skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Feasibility of critical infrastructure protection using network functions for programmable and decoupled ICS policy enforcement over WAN

Journal Article · · International Journal of Critical Infrastructure Protection

Industrial control systems (ICS) represent a major component of our critical infrastructure. With the increasing need for more control and monitoring of such systems, ICS have seen an increase in connectivity to wide area networks (WAN) exposing aging equipment to rapidly evolving cybersecurity threats. Furthermore, the ICS data requires a reliability measure from the networks for critical functions for infrastructure monitoring and control. Especially when remote plant sites are involved such as pipelines, energy distribution networks, and transportation, WAN transport impairments most often provide a best effort delivery with no strict reliability guarantees. Network functions can provide a vendor agnostic, programmable critical infrastructure protection with a single maintenance, policy determination, and reliability assurance surface. A network function (NF) can be utilized for policy enforcement over the communication between remote entities and the main control office. This paper presents the research on transparent integration with existing ICS without disrupting communications, resulting in minimal downtime while decoupling the fast paced evolution of defensive security measures from the upgrade cycle of expensive long term hardware. We report our measurements on the resource requirements and overhead in the network for successful NF insertion under a wide variety of network impairments (network packet delay, reordering, and loss). Our paired NF implementation provides a policy enforcement platform extensible to cover myriad cybersecurity-related communication goals, including packet signing for verification, encryption for data privacy, packet filtering and data diode operation (i.e. protecting against eavesdropping, packet injection, and denial-of-service). Furthermore, bundling communication specifications into packet flows allows for tunability in applying policies as coarse- or fine-grained as the needs of the operator. We report on network function resource requirements in the form of required queue depth and network utilization overhead to inform the decision making against hardware cost constraints.

Research Organization:
Univ. of Houston, TX (United States)
Sponsoring Organization:
USDOE Office of Electricity (OE)
Grant/Contract Number:
OE0000780
OSTI ID:
1897182
Alternate ID(s):
OSTI ID: 1900049
Journal Information:
International Journal of Critical Infrastructure Protection, Vol. 39; ISSN 1874-5482
Publisher:
ElsevierCopyright Statement
Country of Publication:
United States
Language:
English

References (11)

Assessing the impacts of IPsec cryptographic algorithms on a virtual network embedding problem journal October 2018
Review of cybersecurity issues in industrial critical infrastructure: manufacturing in perspective journal November 2016
The Cybersecurity Landscape in Industrial Control Systems journal May 2016
The performance of TCP/IP for networks with high bandwidth-delay products and random loss journal June 1997
Experimental assessment of network design approaches for protecting industrial control systems journal December 2015
How network asymmetry affects TCP journal April 2001
An Overview of Packet Reordering in Transmission Control Protocol (TCP): Problems, Solutions, and Challenges journal April 2007
Industrial control protocols in the Internet core: Dismantling operational practices journal April 2021
Resilient Control under Denial-of-Service journal January 2014
Presto journal September 2015
SCADA and IP is network convergence readlly here? journal March 2003

Similar Records

Autonomous Tools for Attack Surface Reduction (Final Report)
Technical Report · Mon Mar 01 00:00:00 EST 2021 · OSTI ID:1897182

Maintenance of Maywood Laboratory Operations Support During Contractor Transition and Replacement of the Project Databases - 16329
Conference · Fri Jul 01 00:00:00 EDT 2016 · OSTI ID:1897182

SDN Project
Technical Report · Fri Dec 23 00:00:00 EST 2016 · OSTI ID:1897182