关键基础设施中的可信邻域发现

Norman Göttert, N. Kuntze, C. Rudolph, Khan Ferdous Wahid
{"title":"关键基础设施中的可信邻域发现","authors":"Norman Göttert, N. Kuntze, C. Rudolph, Khan Ferdous Wahid","doi":"10.1109/SmartGridComm.2014.7007775","DOIUrl":null,"url":null,"abstract":"In today's Industrial Control Systems (ICSs) interconnection and reliable communication are valuable properties that enable the controlling and monitoring of various processes-even remotely. Cyber attacks or attacks via local digital interfaces break security requirements by altering software, configurations or control sequences. In such cases, safety requirements can no longer be guaranteed. Further, forged information such as wrong load measurements in power grid scenarios can lead to faulty decisions in the control center and has the potential to cause substantial damage with potentially catastrophic results. To detect and mitigate such kinds of attacks, the Trusted Neighborhood Discovery (TND) protocol introduces a decentralized, hardware-based approach for distributed peer-to-peer security monitoring. It uses hardware-based mutual attestation of the current state of adjacent devices. TND enables efficient monitoring, detection, and location of attacks in distributed infrastructures. The TND protocol is complemented by a Zero-Touch configuration solution for efficient and economic integration of new devices and secure configuration. Both protocols are realized in a proof-of-concept implementation running on commercially available hardware components. By implementing security in hardware roots of trust, the TND solution achieves a higher level of security than software-only based solutions. Even exchanging the entire firmware will be reliably reported.","PeriodicalId":6499,"journal":{"name":"2014 IEEE International Conference on Smart Grid Communications (SmartGridComm)","volume":"31 1","pages":"976-981"},"PeriodicalIF":0.0000,"publicationDate":"2014-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Trusted neighborhood discovery in critical infrastructures\",\"authors\":\"Norman Göttert, N. Kuntze, C. Rudolph, Khan Ferdous Wahid\",\"doi\":\"10.1109/SmartGridComm.2014.7007775\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In today's Industrial Control Systems (ICSs) interconnection and reliable communication are valuable properties that enable the controlling and monitoring of various processes-even remotely. Cyber attacks or attacks via local digital interfaces break security requirements by altering software, configurations or control sequences. In such cases, safety requirements can no longer be guaranteed. Further, forged information such as wrong load measurements in power grid scenarios can lead to faulty decisions in the control center and has the potential to cause substantial damage with potentially catastrophic results. To detect and mitigate such kinds of attacks, the Trusted Neighborhood Discovery (TND) protocol introduces a decentralized, hardware-based approach for distributed peer-to-peer security monitoring. It uses hardware-based mutual attestation of the current state of adjacent devices. TND enables efficient monitoring, detection, and location of attacks in distributed infrastructures. The TND protocol is complemented by a Zero-Touch configuration solution for efficient and economic integration of new devices and secure configuration. Both protocols are realized in a proof-of-concept implementation running on commercially available hardware components. By implementing security in hardware roots of trust, the TND solution achieves a higher level of security than software-only based solutions. Even exchanging the entire firmware will be reliably reported.\",\"PeriodicalId\":6499,\"journal\":{\"name\":\"2014 IEEE International Conference on Smart Grid Communications (SmartGridComm)\",\"volume\":\"31 1\",\"pages\":\"976-981\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2014-11-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2014 IEEE International Conference on Smart Grid Communications (SmartGridComm)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SmartGridComm.2014.7007775\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 IEEE International Conference on Smart Grid Communications (SmartGridComm)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SmartGridComm.2014.7007775","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

在当今的工业控制系统(ics)中,互连和可靠的通信是有价值的属性,可以控制和监视各种过程-即使是远程控制。网络攻击或通过本地数字接口的攻击通过改变软件、配置或控制序列打破安全要求。在这种情况下,安全要求不能再得到保证。此外,伪造的信息,如电网场景中的错误负载测量,可能导致控制中心做出错误的决策,并有可能造成重大损害和潜在的灾难性后果。为了检测和减轻此类攻击,可信邻居发现(TND)协议引入了一种分散的、基于硬件的方法,用于分布式点对点安全监控。它使用基于硬件的相互认证相邻设备的当前状态。TND能够有效地监视、检测和定位分布式基础设施中的攻击。TND协议由零接触配置解决方案补充,用于高效经济地集成新设备和安全配置。这两种协议都是在商用硬件组件上运行的概念验证实现中实现的。通过在硬件信任根中实现安全性,TND解决方案实现了比仅基于软件的解决方案更高级别的安全性。即使交换整个固件也会可靠地报告。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Trusted neighborhood discovery in critical infrastructures
In today's Industrial Control Systems (ICSs) interconnection and reliable communication are valuable properties that enable the controlling and monitoring of various processes-even remotely. Cyber attacks or attacks via local digital interfaces break security requirements by altering software, configurations or control sequences. In such cases, safety requirements can no longer be guaranteed. Further, forged information such as wrong load measurements in power grid scenarios can lead to faulty decisions in the control center and has the potential to cause substantial damage with potentially catastrophic results. To detect and mitigate such kinds of attacks, the Trusted Neighborhood Discovery (TND) protocol introduces a decentralized, hardware-based approach for distributed peer-to-peer security monitoring. It uses hardware-based mutual attestation of the current state of adjacent devices. TND enables efficient monitoring, detection, and location of attacks in distributed infrastructures. The TND protocol is complemented by a Zero-Touch configuration solution for efficient and economic integration of new devices and secure configuration. Both protocols are realized in a proof-of-concept implementation running on commercially available hardware components. By implementing security in hardware roots of trust, the TND solution achieves a higher level of security than software-only based solutions. Even exchanging the entire firmware will be reliably reported.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Household Level Electricity Load Forecasting Using Echo State Network Roaming electric vehicle charging and billing: An anonymous multi-user protocol Generating realistic Smart Grid communication topologies based on real-data Cooperative closed-loop MIMO selective transmissions in a HV environment Integration of V2H/V2G hybrid system for demand response in distribution network
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1