The security of industrial computer finds the intersection of information security and industrial control

Jan 03, 2022

Leave a message

The development of information security technology of industrial computer control system is constantly evolving with the development of industrial automation system. The current trend of automation system development is digitization, intelligence, networking and human-computer interaction, and at the same time, more IT technology is applied to traditional logic control and digital control. In the future, the information security technology of industrial control system will further rely on traditional IT technology to make it more intelligent and networked and become an indispensable part of the control system. Similar to the information security product R&D route of the traditional IP Internet, the industrial control system information security products will find a convergence point between information security and industrial production control, forming a product system with distinctive features of the industrial control system of safe input, security control, and safe output. .
Industrial control security takes into account functional, physical and information security
Usually, industrial control system security can be divided into three aspects, namely functional security, physical security and information security.

Functional safety is that in order to achieve equipment and plant safety functions, the safety-related parts of the protected and controlling equipment must perform their functions correctly, and when a failure or malfunction occurs, the equipment or system must still maintain a safe condition or enter a safe state .

Physical safety is the reduction of hazards caused by factors such as electric shock, fire, radiation, mechanical hazards, and chemical hazards.

The definition of information security for industrial control systems in IEC 62443 is: "The measures taken to protect the system; the system state obtained by establishing and maintaining the measures to protect the system; the ability to be free from unauthorized access to system resources and unauthorized or accidental change, destruction or loss; based on the ability of the computer system, it can ensure that unauthorized personnel and systems can neither modify the software and its data, nor access system functions, but ensure that authorized personnel and systems are not blocked; prevent access to industrial control systems Unlawful or harmful intrusion, or interference with its proper and planned operation."

The definitions and connotations of the three types of security are quite different.
Functional Safety, the concept of Safety Integrity Levels has been used for almost 20 years. Functional safety specifications require that the safety of a component or system is usually expressed as a single number, and this number is a protection factor based on the failure rate of the component or system proposed to protect human health, production safety, and environmental safety.

Physical security, protection elements are mainly defined by a series of safety production operation specifications. Governments, enterprises and industry organizations generally restrict the standardization of on-site operation of industrial systems through complete safety production operation procedures, ensure the traceability of accidents, and clarify the responsibilities of relevant personnel. Management and institutional factors are the main ways to protect physical security. .

The evaluation method of industrial control system information security is different from the evaluation of functional safety. Although they are all to protect personnel health, production safety or environmental safety, the functional safety use safety integrity level is calculated based on the possibility of random hardware failure of a component or system failure, and information security systems have a wider range of applications. , and many more possible causes and consequences. The factors that affect information security are very complex and difficult to describe with a simple number. However, the full life cycle security concept of functional safety is also applicable to information security, and the management and maintenance of information security must also be carried out in cycles.

The difference between industrial control security and network information security

The differences between industrial control system information security and traditional IP information network security are: 1. Different security requirements, 2. Differences between security patches and upgrade mechanisms, 3. Differences in real-time performance, and 4. Differences in security protection priorities , 5. Differences in the adaptability of security protection technology.

In general, traditional IP information network security has developed into relatively mature technologies and design principles (authentication, access control, information integrity, privilege separation, etc.), which can help us prevent and respond to attacks against industrial control systems. Traditionally, however, computer information security research focuses on the protection of information, and researchers do not consider how an attack affects evaluation and control algorithms and ultimately how an attack affects the physical world.

Various existing information security tools can provide necessary mechanisms for the security of control systems. These individual mechanisms are not enough for deep protection control. By deeply understanding the interaction process between control systems and the real physical world, researchers need to develop in the future The job might be:

1. Better understanding of the consequences of an attack: So far, there has been no in-depth study of the harm that an attacker can cause if they gain unauthorized access to some controlled network device.

2. Design a new attack detection algorithm: By understanding the control behavior of the physical process, and based on process control commands and sensor measurements, it is possible to identify whether an attacker is trying to interfere with control or sensor data.

3. Design a new anti-attack resilience algorithm and architecture: When an industrial control system attack behavior is detected, the control command can be changed in time to increase the resilience of the control system and reduce losses.

4. Design the identity authentication and password technology suitable for the field equipment of the industrial SCADA system: At present, some mature, complex and robust password technology usually cannot complete the access control function in the field equipment of the industrial control system. The main reason is that the password is too complex Mechanisms may run the risk of hampering the rapid response of emergency procedures in an emergency. Experts in the field of industrial automatic control generally believe that relatively weak password mechanisms (such as default passwords, fixed passwords, and even empty passwords, etc.) are easier to guess, transmit, etc. additional impact.

