    Abstract:

    industrial control system security has been a topic of scrutiny and research for several years, and many security issues are well known. However, research efforts are impeded by a lack of an open virtual industrial control system testbed for security research. This paper describes a virtual testbed framework using Python to create discrete testbed components including virtual devices and process simulators. The virtual testbed is designed such that the testbeds are inter-operable with real industrial control system devices and such that the virtual testbeds can provide comparable industrial control system network behavior to a laboratory testbed. Two virtual testbeds modeled upon actual laboratory testbeds have been developed and have been shown to be inter-operable with real industrial control system equipment and vulnerable to attacks in the same manner as a real system. Additionally, these testbeds have been quantitatively shown to produce traffic close to laboratory systems.

Yixiang Jiang - One of the best experts on this subject based on the ideXlab platform.

  • ICAIS (4) - Active Defense system of industrial control system Based on Dynamic Behavior Analysis
    Lecture Notes in Computer Science, 2019
    Co-Authors: Yixiang Jiang, Yizhen Lin
    Abstract:

    The Internet and the traditional network continue to converge. With the continuous occurrence of security incidents for industrial control systems such as the “Stuxnet” and the Ukraine power grid incident, the security of industrial control systems has attracted more and more attention from the state and enterprises. In order to cope with the continuous attacks, an active defense system for industrial control systems based on dynamic behavior analysis is proposed in this paper. By analyzing the traffic of the captured intruder and the attack behavior of the intruder, the system can make corresponding countermeasures when the attack occurs. The system realizes the expected goal of the industrial control system to actively defend against the intrusion behavior.

  • Tobacco system industrial control system Security
    2019 IEEE 4th International Conference on Computer and Communication Systems (ICCCS), 2019
    Co-Authors: Yixiang Jiang, Liujing Wang, Xun Zhang
    Abstract:

    In recent years, industrial control systems have received more and more attention, especially in the industrial safety of the tobacco industry. In order to solve the specific problems faced by industrial automation in the tobacco industry, a comprehensive industrial safety protection system based on system construction, networking security, data security and border protection is built in this paper.

  • ICCCS (6) - Security Threat and Protection in industrial control system
    Cloud Computing and Security, 2018
    Co-Authors: Yixiang Jiang, Chengting Zhang
    Abstract:

    With the deepening integration of informatization and industrialization, the industrial control system is facing more and more serious security threats at the same time of rapid development. At present, the legal norms and national security standards in the field of industrial control system are relatively lacking. And there is no strict market access system. In addition, the state’s industrial support for domestic industrial control equipment needs to be strengthened. Especially in terms of system security, data security, application security, and security management system, the research investment needs to be further increased, professional and technical forces need to be cultivated and the research of core technologies need to be focused on. To solve the information security problem of industrial control systems has become one of the key topics that the industry pays close attention to. In this paper, the development history of industrial control system is introduced, the root cause of industrial control system security threats is deeply analyzed, the future security threats of industrial control system is pointed out and the safety precautions of industrial control system is put forward. Based on the analysis of this paper, the personal security awareness of the industrial control system can be raised and the challenges of security threats can be better solved.

Bradley Reaves - One of the best experts on this subject based on the ideXlab platform.

  • An open virtual testbed for industrial control system security research
    International Journal of Information Security, 2012
    Co-Authors: Bradley Reaves, Thomas Morris
    Abstract:

    industrial control system security has been a topic of scrutiny and research for several years, and many security issues are well known. However, research efforts are impeded by a lack of an open virtual industrial control system testbed for security research. This paper describes a virtual testbed framework using Python to create discrete testbed components including virtual devices and process simulators. The virtual testbed is designed such that the testbeds are inter-operable with real industrial control system devices and such that the virtual testbeds can provide comparable industrial control system network behavior to a laboratory testbed. Two virtual testbeds modeled upon actual laboratory testbeds have been developed and have been shown to be inter-operable with real industrial control system equipment and vulnerable to attacks in the same manner as a real system. Additionally, these testbeds have been quantitatively shown to produce traffic close to laboratory systems.

Feng Li - One of the best experts on this subject based on the ideXlab platform.

  • Study of Security Protection on Power industrial control system
    DEStech Transactions on Computer Science and Engineering, 2017
    Co-Authors: Feng Li, Yang Li, Xu Wang, Tao Chen
    Abstract:

    In this paper, the security structure of power industrial control systems is introduced, and the information security risk of them is deeply analyzed. A security protection architecture based on power industrial control systems is put forward according to the development of information security at home and abroad, and it is made up of safe operation, technology, management, and security evaluation to ensure safety.

  • A safety assessment model of industrial control system based on fuzzing synthesis theory
    2017 IEEE 2nd Information Technology Networking Electronic and Automation Control Conference (ITNEC), 2017
    Co-Authors: Xu Wang, Feng Li, Jianye Zhang, Song Qing
    Abstract:

    A safety assessment model of industrial control system based on fuzzing theory is proposed to implement the goal of quantizing industrial control system safety assessment. Assessing matrix is established based on fuzzing synthesis theory by confirming assemble of industrial control system safety element and its weight coefficient and index assemble. And the matrix is applied to the industrial control system. industrial control system is influenced by circumstance, artificial and natural factors. By using this model to calculate industrial control system OPC server component value of risk, supplying theory gist for industrial control system managing and operating department.