Shahzad Aamir, Lee Malrey, Kim Suntae, Kim Kangmin, Choi Jae-Young, Cho Younghwa, Lee Keun-Kwang
Center for Advanced Image and Information Technology, School of Electronics & Information Engineering, Chon Buk National University, 664-14, 1Ga, Deokjin-Dong, Jeonju, Chonbuk 561-756, Korea.
Department of Software Engineering, Chon Buk National University, 664-14, 1Ga, Deokjin-Dong, Jeonju, Chonbuk 561-756, Korea.
Sensors (Basel). 2016 Jan 6;16(1):37. doi: 10.3390/s16010037.
Today, security is a prominent issue when any type of communication is being undertaken. Like traditional networks, supervisory control and data acquisition (SCADA) systems suffer from a number of vulnerabilities. Numerous end-to-end security mechanisms have been proposed for the resolution of SCADA-system security issues, but due to insecure real-time protocol use and the reliance upon open protocols during Internet-based communication, these SCADA systems can still be compromised by security challenges. This study reviews the security challenges and issues that are commonly raised during SCADA/protocol transmissions and proposes a secure distributed-network protocol version 3 (DNP3) design, and the implementation of the security solution using a cryptography mechanism. Due to the insecurities found within SCADA protocols, the new development consists of a DNP3 protocol that has been designed as a part of the SCADA system, and the cryptographically derived security is deployed within the application layer as a part of the DNP3 stack.
如今,在进行任何类型的通信时,安全都是一个突出问题。与传统网络一样,监控与数据采集(SCADA)系统存在许多漏洞。为解决SCADA系统安全问题,人们提出了众多端到端安全机制,但由于实时协议使用不安全以及在基于互联网的通信过程中依赖开放协议,这些SCADA系统仍可能受到安全挑战的影响。本研究回顾了SCADA/协议传输过程中常见的安全挑战和问题,并提出了一种安全分布式网络协议版本3(DNP3)设计,以及使用加密机制实现安全解决方案。由于在SCADA协议中发现的不安全因素,新的开发成果包括一个作为SCADA系统一部分设计的DNP3协议,以及在应用层作为DNP3堆栈一部分部署的基于加密的安全性。