Cargando…

Control systems under attack?

The enormous growth of the Internet during the last decade offers new means to share and distribute both information and data. In Industry, this results in a rapprochement of the production facilities, i.e. their Process Control and Automation Systems, and the data warehouses. At CERN, the Internet...

Descripción completa

Detalles Bibliográficos
Autor principal: Lüders, Stefan
Lenguaje:eng
Publicado: 2005
Materias:
Acceso en línea:http://cds.cern.ch/record/906638
_version_ 1780908794705870848
author Lüders, Stefan
author_facet Lüders, Stefan
author_sort Lüders, Stefan
collection CERN
description The enormous growth of the Internet during the last decade offers new means to share and distribute both information and data. In Industry, this results in a rapprochement of the production facilities, i.e. their Process Control and Automation Systems, and the data warehouses. At CERN, the Internet opens the possibility to monitor and even control (parts of) the LHC and its four experiments remotely from anywhere in the world. However, the adoption of standard IT technologies to Distributed Process Control and Automation Systems exposes inherent vulnerabilities to the world. The Teststand On Control System Security at CERN (TOCSSiC) is dedicated to explore the vulnerabilities of arbitrary Commercial-Of-The-Shelf hardware devices connected to standard Ethernet. As such, TOCSSiC should discover their vulnerabilities, point out areas of lack of security, and address areas of improvement which can then be confidentially communicated to manufacturers. This paper points out risks of accessing the Control and Automation Systems in an unprotected manner over the standard Ethernet, presents the TOCSSiC and its findings, and finally discusses methods for protective measures.
id cern-906638
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2005
record_format invenio
spelling cern-9066382019-09-30T06:29:59Zhttp://cds.cern.ch/record/906638engLüders, StefanControl systems under attack?Detectors and Experimental TechniquesThe enormous growth of the Internet during the last decade offers new means to share and distribute both information and data. In Industry, this results in a rapprochement of the production facilities, i.e. their Process Control and Automation Systems, and the data warehouses. At CERN, the Internet opens the possibility to monitor and even control (parts of) the LHC and its four experiments remotely from anywhere in the world. However, the adoption of standard IT technologies to Distributed Process Control and Automation Systems exposes inherent vulnerabilities to the world. The Teststand On Control System Security at CERN (TOCSSiC) is dedicated to explore the vulnerabilities of arbitrary Commercial-Of-The-Shelf hardware devices connected to standard Ethernet. As such, TOCSSiC should discover their vulnerabilities, point out areas of lack of security, and address areas of improvement which can then be confidentially communicated to manufacturers. This paper points out risks of accessing the Control and Automation Systems in an unprotected manner over the standard Ethernet, presents the TOCSSiC and its findings, and finally discusses methods for protective measures.CERN-OPEN-2005-025oai:cds.cern.ch:9066382005-10-11
spellingShingle Detectors and Experimental Techniques
Lüders, Stefan
Control systems under attack?
title Control systems under attack?
title_full Control systems under attack?
title_fullStr Control systems under attack?
title_full_unstemmed Control systems under attack?
title_short Control systems under attack?
title_sort control systems under attack?
topic Detectors and Experimental Techniques
url http://cds.cern.ch/record/906638
work_keys_str_mv AT ludersstefan controlsystemsunderattack