Engineering Secure Software and Systems

Engineering Secure Software and Systems
复制标题

工程安全软件和系统

DOI:
10.1007/978-3-319-62105-0_3
复制
发表时间:
2017
期刊:
--
影响因子:
--
通讯作者:
Le A
Le A
中科院分区:
--
文献类型:
--
作者:
Le A

文献摘要

被引文献

相似文献

许多运行工业控制系统(ICSS)是在多年前设计和部署的,很少或根本没有考虑到相互关联的世界所产生的安全问题。众所周知,攻击者可以从可编程逻辑控制器(PLC)读取和写入传感器和执行器数据,因为传统的IC提供的保护手段很少。更换这种传统的ICS成本高昂,需要广泛的规划和一项通常跨越几年的重大更新计划。然而,用已建立的安全机制来增强已部署的ICS几乎是不可能的。传统PLC不能在保持实时控制的同时支持计算昂贵的(即,密码)操作。入侵检测系统(入侵检测系统)已经被用来提高传统IC的安全性。然而,攻击者可以通过从观察到的数据学习可接受的系统行为来避免被检测到。在本文中,我们提出了Lasarus,这是一个轻量级的方法,可以在传统PLC上实现,以减少它们的攻击面,使攻击者更难学习系统行为和策划有用的攻击。我们的方法包括在PLC数据被存储或访问时对其进行模糊处理,这会导致目标曲面的连续变化。模糊密钥可以根据威胁情况进行刷新,从而在系统性能和保护级别之间取得平衡。使用真实世界和模拟ICS数据集,我们证明了Lasarus能够通过显著降低通过率-高达100倍-来阻止一系列众所周知的攻击,如随机或重放注入。
Many operational Industrial Control Systems (ICSs) were designed and deployed years ago with little or no consideration of security issues arising from an interconnected world. It is well-known that attackers can read and write sensor and actuator data from Programmable Logic Controllers (PLCs) as legacy ICS offer little means of protection. Replacing such legacy ICS is expensive, requires extensive planning and a major programme of updates often spanning several years. Yet augmenting deployed ICS with established security mechanisms is rarely possible. Legacy PLCs cannot support computationally expensive (i.e., cryptographic) operations while maintaining real-time control. Intrusion Detection Systems (IDSs) have been employed to improve security of legacy ICS. However, attackers can avoid detection by learning acceptable system behaviour from observed data. In this paper, we present LASARUS, a lightweight approach that can be implemented on legacy PLCs to reduce their attack surface, making it harder for an attacker to learn system behaviour and craft useful attacks. Our approach involves applying obfuscation to PLC data whenever it is stored or accessed which leads to a continuous change of the target surface. Obfuscation keys can be refreshed depending on the threat situation, striking a balance between system performance and protection level. Using real-world and simulated ICS data sets, we demonstrate that LASARUS is able to prevent a set of well-known attacks like random or replay injection, by reducing their passing rate significantly—up to a 100 times.