...
首页> 外文期刊>Procedia Computer Science >Smart Factory Security: A Case Study on a Modular Smart Manufacturing System
【24h】

Smart Factory Security: A Case Study on a Modular Smart Manufacturing System

机译:智能工厂安全:模块化智能制造系统的案例研究

获取原文
           

摘要

Smart manufacturing systems are an attractive target for cyber attacks, because they embed valuable data and critical equipment. Despite the market is driving towards integrated and interconnected factories, current smart manufacturing systems are still designed under the assumption that they will stay isolated from the corporate network and the outside world. This choice may result in an internal architecture with insufficient network and system compartmentalization. As a result, once an attacker has gained access, they have full control of the entire production plant because of the lack of network segmentation.With the goal of raising cybersecurity awareness, in this paper we describe a practical case study showing attack scenarios that we have validated on a real modular smart manufacturing system, and suggest practical security counter measures. The testbed smart manufacturing system is part of the Industry 4.0 research laboratory hosted by Politecnico di Milano, and comprises seven assembly stations, each with their programmable logic controllers and human-computer interfaces, as well as an industrial robotic arm that performs pick-and-place tasks.On this testbed we show two indirect attacks to gain initial access, even under the best-case scenario of a system not directly connected to any public network. We conclude by showing two post-exploitation scenarios that an adversary can use to cause physical impact on the production, or keep persistent access to the plant.We are unaware of a similar security analysis performed within the premises of a research facility, following a scientific methodology, so we believe that this work can represent a good first step to inspire follow up research on the many verticals that we touch.
机译:智能制造系统是一个有吸引力的网络攻击目标,因为它们嵌入了有价值的数据和关键设备。尽管市场正在驾驶综合和相互连接的工厂,但目前的智能制造系统仍然是在假设中,他们将停留从公司网络和外界的隔离。此选择可能导致内部架构,网络和系统划分的不足。因此,一旦攻击者获得了访问,他们就可以完全控制整个生产工厂,因为缺乏网络分割。在提高网络安全意识的目的,在本文中,我们描述了一个实用的案例研究,显示了我们的攻击情景在真正的模块化智能制造系统上验证,并提出了实用的安全计数措施。测试平智智能制造系统是由PoliteCnico di Milano主办的行业4.0研究实验室的一部分,包括七个装配站,每个组装站都有可编程逻辑控制器和人机接口,以及执行挑选的工业机器人臂,以及将Tasks.on此测试平台显示两个间接攻击以获得初始访问,即使在没有直接连接到任何公共网络的系统的最佳情况下也是如此。我们通过显示对手可以使用对生产产生身体影响的两种开发后情景,或者保持对工厂的持久访问。我们不知道在科学的研究机构的房屋内执行的类似安全分析方法论,所以我们认为这项工作可以代表一个良好的第一步,以鼓励我们触及的许多垂直垂直研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号