首页> 外文会议>Annual Conference of the IEEE Industrial Electronics Society >On Experimental validation of Whitelist Auto-Generation Method for Secured Programmable Logic Controllers
【24h】

On Experimental validation of Whitelist Auto-Generation Method for Secured Programmable Logic Controllers

机译:安全可编程逻辑控制器白名单自动生成方法的实验验证

获取原文

摘要

This paper considers a whitelisting system for programmable logic controllers (PLCs). In control systems, controllers are final fortresses to continues the operation of field devices (actuators/sensors), but they are fragile with respect to malware and zero-day attacks. One of the countermeasures applicable for controllers is a whitelisting system which registers normal operations of controller behavior in a “whitelist” to detect abnormal operations via a whitelist. The previous research of the current author proposed a PLC whitelisting system with a control via a ladder diagram (LD). LD representations have a wide applicability because LDs can be implemented for all PLCs and security functions without hardware/firmware updates. However, the current status requires that all instances are manually entered in the whitelist. In this talk, we show how the setting up of the can be automatized whitelist from the PLC behavior. This paper introduces an auto-generation approach for the whitelist using sequential function chart (SFC) instead of the LD. SFC and LD are compatible representations for the PLC. Using Petri Net modeling, this paper proposes how to generate the whitelist from the SFC and how to detect abnormal operations via the whitelist. We call the SFC-based approach the model-based whitelist, the Petri Net based approach the model-based detection. Further, this paper carries out an experimental validation of the algorithms using an OpenPLC based testbed system.
机译:本文考虑了用于可编程逻辑控制器(PLC)的白名单系统。在控制系统中,控制器是继续现场设备(执行器/传感器)运行的最后要塞,但它们在恶意软件和零时差攻击方面脆弱。适用于控制器的对策之一是白名单系统,该系统将控制器行为的正常操作记录在“白名单”中,以通过白名单检测异常操作。当前作者的先前研究提出了一种PLC白名单系统,该系统具有通过梯形图(LD)进行控制的功能。 LD表示法具有广泛的适用性,因为可以在不进行硬件/固件更新的情况下为所有PLC和安全功能实现LD。但是,当前状态要求将所有实例手动输入白名单。在本次演讲中,我们展示了如何根据PLC行为自动设置白名单。本文介绍了一种使用顺序功能图(SFC)而不是LD的白名单自动生成方法。 SFC和LD是PLC的兼容表示。本文使用Petri Net建模,提出了如何从SFC生成白名单以及如何通过白名单检测异常操作的方法。我们将基于SFC的方法称为基于模型的白名单,将基于Petri Net的方法称为基于模型的检测。此外,本文使用基于OpenPLC的测试平台系统对算法进行了实验验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号