Deep Packet Inspection in Industrial Automation Control System to Mitigate Attacks Exploiting Modbus/TCP Vulnerabilities

被引:19
|
作者
Nyasore, Osborn N. [1 ]
Zavarsky, Pavol [1 ]
Swar, Bobby [1 ]
Naiyeju, Raphael [1 ]
Dabra, Shubham [1 ]
机构
[1] Concordia Univ Edmonton, Informat Syst Secur & Assurance Management, Edmonton, AB, Canada
关键词
industrial control and automation system security; Modbus/TCP; deep packet inspection; intrusion detection and prevention system; industrial firewall;
D O I
10.1109/BigDataSecurity-HPSC-IDS49724.2020.00051
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Modbus TCP/IP protocol is a commonly used protocol in industrial automation control systems, systems responsible for sensitive operations such as gas turbine operation and refinery control. The protocol was designed decades ago with no security features in mind. Denial of service attack and malicious parameter command injection are examples of attacks that can exploit vulnerabilities in industrial control systems that use Modbus/TCP protocol. This paper discusses and explores the use of intrusion detection and prevention systems (IDPS) with deep packet inspection (DPI) capabilities and DPI industrial firewalls that have capability to detect and stop highly specialized attacks hidden deep in the communication flow. The paper has the following objectives: (i) to develop signatures for IDPS for common attacks on Modbus/TCP based network architectures; (ii) to evaluate performance of three IDPS - Snort, Suricata and Bro - in detecting and preventing common attacks on Modbus/TCP based control systems; and (iii) to illustrate and emphasize that the IDPS and industrial firewalls with DPI capabilities are not preventing but only mitigating likelihood of exploitation of Modbus/TCP vulnerabilities in the industrial and automation control systems. The results presented in the paper illustrate that it might be challenging task to achieve requirements on real-time communication in some industrial and automation control systems in case the DPI is implemented because of the latency and jitter introduced by these IDPS and DPI industrial firewall.
引用
收藏
页码:241 / 245
页数:5
相关论文
共 11 条
  • [1] Reconnaissance of Industrial Control System By Deep Packet Inspection
    Wakchaure, Mahesh
    Sarwade, Satish
    Siddavatam, Irfan
    [J]. PROCEEDINGS OF 2ND IEEE INTERNATIONAL CONFERENCE ON ENGINEERING & TECHNOLOGY ICETECH-2016, 2016, : 1093 - 1096
  • [2] Improve the Security of Industrial Control System: A Fine-Grained Classification Method for DoS Attacks on Modbus/TCP
    Hao Zhang
    Yuandong Min
    Sanya Liu
    Hang Tong
    Yaopeng Li
    Zhihan Lv
    [J]. Mobile Networks and Applications, 2023, 28 : 839 - 852
  • [3] Improve the Security of Industrial Control System: A Fine-Grained Classification Method for DoS Attacks on Modbus/TCP
    Zhang, Hao
    Min, Yuandong
    Liu, Sanya
    Tong, Hang
    Li, Yaopeng
    Lv, Zhihan
    [J]. MOBILE NETWORKS & APPLICATIONS, 2023, 28 (02): : 839 - 852
  • [4] Intrusion Detection of Industrial Control System based on Modbus TCP Protocol
    Wang Yusheng
    Fan Kefeng
    Lai Yingxu
    Liu Zenghui
    Zhou Ruikang
    Yao Xiangzhen
    Li Lin
    [J]. 2017 IEEE 13TH INTERNATIONAL SYMPOSIUM ON AUTONOMOUS DECENTRALIZED SYSTEMS (ISADS 2017), 2017, : 156 - 162
  • [5] Key Vulnerabilities of Industrial Automation and Control Systems and Recommendations to Prevent Cyber-Attacks
    Calvo, I.
    Etxeberria-Agiriano, I.
    Inigo, M. A.
    Gonzalez-Nalda, P.
    [J]. INTERNATIONAL JOURNAL OF ONLINE ENGINEERING, 2016, 12 (01) : 9 - 16
  • [6] Protecting Modbus/TCP-Based Industrial Automation and Control Systems Using Message Authentication Codes
    Katulic, Filip
    Sumina, Damir
    Gros, Stjepan
    Erceg, Igor
    [J]. IEEE ACCESS, 2023, 11 : 47007 - 47023
  • [7] Estimating the Time-To-Compromise of Exploiting Industrial Control System Vulnerabilities
    Ling, Engla Rencelj
    Ekstedt, Mathias
    [J]. PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2021, : 96 - 107
  • [8] System-specific risk rating of software vulnerabilities in industrial automation & control systems
    Maidl, Monika
    Kroeselberg, Dirk
    Zhao, Tiange
    Limmer, Tobias
    [J]. 2021 IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW 2021), 2021, : 327 - 332
  • [9] Educational mobile laboratory unit implementation to study and research industrial control system vulnerabilities to cyber attacks
    Yildiz, Faruk
    Pecen, Recayi
    Dakeev, Ulan
    [J]. Journal of Technology, Management, and Applied Engineering, 2020, 36 (02): : 1 - 19
  • [10] Evolutionary Deep Belief Network for Cyber-Attack Detection in Industrial Automation and Control System
    Lu, Kang-Di
    Zeng, Guo-Qiang
    Luo, Xizhao
    Weng, Jian
    Luo, Weiqi
    Wu, Yongdong
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (11) : 7618 - 7627