5. Develop industrial SCADA system security protection technologies with stronger hardware compatibility: technologies with strong security protection capabilities in traditional IT data networks, such as identity authentication, authentication, encryption, intrusion detection and access control technologies, generally emphasize the occupation of more networks Bandwidth, processor performance, and memory resources, which are very limited in industrial control system equipment, which were originally designed to perform specific field tasks, are generally low-cost, low-processor devices. Moreover, some very outdated processors (such as the Intel 8088 processor manufactured in 1978) are still used in the control devices of energy industrial systems such as petroleum and water supply. Therefore, it is difficult to deploy mainstream information security protection technologies in such devices without significantly degrading the performance of industrial field control devices.

6. Develop security protection technologies compatible with multiple operating systems or software platforms: Information security technology mechanisms in traditional IT data networks, mainly to solve information security issues on general-purpose operating system platforms such as Windows, Linux, and Unix. In the field of industrial SCADA systems, on-site industrial SCADA system devices generally use non-public operating systems (sometimes called firmware), dedicated software platforms (such as GE, etc.) independently developed by equipment suppliers (ABB, Siemens, Honeywell, etc.). iFix, etc.) to complete specific industrial process control functions. Therefore, how to develop, deploy and even upgrade information security protection technologies on non-universal operating systems and software platforms is a key issue that needs to be solved in the future of industrial SCADA system information security.

Establish a pre-event, in-event and post-event protection system

The connotation, requirements and target characteristics of industrial control system information security determine the need for some special information security technologies and measures. In the industrial production process, IEDs, PLCs, RTUs, controllers, communication processors, SCADA systems and various practical , Used or configured in various types of programmable digital equipment to achieve the security function goal of ensuring the production, control and management of industrial control systems. The basic technology of information security of all automatic control systems is access control and user identity authentication. On this basis, some technologies are developed to protect the security of communication data packets by means of probes, channel encryption, data packet verification and authentication. In order to realize the information security of the industrial control system under the premise of functional safety, it is necessary to build a comprehensive management and overall security protection technology system for the information security of the industrial control system before, during and after the event.

1. Advance defense technology
Pre-defense technology is an important part of the industrial control information security protection technology system. At present, there are many mature basic technologies that can be used: access control/industrial control dedicated firewall, identity authentication, ID equipment, biometric-based identification technology, secure Modems, encryption technology, public key infrastructure (PKI), virtual local area network (VPN).

2. Response technology in the event
Intrusion Detection (IDS) technology is very effective in identifying internal misoperations and external attackers trying to gain internal access. It is able to detect and identify the intent of internal or external users to disrupt the network. IDSs come in two common forms: digital signature detection systems and irregularity detection systems. Intruders often attack digital signatures to gain access to the system or compromise the integrity of the network. The digital signature detection system compares the current attack characteristics with the database of known attack characteristics, and finally determines the comparison result according to the selected sensitivity. Then, according to the comparison result, the occurrence of the attack behavior is determined, so as to block the attack behavior and notify the system administrator that the current system is under attack. Irregularity detection technology determines the occurrence of intrusion and alerts system administrators by comparing the difference between the running system behavior and the normal system behavior. For example, IDS can detect abnormal system activity at midnight or heavy access to an I/O port from the external network. When abnormal activity occurs, IDS can block attacks and alert system administrators.

Both of the above IDS systems have their advantages and disadvantages, however, they all have the same problem - how to set the detection sensitivity. High sensitivity will cause false intrusion alarms, and IDS will make corresponding system actions for each intrusion alarm. Therefore, too many false intrusion alarms will not only destroy some necessary functions of the normal system, but also cause a lot of damage to the system. extra burden. The low sensitivity will make IDS unable to detect the occurrence of some intrusion behaviors, so IDS will turn a blind eye to some intrusion behaviors, so that the intruder can successfully enter the system and cause unpredictable losses.

3. Post-event forensics technology
The audit log mechanism is a file that records the authentication information and other characteristic information of legal and illegal users, and is one of the main post-event forensic technologies for industrial control system information security. Therefore, every access to the system and its associated actions needs to be documented. When diagnosing and auditing whether a network electronic intrusion has occurred, the audit diary is one of the essential judgment criteria. In addition, system behavior recording is also a common technology for information security of industrial SCADA systems.

These are some commonly used and conventional technologies in the information security of industrial computer control systems, and there are some special key technologies in the process of implementing industrial control system information security.

Send Inquiry