Moving Target Defense for Securing SCADA Communications

被引:15
|
作者
Heydari, Vahid [1 ]
机构
[1] Rowan Univ, Comp Sci Dept, Glassboro, NJ 08028 USA
来源
IEEE ACCESS | 2018年 / 6卷
关键词
SCADA; mobile IPv6; moving target defense; dynamic IP; ATTACKS;
D O I
10.1109/ACCESS.2018.2844542
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we introduce a framework for building a secure and private peer to peer communication used in supervisory control and data acquisition networks with a novel Mobile IPv6-based moving target defense strategy. Our approach aids in combating remote cyber-attacks against peer hosts by thwarting any potential attacks at their reconnaissance stage. The IP address of each host is randomly changed at a certain interval creating a moving target to make it difficult for an attacker to find the host. At the same time, the peer host is updated through the use of the binding update procedure (standard Mobile IPv6 protocol). Compared with existing results that can incur significant packet-loss during address rotations, the proposed solution is loss-less. Improving privacy and anonymity for communicating hosts by removing permanent IP addresses from all packets is also one of the major contributions of this paper. Another contribution is preventing black hole attacks and bandwidth depletion DDoS attacks through the use of extra paths between the peer hosts. Recovering the communication after rebooting a host is also a new contribution of this paper. Lab-based simulation results are presented to demonstrate the performance of the method in action, including its overheads. The testbed experiments show zero packet-loss rate during handoff delay.
引用
收藏
页码:33329 / 33343
页数:15
相关论文
共 50 条
  • [1] Moving Target Defense Based on Adaptive Forwarding Path Migration for Securing the SCADA Network
    Hu, Yifan
    Xun, Peng
    Zhu, Peidong
    Kang, Wenjie
    Xiong, Yinqiao
    Zhu, Yufei
    Shi, Weiheng
    Hu, Chenxi
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [2] Moving Target Defense for Securing Smart Grid Communications: Architecture, Implementation & Evaluation
    Pappa, Aswin Chidambaram
    Ashok, Aditya
    Govindarasu, Manimaran
    2017 IEEE POWER & ENERGY SOCIETY INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE (ISGT), 2017,
  • [3] Securing Critical Infrastructure by Moving Target Defense
    Heydari, Vahid
    Yoo, Seong-Moo
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2016), 2016, : 382 - 390
  • [4] sSCADA: securing SCADA infrastructure communications
    Wang, Yongge
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2011, 6 (01) : 59 - 78
  • [5] A Moving Target Defense for Securing Cyber-Physical Systems
    Griffioen, Paul
    Weerakkody, Sean
    Sinopoli, Bruno
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2021, 66 (05) : 2016 - 2031
  • [6] Securing Communications for SCADA and Critical Industrial Systems
    Bartman, Tom
    Carson, Kevin
    2016 69TH ANNUAL CONFERENCE FOR PROTECTIVE RELAY ENGINEERS (CPRE), 2016,
  • [7] Securing Software-Defined Networks Through Adaptive Moving Target Defense Capabilities
    Silva, Felipe Dantas S.
    Neto, Emidio P.
    Nunes, Rodrigo S. S.
    Souza, Cristian H. M.
    Neto, Augusto J. V.
    Pascoal, Tulio
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (03)
  • [8] Integrated moving target defense and control reconfiguration for securing Cyber-Physical systems
    Potteiger, Bradley
    Zhang, Zhenkai
    Koutsoukos, Xenofon
    MICROPROCESSORS AND MICROSYSTEMS, 2020, 73
  • [9] Securing IIoT systems against DDoS attacks with adaptive moving target defense strategies
    Sangita Swati
    Jawar Roy
    Jimson Singh
    undefined Mathew
    Scientific Reports, 15 (1)
  • [10] Securing Software-Defined Networks Through Adaptive Moving Target Defense Capabilities
    Felipe S. Dantas Silva
    Emidio P. Neto
    Rodrigo S. S. Nunes
    Cristian H. M. Souza
    Augusto J. V. Neto
    Túlio Pascoal
    Journal of Network and Systems Management, 2023, 31