EDSGuard: Enforcing Network Security Requirements for Energy Delivery Systems

Vu Coughlin, Carlos E. Rubio-Medrano, Ziming Zhao, Gail-Joon Ahn
{"title":"EDSGuard: Enforcing Network Security Requirements for Energy Delivery Systems","authors":"Vu Coughlin, Carlos E. Rubio-Medrano, Ziming Zhao, Gail-Joon Ahn","doi":"10.1109/SmartGridComm.2018.8587430","DOIUrl":null,"url":null,"abstract":"Recently, energy delivery systems (EDS) have been targeted by sophisticated network-based attacks tailored to disrupt the proper distribution of energy among different geographical regions, resulting in non-trivial socio-economical loses and a loss of public confidence in EDS infrastructures. Such attacks were facilitated by the lack of native security measures regarding existing network communication protocols for EDS, which allowed attackers to deliberately manipulate the state of network connections between control modules and field devices. In order to address these concerns, this paper presents EDSGuard, a state-based firewall and monitoring tool that leverages state-of the-art packet inspection techniques along with software-defined networks (SDN), to intelligently implement a set of security requirements and best practices for protecting EDS networks, as issued by regulatory organizations within the EDS community in the last years. In addition, EDSGuard implements a series of first-response countermeasure strategies, which can automatically react to anomalies and attacks, thus effectively mitigating their consequences and impact as a result. We provide the overall rationale behind our approach, as well as a description of our experimental results depicting a set of attack scenarios inspired by recent incidents affecting EDS infrastructures, which provide evidence of the suitability of EDSGuard for being fully adopted in practice.","PeriodicalId":213523,"journal":{"name":"2018 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm)","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SmartGridComm.2018.8587430","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Recently, energy delivery systems (EDS) have been targeted by sophisticated network-based attacks tailored to disrupt the proper distribution of energy among different geographical regions, resulting in non-trivial socio-economical loses and a loss of public confidence in EDS infrastructures. Such attacks were facilitated by the lack of native security measures regarding existing network communication protocols for EDS, which allowed attackers to deliberately manipulate the state of network connections between control modules and field devices. In order to address these concerns, this paper presents EDSGuard, a state-based firewall and monitoring tool that leverages state-of the-art packet inspection techniques along with software-defined networks (SDN), to intelligently implement a set of security requirements and best practices for protecting EDS networks, as issued by regulatory organizations within the EDS community in the last years. In addition, EDSGuard implements a series of first-response countermeasure strategies, which can automatically react to anomalies and attacks, thus effectively mitigating their consequences and impact as a result. We provide the overall rationale behind our approach, as well as a description of our experimental results depicting a set of attack scenarios inspired by recent incidents affecting EDS infrastructures, which provide evidence of the suitability of EDSGuard for being fully adopted in practice.
EDSGuard:执行能源输送系统的网络安全要求
最近,能源输送系统(EDS)成为了复杂的基于网络的攻击的目标,这些攻击旨在破坏不同地理区域之间的能源合理分配,导致重大的社会经济损失和公众对EDS基础设施的信心丧失。由于缺乏针对EDS现有网络通信协议的本地安全措施,这使得攻击者可以故意操纵控制模块和现场设备之间的网络连接状态,从而促进了此类攻击。为了解决这些问题,本文介绍了EDSGuard,这是一种基于状态的防火墙和监控工具,利用最先进的数据包检测技术以及软件定义网络(SDN),智能地实现一组安全要求和保护EDS网络的最佳实践,正如EDS社区内的监管组织在过去几年中发布的那样。此外,EDSGuard还实现了一系列的第一反应对策策略,可以自动应对异常和攻击,从而有效地减轻其后果和影响。我们提供了我们的方法背后的总体原理,以及我们的实验结果的描述,描述了一系列受最近影响EDS基础设施的事件启发的攻击场景,这为EDSGuard在实践中完全采用的适用性提供了证据。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信