Protecting Modbus/TCP-Based Industrial Automation and Control Systems Using Message Authentication Codes

被引:5
|
作者
Katulic, Filip [1 ]
Sumina, Damir [1 ]
Gros, Stjepan [1 ]
Erceg, Igor [1 ]
机构
[1] Univ Zagreb, Fac Elect Engn & Comp, Zagreb 10000, Croatia
关键词
Computer security; Protocols; Cryptography; Codes; Authentication; Ethernet; Critical infrastructure; Control systems; Automation; communication system security; cyber-physical systems; industrial communication;
D O I
10.1109/ACCESS.2023.3275443
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Critical infrastructure (CI), such as energy and water distribution systems, is essential for the stability and well-being of the modern society. Industrial automation and control systems (IACSs) form the backbone of CIs and enable the operation of such systems in a safe and reliable manner. However, with the increasing use of industrial Ethernet communication protocols, such as Modbus-over-TCP (Modbus/TCP), once air-gapped IACSs are becoming vulnerable to potential cybersecurity threats. This paper presents a novel method for enhancing the cybersecurity of Modbus/TCP-based IACSs by implementing an authentication method based on message authentication codes (MACs). To provide partial protection of communication even when communicating with legacy Modbus/TCP peers, we propose a novel supervising device that analyzes exchanged messages and verifies the authenticity of the protected messages. To experimentally verify the protection method, a water-treatment cyber-physical system (CPS) was implemented as a digital twin in a programmable logic controller (PLC). The underlying MAC is the Chaskey-12, lightweight MAC defined in IEC 29192-6. It was implemented in the PLC program using the programming languages defined in IEC 61131-3. As an additional contribution, the presented implementation allows protection of communication between PLCs and other Modbus/TCP peers installed in existing IACSs without hardware or firmware modifications. The results show that the method provides protection against network attacks without significantly affecting performance, also demonstrating the feasibility of such protection in IACSs.
引用
收藏
页码:47007 / 47023
页数:17
相关论文
共 50 条
  • [41] Simple adaptive control for industrial feed drive systems using a jerk-based augmented output signal
    Haryson Johanes Nyobuya
    Mathias Sebastian Halinga
    Naoki Uchiyama
    [J]. The International Journal of Advanced Manufacturing Technology, 2023, 128 : 3613 - 3626
  • [42] Simple adaptive control for industrial feed drive systems using a jerk-based augmented output signal
    Nyobuya, Haryson Johanes
    Halinga, Mathias Sebastian
    Uchiyama, Naoki
    [J]. INTERNATIONAL JOURNAL OF ADVANCED MANUFACTURING TECHNOLOGY, 2023, 128 (7-8): : 3613 - 3626
  • [43] Intrusion Detection in PLC-Based Industrial Control Systems Using Formal Verification Approach in Conjunction with Graphs
    Muluken Hailesellasie
    Syed Rafay Hasan
    [J]. Journal of Hardware and Systems Security, 2018, 2 (1) : 1 - 14
  • [44] A Complex Network-Based Critical Node Identification Method for Industrial Control Systems Using Range of Failure Impacts
    Yang, Jian
    Zhang, Renbin
    Shi, Lei
    Fan, Yuqi
    Zhao, Jixiang
    Cao, Zongze
    Wang, Long
    [J]. PROCEEDINGS OF 2020 IEEE 5TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2020), 2020, : 539 - 545
  • [45] Enhanced Motion Accuracy in Industrial Feed Drive Systems Using Simple Adaptive Control with a Jerk-Based Augmented Signal
    Nyobuya, Haryson Johanes
    Halinga, Mathias Sebastian
    Uchiyama, Naoki
    [J]. IFAC PAPERSONLINE, 2023, 56 (02): : 9203 - 9208
  • [46] Improving Deceptive Patch Solutions Using Novel Deep Learning-Based Time Analysis Model for Industrial Control Systems
    Tanyıldız, Hayriye
    Batur Şahin, Canan
    Batur Dinler, Özlem
    [J]. Applied Sciences (Switzerland), 2024, 14 (20):
  • [47] A combined control approach for industrial process systems using feed-forward and adaptive action based on second order sliding mode controller design
    Dumlu, Ahmet
    Ayten, Kagan Koray
    [J]. TRANSACTIONS OF THE INSTITUTE OF MEASUREMENT AND CONTROL, 2019, 41 (04) : 1160 - 1171
  • [48] Retraction Note: Internet of Things Based Industrial Automation Using Brushless DC Motor Application with Resilient Directed Neural Network Control FED Virtual Z-Source Multilevel Inverter Topology
    S. Sivaranjani
    R. Rajeswari
    [J]. Wireless Personal Communications, 2023, 128 : 1507 - 1507
  • [49] RETRACTED ARTICLE: Internet of Things Based Industrial Automation Using Brushless DC Motor Application with Resilient Directed Neural Network Control FED Virtual Z-Source Multilevel Inverter Topology
    S. Sivaranjani
    R. Rajeswari
    [J]. Wireless Personal Communications, 2018, 102 : 3239 - 3254
  • [50] Detection of Cyberattacks in Industrial Control Systems Using Enhanced Principal Component Analysis and Hypergraph-Based Convolution Neural Network (EPCA-HG-CNN)
    Priyanga, S.
    Krithivasan, Kannan
    Pravinraj, S.
    Sriram, Shankar V. S.
    [J]. IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, 2020, 56 (04) : 4394 - 4404