4.7 Article

A Unified Architectural Approach for Cyberattack-Resilient Industrial Control Systems

期刊

PROCEEDINGS OF THE IEEE
卷 109, 期 4, 页码 517-541

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/JPROC.2020.3034595

关键词

Security; Integrated circuits; Computer security; Cyberattack; Process control; Systematics; Resilience; Fourth Industrial Revolution; Networked control systems; Cybersecurity; industrial control system (ICS); network; process; resilience; system

资金

  1. National Natural Science Foundation of China [61433006, 61873103, 61272204]
  2. National Key R&D Program of China [2019YFB2006300]
  3. Australian Research Council (ARC) [DP160102571, DP170103305]

向作者/读者索取更多资源

This article presents a global and systematic architectural approach for industrial control system cybersecurity to address the threats posed by cyberattacks on ICSs. Through the integration of secure networks, secure control systems, and secure physical processes, layer-by-layer defense is implemented to enhance the network security risk management level of ICSs.
With the rapid development of functional requirements in the emerging Industry 4.0 era, modern industrial control systems (ICSs) are no longer isolated islands, making them more vulnerable to various cyberattack threats. Cyberattacks on ICSs may have disruptive consequences, such as significant social and economic losses. To proactively address the security issue of ICSs, this article presents a unified architectural approach from the perspectives of cyberthreats on ICSs, security-related ICS technologies, and methods for ICSs. It incorporates secure networks, secure control systems, secure physical processes, and their interactions seamlessly into a unified framework. To increase the resistance of ICSs against intrusions, the network security in our architectural approach is to secure the data in motion through the integration of secure network architecture, secure industrial network protocols, and secure end-to-end communications. The protection of control systems in our architectural approach is risk-based and hierarchical and encompasses prevention- and tolerance-centric defenses. It provides a layer-by-layer defense so that an acceptable level of cybersecurity risk is achieved and maintained. Aiming to maintain the stable operation of physical ICS processes, the secure control in our architectural approach implements a security process against process-aware attacks through a resilient safety control scheme. The global and systematic architectural approach presented in this article for the ICS cybersecurity will help facilitate the design and implementation of cyberattack-resilient ICSs in the networked world. For further development of ICS security technologies, emerging challenges are identified and discussed to motivate future research efforts.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据