首页> 外文会议>IFIP Working Group 11.10 International Conference on Critical Infrastructure Protection >MODELING AND MACHINE-CHECKING BUMP-IN-THE-WIRE SECURITY FOR INDUSTRIAL CONTROL SYSTEMS
【24h】

MODELING AND MACHINE-CHECKING BUMP-IN-THE-WIRE SECURITY FOR INDUSTRIAL CONTROL SYSTEMS

机译:工业控制系统的建模与机器检查碰到电线安全性

获取原文

摘要

This chapter describes the formal modeling and machine-checking of a bump-in-the-wire device that secures field device communications in industrial control networks. Field devices serve as the connection points between computer-based control systems and the physical processes being controlled. Industrial control network traffic is routinely checked for transmission errors, but limited mechanisms are available for combating attacks that exploit industrial control protocols to target critical infrastructure assets. This chapter focuses on a bump-in-the-wire solution that can be retrofitted on field devices to provide security functionality. The TLA+ formal specification language in combination with the isolation guarantees provided by the seL4 microkernel are used to demonstrate that the bump-in-the-wire solution provides important security and liveness properties. The resulting machine-checked system correctly applies hash-based message authentication to verify the authenticity of incoming messages while being resistant to attacks.
机译:本章介绍了在工业控制网络中保护现场设备通信的颠簸内设备的正式建模和机器检查。现场设备用作基于计算机的控制系统和被控制的物理过程之间的连接点。工业控制网络流量经常检查传输错误,但有限的机制可用于打击利用工业控制协议以针对关键基础设施资产的攻击。本章重点介绍了在现场设备上进行改装的碰到电线解决方案,以提供安全功能。 TLA +正式规范语言与SEL4 Microkernel提供的隔​​离保证结合使用用于证明碰到导线解决方案提供了重要的安全性和活力属性。生成的机器检查系统正确地应用基于哈希的消息认证,以验证传入消息的真实性,同时抵抗攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号