Dynamic Defense Methods for Endogenously Secure Industrial Control Networks

Tianyou Yun, Jun Luo, Bo Peng, Daojian Yao · 2018

The security defense problem shows a great significance in industrial networks for the existence of security risks. However traditional defense methods reveal technical limitations. To address this issue, a dynamic defense method with the characteristic of endogenous security is proposed in this paper. The main idea is to establish a multi-mode, dynamic and transparent security-specific channel between controlled devices, by utilizing the reconstruction of IP packet and the random change of security elements such as encryption algorithms, keys and authentication passwords, so as to form an endogenously secure industrial control network system. This method is further implemented by FPGA hardware, such that the performances of real-time and security of the control network are both guaranteed. Experimental results show that the proposed method can effectively prevent typical security risks such as unauthorized accesses, middle-man attacks and replay attacks from the network, changing the passive defense as the active defense and changing the boundary security into endogenous security.

Read the paper · More papers on PaperTik