A control system testbed to validate critical infrastructure protection concepts

被引:115
作者
Morris, Thomas [1 ]
Srivastava, Anurag [2 ]
Reaves, Bradley [1 ]
Gao, Wei [1 ]
Pavurapu, Kalyan [1 ]
Reddi, Ram [1 ]
机构
[1] Mississippi State Univ, Dept Elect & Comp Engn, Mississippi State, MS 39762 USA
[2] Washington State Univ, Sch Elect Engn & Comp Sci, Pullman, WA 99164 USA
关键词
Testbed; Industrial control system; SCADA; Smart grid; Cybersecurity;
D O I
10.1016/j.ijcip.2011.06.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
080201 [机械制造及其自动化];
摘要
This paper describes the Mississippi State University SCADA Security Laboratory and Power and Energy Research laboratory. This laboratory combines model control systems from multiple critical infrastructure industries to create a testbed with functional physical processes controlled by commercial hardware and software over common industrial control system routable and non-routable networks. Laboratory exercises, functional demonstrations, and lecture material from the testbed have been integrated into a newly developed industrial control system cybersecurity course, into multiple other engineering and computer science courses, and into a series of short courses targeted to industry. Integration into the classroom allows the testbed to provide a workforce development function, prepares graduate students for research activities, and raises the profile of this research area with students. The testbed enables a research process in which cybersecurity vulnerabilities are discovered, exploits are used to understand the implications of the vulnerability on controlled physical processes, identified problems are classified by criticality and similarities in type and effect, and finally cybersecurity mitigations are developed and validated against within the testbed. Overviews of research enabled by the testbed are provided, including descriptions of software and network vulnerability research, a description of forensic data logger capability developed using the testbed to retrofit existing serial port MODBUS and DNP3 devices, and a description of intrusion detection research which leverages unique characteristics of industrial control systems. (C) 2011 Elsevier B.V. All rights reserved.
引用
收藏
页码:88 / 103
页数:16
相关论文
共 24 条
[1]
[Anonymous], 2009, WIR PROC LANG SUPP A
[2]
[Anonymous], POWER GRID SIMULATIO
[3]
[Anonymous], 2009, 00230093 N AM EL REL
[4]
[Anonymous], CONTROL SYSTEM CYBER
[5]
[Anonymous], CYB SEC EV TOOL CSET
[6]
[Anonymous], 2010, SYMANTEC SECURITY RE
[7]
[Anonymous], 2010, 1 WORKSH SEC CONTR S
[8]
Christiansson H, 2008, INT FED INFO PROC, V253, P237
[9]
Davis C.M., 2006, NORTH AMER POW SYMP, P483, DOI DOI 10.1109/NAPS.2006.359615
[10]
Fink R., 2006, LESS LEARN CYB SEC A