...
首页> 外文期刊>Journal of network and computer applications >Formal modelling and analysis of DNP3 secure authentication
【24h】

Formal modelling and analysis of DNP3 secure authentication

机译:DNP3安全认证的正式建模和分析

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Supervisory Control and Data Acquisition (SCADA) systems are one of the key foundations of smart grids. The Distributed Network Protocol version 3 (DNP3) is a standard SCADA protocol designed to facilitate communications in substations and smart grid nodes. The protocol is embedded with a security mechanism called Secure Authentication (DNP3-SA). This mechanism ensures that end-to-end communication security is provided in substations. This paper presents a formal model for the behavioural analysis of DNP3-SA using Coloured Petri Nets (CPN). Our DNP3-SA CPN model is capable of testing and verifying various attack scenarios: modification, replay and spoofing, combined complex attack and mitigation strategies. Using the model has revealed a previously unidentified flaw in the DNP3-SA protocol that can be exploited by an attacker that has access to the network interconnecting DNP3 devices. An attacker can launch a successful attack on an outstation without possessing the pre-shared keys by replaying a previously authenticated command with arbitrary parameters. We propose an update to the DNP3-SA protocol that removes the flaw and prevents such attacks. The update is validated and verified using our CPN model proving the effectiveness of the model and importance of the formal protocol analysis. (C) 2015 Elsevier Ltd. All rights reserved.
机译:监控和数据采集(SCADA)系统是智能电网的关键基础之一。分布式网络协议版本3(DNP3)是标准的SCADA协议,旨在促进变电站和智能电网节点中的通信。该协议嵌入了称为安全认证(DNP3-SA)的安全机制。该机制确保在变电站中提供端到端的通信安全性。本文提出了使用有色Petri网(CPN)进行DNP3-SA行为分析的正式模型。我们的DNP3-SA CPN模型能够测试和验证各种攻击方案:修改,重播和欺骗,复杂的攻击和缓解策略相结合。使用该模型揭示了DNP3-SA协议中以前未发现的缺陷,攻击者可以利用此缺陷,该攻击者可以访问互连DNP3设备的网络。攻击者可以通过使用任意参数重播以前通过身份验证的命令,而无需拥有预共享密钥即可在外站上成功发起攻击。我们建议对DNP3-SA协议进行更新,以消除该缺陷并防止此类攻击。使用我们的CPN模型对更新进行了验证和验证,证明了该模型的有效性以及正式协议分析的重要性。 (C)2015 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号