skip to main content
US FlagAn official website of the United States government
dot gov icon
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
https lock icon
Secure .gov websites use HTTPS
A lock ( lock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


Title: Towards a High-Fidelity Network Emulation of IEC 104 SCADA Systems
With the rise of malware targeting industrial control systems, researchers need more tools to develop a better understanding of the networks under attack, the potential behavior of malware, and design possible defenses. One of the most important protocols used in practice today is IEC 104, which is used to monitor and control the Power Grid of several countries, as well as to monitor and control other critical infrastructures such as gas, oil, and water systems. In this paper, we present our preliminary results in implementing the IEC 104 industrial protocol standard in Python and integrate it into a network emulation tool supported by Mininet.  more » « less
Award ID(s):
1929406
PAR ID:
10201022
Author(s) / Creator(s):
; ; ;
Date Published:
Journal Name:
CPSIOTSEC'20: Proceedings of the 2020 Joint Workshop on CPS&IoT Security and Privacy
Page Range / eLocation ID:
3 to 12
Format(s):
Medium: X
Sponsoring Org:
National Science Foundation
More Like this
  1. Programmable Logic Controllers are an established platform used throughout industrial automation, but rather poorly understood among researchers in the control systems community. This paper gives an overview of the state of the practice in industrial control systems while presenting a critical analysis of the dominant programming styles used in today's automation systems. We describe the patterns standardized loosely in IEC 61131-3 and, where there are ambiguities in the standard, realized in concrete vendor implementations. Ultimately, we suggest directions for further research towards enabling increasingly complex industrial control applications subject to the novel requirements of Industry 4.0 settings without compromising the safety and reliability guaranteed by the current industrial automation stack. 
    more » « less
  2. Interlayer exchange coupling (IEC) has been intensively investigated in magnetic multilayers, owing to its potential for magnetic memory and logic device applications. Although IEC can be reliably obtained in metallic ferromagnetic multilayer systems by adjusting structural parameters, it is difficult to achieve gate control of IEC in metallic systems due to their large carrier densities. Here, we demonstrate that IEC can be reliably controlled in ferromagnetic semiconductor (FMS) trilayer structures by means of an external gate voltage. We show that, by designing a quantum-well-type trilayer structure based on (Ga,Mn)(As,P) FMSs and adapting the ionic liquid gating technique, the carrier density in the nonmagnetic spacer of the system can be modulated with gate voltages of only a few volts. Due to this capability, we are able to vary the strength of IEC by as much as 49% in the FMS trilayer. These results provide important insights into design of spintronic devices and their energy-efficient operation. 
    more » « less
  3. Programmable Logic Controllers (PLCs) are an established platform, widely used throughout industrial automation but poorly understood among researchers. This paper gives an overview of the state of the practice, explaining why this settled technology persists throughout industry and presenting a critical analysis of the strengths and weaknesses of the dominant programming styles for today's PLC-based automation systems. We describe the software execution patterns that are standardized loosely in IEC 61131-3. We identify opportunities for improvements that would enable increasingly complex industrial automation applications while strengthening safety and reliability. Specifically, we propose deterministic, distributed programming models that embrace explicit timing, event-triggered computation, and improved security. 
    more » « less
  4. With the introduction of Cyber-Physical Systems (CPS) and Internet of Things (IoT) technologies, the automation industry is undergoing significant changes, particularly in improving production efficiency and reducing maintenance costs. Industrial automation applications often need to transmit time- and safety-critical data to closely monitor and control industrial processes. Several Ethernet-based fieldbus solutions, such as PROFINET IRT, EtherNet/IP, and EtherCAT, are widely used to ensure real-time communications in industrial automation systems. These solutions, however, commonly incorporate additional mechanisms to provide latency guarantees, making their interoperability a grand challenge. The IEEE 802.1 Time-Sensitive Networking (TSN) task group was formed to enhance and optimize IEEE 802.1 network standards, particularly for Ethernet-based networks. These solutions can be evolved and adapted for cross-industry scenarios, such as large-scale distributed industrial plants requiring multiple industrial entities to work collaboratively. This paper provides a comprehensive review of current advances in TSN standards for industrial automation. It presents the state-of-the-art IEEE TSN standards and discusses the opportunities and challenges of integrating TSN into the automation industry. Some promising research directions are also highlighted for applying TSN technologies to industrial automation applications. 
    more » « less
  5. Sugunaraj, Niroop (Ed.)
    Abstract—The recent increase in attacks against publicly networked industrial control systems (ICS) has demonstrated a need for network-based anomaly detection systems, offering realtime flagging of potentially malicious activity by internal and external threat actors. Fuzzy hashing, also known as similarity hashing, has gained popularity in malware analysis and digital forensics circles as it provides analysts functionality to determine the similarity of two pieces of data by providing a similarity score. This work proposes a scheme that utilizes the similarity score to find variations from a self-establishing baseline in an ICS network to identify anomalous network traffic sections that could signify malicious activity. 
    more » « less