...
首页> 外文期刊>Journal of Industrial Engineering and Management >Software defined networking firewall for industry 4.0 manufacturing systems
【24h】

Software defined networking firewall for industry 4.0 manufacturing systems

机译:适用于工业4.0制造系统的软件定义的网络防火墙

获取原文
           

摘要

Purpose: In order to leverage automation control data, Industry 4.0 manufacturing systems require industrial devices to be connected to the network. Potentially, this can increase the risk of cyberattacks, which can compromise connected industrial devices to acquire production data or gain control over the production process. Search engines such as Sentient Hyper-Optimized Data Access Network (SHODAN) can be perverted by attackers to acquire network information that can be later used for intrusion. To prevent this, cybersecurity standards propose network architectures divided into several networks segments based on system functionalities. In this architecture, Firewalls limit the exposure of industrial control devices in order to minimize security risks. This paper presents a novel Software Defined Networking (SDN) Firewall that automatically applies this standard architecture without compromising network flexibility. Design/methodology/approach: The proposed SDN Firewall changes filtering rules in order to implement the different network segments according to application level access control policies. The Firewall applies two filtering techniques described in this paper: temporal filtering and spatial filtering, so that only applications in a white list can connect to industrial control devices. Network administrators need only to configure this application-oriented white lists to comply with security standards for ICS. This simplifies to a great extent network management tasks. Authors have developed a prototype implementation based on the OPC UA Standard and conducted security tests in order to test the viability of the proposal.Findings: Network segmentation and segregation are effective counter-measures against network scanning attacks. The proposed SDN Firewall effectively configures a flat network into virtual LAN segments according to security standard guidelines.Research limitations/implications: The prototype implementation still needs to implement several features to exploit the full potential of the proposal. Next steps for development are discussed in a separate section.Practical implications: The proposed SDN Firewall has similar security features to commercially available application Firewalls, but SDN Firewalls offer additional security features. First, SDN technology provides improved performance, since SDN low-level processing functions are much more efficient. Second, with SDN, security functions are rooted in the network instead of being centralized in particular network elements. Finally, SDN provides a more flexible and dynamic, zero configuration framework for secure manufacturing systems by automating the rollout of security standard-based network architectures. Social implications: SDN Firewalls can facilitate the deployment of secure Industry 4.0 manufacturing systems, since they provide ICS networks with many of the needed security capabilities without compromising flexibility.?Originality/value: The paper proposes a novel SDN Firewall specifically designed to secure ICS networks. A prototype implementation of the proposed SDN Firewall has been tested in laboratory conditions. The prototype implementation complements the security features of the OPC UA communication standard to provide a holistic security framework for ICS networks.
机译:目的:为了利用自动化控制数据,工业4.0制造系统要求将工业设备连接到网络。潜在地,这可能会增加网络攻击的风险,这可能会损害相连的工业设备以获取生产数据或获得对生产过程的控制权。诸如Sentient超优化数据访问网络(SHODAN)之类的搜索引擎可能会受到攻击者的攻击,以获取网络信息,这些信息随后可用于入侵。为防止这种情况,网络安全标准提出了基于系统功能将网络架构分为几个网络段的建议。在这种体系结构中,防火墙限制了工业控制设备的暴露,以最大程度地降低安全风险。本文提出了一种新颖的软件定义网络(SDN)防火墙,该防火墙自动应用此标准体系结构而不会损害网络灵活性。设计/方法/方法:建议的SDN防火墙更改过滤规则,以便根据应用程序级别的访问控制策略实现不同的网段。防火墙应用了本文描述的两种过滤技术:时间过滤和空间过滤,因此只有白名单中的应用程序才能连接到工业控制设备。网络管理员只需配置此面向应用程序的白名单即可符合ICS的安全标准。这在很大程度上简化了网络管理任务。作者开发了基于OPC UA标准的原型实现,并进行了安全性测试,以测试该提案的可行性。发现:网络分段和隔离是针对网络扫描攻击的有效对策。拟议中的SDN防火墙根据安全标准指南将平面网络有效地配置为虚拟LAN网段。研究限制/启示:原型实现仍需要实现若干功能,以充分利用建议的全部潜力。下一步将在单独的部分中讨论开发。实际意义:建议的SDN防火墙具有与市售应用程序防火墙类似的安全性功能,但是SDN防火墙提供了其他安全性功能。首先,由于SDN低级处理功能效率更高,因此SDN技术可提高性能。其次,借助SDN,安全功能植根于网络,而不是集中在特定的网络元素中。最终,SDN通过自动化基于安全标准的网络架构的推出,为安全制造系统提供了更灵活,动态,零配置的框架。社会意义:SDN防火墙可以为安全的Industry 4.0制造系统提供部署,因为它们为ICS网络提供了许多必需的安全功能,而又不损害灵活性。原创性/价值:本文提出了一种专为保护ICS网络而设计的新型SDN防火墙。 。建议的SDN防火墙的原型实现已在实验室条件下进行了测试。原型实施对OPC UA通信标准的安全功能进行了补充,为ICS网络提供了整体安全框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号