Laboratory Exercises to Accompany Industrial Control and Embedded Systems Security Curriculum Modules

Guillermo A. Francia, J. Snellen, Gretchen M. Richards
{"title":"Laboratory Exercises to Accompany Industrial Control and Embedded Systems Security Curriculum Modules","authors":"Guillermo A. Francia, J. Snellen, Gretchen M. Richards","doi":"10.1201/9780429263897-9","DOIUrl":null,"url":null,"abstract":"The daily intrusion attempts and attacks on industrial control systems (ICS) and embedded systems (ES) underscore the criticality of the protection of our Critical Infrastructures (CIs). As recent as mid-July 2018, numerous reports on the infiltration of US utility control rooms by Russian hackers have been published. These successful infiltration and possible manipulation of the utility companies could easily translate to a devastating attack on our nation’s power grid and, consequently, our economy and well-being. Indeed, the need to secure the control and embedded systems which operate our CIs has never been so pronounced. In our attempt to address this critical need, we designed, developed and implemented ICS and ES security curriculum modules with pertinent hands-on laboratory exercises that can be freely adopted across the national setting. This paper describes in detail the modules and the accompanying exercises and proposes future enhancements and extensions to these pedagogical instruments. It highlights the interaction between control and embedded systems security with Presidential Policy Directive 8the National Preparedness Plan (NPP), cyber risk management, incident handling. To establish the premise the laboratory exercises were developed. This paper outlines the description and content of the modules in the areas of (1) Industrial Control Systems (ICS) Security, (2) embedded systems (ES), and (3) guidelines, standards, and policy. The ICS security modules cover the predominant ICS protocols, ladder logic programming, Human Machine Interface (HMI), defensive techniques, ICS reconnaissance, vulnerability assessment, Intrusion detection, and penetration testing. The ES security modules include topics such as secure firmware programming and authentication mechanisms. In the guidelines, standards, and policy section, the topics covered by the modules include the NPP as it relates to CI protection, risk management, system protection and policy design, and managing operations and controls. An overview of the various hands-on exercises that accompany the course modules is also presented. Further, to evaluate the effectiveness of the pedagogical materials, an initial evaluation was conducted and the survey data were collected, analyzed, and presented. The paper concludes with future enhancements and directives on opportunities for module extensions and course adoption.","PeriodicalId":115859,"journal":{"name":"Cybersecurity and Privacy in Cyber-Physical Systems","volume":"69 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Cybersecurity and Privacy in Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1201/9780429263897-9","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

The daily intrusion attempts and attacks on industrial control systems (ICS) and embedded systems (ES) underscore the criticality of the protection of our Critical Infrastructures (CIs). As recent as mid-July 2018, numerous reports on the infiltration of US utility control rooms by Russian hackers have been published. These successful infiltration and possible manipulation of the utility companies could easily translate to a devastating attack on our nation’s power grid and, consequently, our economy and well-being. Indeed, the need to secure the control and embedded systems which operate our CIs has never been so pronounced. In our attempt to address this critical need, we designed, developed and implemented ICS and ES security curriculum modules with pertinent hands-on laboratory exercises that can be freely adopted across the national setting. This paper describes in detail the modules and the accompanying exercises and proposes future enhancements and extensions to these pedagogical instruments. It highlights the interaction between control and embedded systems security with Presidential Policy Directive 8the National Preparedness Plan (NPP), cyber risk management, incident handling. To establish the premise the laboratory exercises were developed. This paper outlines the description and content of the modules in the areas of (1) Industrial Control Systems (ICS) Security, (2) embedded systems (ES), and (3) guidelines, standards, and policy. The ICS security modules cover the predominant ICS protocols, ladder logic programming, Human Machine Interface (HMI), defensive techniques, ICS reconnaissance, vulnerability assessment, Intrusion detection, and penetration testing. The ES security modules include topics such as secure firmware programming and authentication mechanisms. In the guidelines, standards, and policy section, the topics covered by the modules include the NPP as it relates to CI protection, risk management, system protection and policy design, and managing operations and controls. An overview of the various hands-on exercises that accompany the course modules is also presented. Further, to evaluate the effectiveness of the pedagogical materials, an initial evaluation was conducted and the survey data were collected, analyzed, and presented. The paper concludes with future enhancements and directives on opportunities for module extensions and course adoption.
伴随工业控制和嵌入式系统安全课程模块的实验室练习
对工业控制系统(ICS)和嵌入式系统(ES)的日常入侵尝试和攻击强调了保护我们的关键基础设施(ci)的重要性。就在2018年7月中旬,许多关于俄罗斯黑客渗透美国公用事业控制室的报道已经发表。这些对公用事业公司的成功渗透和可能的操纵很容易转化为对我们国家电网的毁灭性攻击,从而影响我们的经济和福祉。事实上,对控制和嵌入式系统的安全需求从未像现在这样明显。为了解决这一关键需求,我们设计、开发和实施了ICS和ES安全课程模块,并提供了相关的动手实验练习,可以在全国范围内自由采用。本文详细描述了这些模块和伴随的练习,并提出了这些教学工具未来的增强和扩展。它强调了控制和嵌入式系统安全与总统政策指令8、国家准备计划(NPP)、网络风险管理、事件处理之间的相互作用。为了确立这一前提,开发了实验室练习。本文概述了(1)工业控制系统(ICS)安全领域模块的描述和内容,(2)嵌入式系统(ES)和(3)指南,标准和政策。ICS安全模块涵盖了主要的ICS协议、梯形逻辑编程、人机界面(HMI)、防御技术、ICS侦察、漏洞评估、入侵检测和渗透测试。ES安全模块包括安全固件编程、认证机制等主题。在指南、标准和策略部分,模块涵盖的主题包括NPP,因为它与CI保护、风险管理、系统保护和策略设计以及管理操作和控制有关。还介绍了伴随课程模块的各种实践练习的概述。此外,为了评估教学材料的有效性,进行了初步评估,并收集、分析和展示了调查数据。论文最后给出了未来的增强和关于模块扩展和课程采用机会的指示。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信