Security Enhancement of Industrial Modbus Message Transmission with Proxy Approach

Yih-Chuan Lin, Ci-Fong Lin, Kevin Chen
{"title":"Security Enhancement of Industrial Modbus Message Transmission with Proxy Approach","authors":"Yih-Chuan Lin, Ci-Fong Lin, Kevin Chen","doi":"10.1109/ECICE52819.2021.9645741","DOIUrl":null,"url":null,"abstract":"This paper presents an approach to improve the cybersecurity of Modbus protocol in industrial control systems by the security proxy strategy, which helps Modbus used in SCADA systems be more capable of dealing with malicious intrusion threats from external networks to the SCADA environment. On designing the security control scheme, there is one critical requirement taken into consideration for minimally changing the original configuration of SCADA systems. To validate the feasibility of the proposed security proxy approach, techniques for protecting the privacy and integrity of Modbus protocol messages are implemented in the proxy functions. Advanced encryption system (AES) is adopted by the proxy function to encrypt the messages before transmitting to prevent commands or data from being interpreted easily. In addition, the hash function is employed to generate an authentication token to make sure the received message is the same as the sender sent. The extra processing delay time required for each Modbus message after passing through the proxy functions is treated as the important factor for the success of the proposed approach in SCADA systems. Based on the experiments with replay and man-in-the-middle (MITM) attacks, satisfactory results are obtained, demonstrating the usefulness of applying the proposed security approach to network-based SCADA systems.","PeriodicalId":176225,"journal":{"name":"2021 IEEE 3rd Eurasia Conference on IOT, Communication and Engineering (ECICE)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE 3rd Eurasia Conference on IOT, Communication and Engineering (ECICE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ECICE52819.2021.9645741","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

This paper presents an approach to improve the cybersecurity of Modbus protocol in industrial control systems by the security proxy strategy, which helps Modbus used in SCADA systems be more capable of dealing with malicious intrusion threats from external networks to the SCADA environment. On designing the security control scheme, there is one critical requirement taken into consideration for minimally changing the original configuration of SCADA systems. To validate the feasibility of the proposed security proxy approach, techniques for protecting the privacy and integrity of Modbus protocol messages are implemented in the proxy functions. Advanced encryption system (AES) is adopted by the proxy function to encrypt the messages before transmitting to prevent commands or data from being interpreted easily. In addition, the hash function is employed to generate an authentication token to make sure the received message is the same as the sender sent. The extra processing delay time required for each Modbus message after passing through the proxy functions is treated as the important factor for the success of the proposed approach in SCADA systems. Based on the experiments with replay and man-in-the-middle (MITM) attacks, satisfactory results are obtained, demonstrating the usefulness of applying the proposed security approach to network-based SCADA systems.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
用代理方法增强工业Modbus消息传输的安全性
提出了一种利用安全代理策略提高工业控制系统Modbus协议的网络安全性的方法,使用于SCADA系统的Modbus能够更好地应对外部网络对SCADA环境的恶意入侵威胁。在设计安全控制方案时,要考虑一个关键的要求,即尽量减少对SCADA系统原有配置的改变。为了验证所提出的安全代理方法的可行性,在代理函数中实现了保护Modbus协议消息的隐私性和完整性的技术。代理功能采用高级加密系统AES (Advanced encryption system)对消息进行加密后再传输,防止命令或数据被轻易解读。此外,哈希函数用于生成身份验证令牌,以确保接收到的消息与发送方发送的消息相同。每个Modbus消息经过代理函数后所需的额外处理延迟时间被认为是该方法在SCADA系统中成功的重要因素。通过对重播攻击和中间人攻击(MITM)的实验,得到了满意的结果,证明了将该安全方法应用于基于网络的SCADA系统的有效性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Experimental Demonstration of 128QAM-OFDM Encoded Terahertz Signals over 20-km SMF Evaluation of Learning Effectiveness Using Mobile Communication and Reality Technology to Assist Teaching: A Case of Island Ecological Teaching [ECICE 2021 Front matter] Application of Time-series Smoothed Excitation CNN Model Study on Humidity Status Fuzzy Estimation of Low-power PEMFC Stack Based on the Softsensing Technology
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1