Get 20M+ Full-Text Papers For Less Than $1.50/day. Start a 14-Day Trial for You or Your Team.

Learn More →

Simulation Implementation and Verification of a Security Framework for ICS Based on SPD

Simulation Implementation and Verification of a Security Framework for ICS Based on SPD Integration of IT and OT blurs the concept of “network perimeter”. This will result in increasing the attack surface in industrial control system (ICS). Zero trust architecture (ZTA) has become a new and alternative network security model to protect an enterprise network. The software-defined perimeter (SDP) is an instance that implemented the concept of ZTA. In this paper, a security framework SDPICS for ICS based on SDP is firstly proposed. In contrast with of security policy based on the perimeter defense security model, SDPICS will not grant implicit trust to any user or device based on their location in the network. In addition, the existing ICS simulation platforms don’t support the idea of SDP. This paper extends the network simulation tool Mininet to design a new ICS simulation platform MiniICS that can support our security framework SDPICS. The simulation modules for ICS and SDP components are implemented in MiniICS. Finally, our security framework SDPICS is tested by performing these popular attacks such as DDoS and etc. in MiniICS. The experimental results show the reliability and availability of the novel security framework SDPICS. http://www.deepdyve.com/assets/images/DeepDyve-Logo-lg.png Automatic Control and Computer Sciences Springer Journals

Simulation Implementation and Verification of a Security Framework for ICS Based on SPD

Loading next page...
 
/lp/springer-journals/simulation-implementation-and-verification-of-a-security-framework-for-uzi24rjYlT

References (17)

Publisher
Springer Journals
Copyright
Copyright © Allerton Press, Inc. 2023. ISSN 0146-4116, Automatic Control and Computer Sciences, 2023, Vol. 57, No. 1, pp. 37–47. © Allerton Press, Inc., 2023.
ISSN
0146-4116
eISSN
1558-108X
DOI
10.3103/s0146411623010042
Publisher site
See Article on Publisher Site

Abstract

Integration of IT and OT blurs the concept of “network perimeter”. This will result in increasing the attack surface in industrial control system (ICS). Zero trust architecture (ZTA) has become a new and alternative network security model to protect an enterprise network. The software-defined perimeter (SDP) is an instance that implemented the concept of ZTA. In this paper, a security framework SDPICS for ICS based on SDP is firstly proposed. In contrast with of security policy based on the perimeter defense security model, SDPICS will not grant implicit trust to any user or device based on their location in the network. In addition, the existing ICS simulation platforms don’t support the idea of SDP. This paper extends the network simulation tool Mininet to design a new ICS simulation platform MiniICS that can support our security framework SDPICS. The simulation modules for ICS and SDP components are implemented in MiniICS. Finally, our security framework SDPICS is tested by performing these popular attacks such as DDoS and etc. in MiniICS. The experimental results show the reliability and availability of the novel security framework SDPICS.

Journal

Automatic Control and Computer SciencesSpringer Journals

Published: Feb 1, 2023

Keywords: cybersecurity; industrial control system; zero trust architecture; software defined perimeter (SDP)

There are no references for this article.