Performance impact of commercial industrial firewalls on networked control systems

作者: Manuel Cheminod , Luca Durante , Adriano Valenzano , Claudio Zunino

DOI: 10.1109/ETFA.2016.7733576

关键词:

摘要: The connection of control and process networks to company infrastructures the Internet, besides offering undeniable advantages, also imposes adoption adequate security countermeasures. Specialized firewalls, able recognize inspect traffic concerning peculiar communication protocols such as Modbus, which are commonly adopted in industrial applications, beginning spread on market. However, several systems (ICSs) must satisfy critical performance timing requirements impact introducing a kind devices an existing network should be evaluated carefully. In this paper we present simple approach based ordinary equipment open source software, can help system designers managers get approximate but useful information about effects produced by including firewall their system. proposed technique, though quite simple, has advantage circumventing need ad-hoc measurement instrumentation used non-experts, virtually with little or no effort, rough guess indications extent insertion tolerated.

参考文章(7)
Artemios G. Voyiatzis, Konstantinos Katsigiannis, Stavros Koubias, A Modbus/TCP Fuzzer for testing internetworked industrial systems 2015 IEEE 20th Conference on Emerging Technologies & Factory Automation (ETFA). pp. 1- 6 ,(2015) , 10.1109/ETFA.2015.7301400
Manuel Cheminod, Luca Durante, Adriano Valenzano, Review of Security Issues in Industrial Networks IEEE Transactions on Industrial Informatics. ,vol. 9, pp. 277- 293 ,(2013) , 10.1109/TII.2012.2198666
Peter Huitsing, Rodrigo Chandia, Mauricio Papa, Sujeet Shenoi, Attack taxonomies for the Modbus protocols International Journal of Critical Infrastructure Protection. ,vol. 1, pp. 37- 44 ,(2008) , 10.1016/J.IJCIP.2008.08.003
Achim D. Brucker, Lukas Brügger, Burkhart Wolff, Formal firewall conformance testing: an application of test and proof techniques Software Testing, Verification and Reliability. ,vol. 25, pp. 34- 71 ,(2015) , 10.1002/STVR.1544
K. Salah, K. Elbadawi, R. Boutaba, Performance Modeling and Analysis of Network Firewalls IEEE Transactions on Network and Service Management. ,vol. 9, pp. 12- 21 ,(2012) , 10.1109/TNSM.2011.122011.110151
JeeHyun Hwang, Tao Xie, Fei Chen, Alex X. Liu, Systematic Structural Testing of Firewall Policies IEEE Transactions on Network and Service Management. ,vol. 9, pp. 1- 11 ,(2012) , 10.1109/TNSM.2012.012012.100092
Marco Cereia, Ivan Cibrario Bertolotti, Luca Durante, Adriano Valenzano, Latency evaluation of a firewall for industrial networks based on the Tofino Industrial Security Solution Proceedings of the 2014 IEEE Emerging Technology and Factory Automation (ETFA). pp. 1- 8 ,(2014) , 10.1109/ETFA.2014.7005177