Software Enabled Security Architecture for Counteracting Attacks in Control Systems
Uday Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar

TL;DR
This paper presents a software-defined networking and network function virtualization based security architecture designed to protect industrial control systems from specific cyber attacks, ensuring safety and operational continuity.
Contribution
It introduces a novel SDN/NFV-enabled security framework and a Control System Security Application tailored for ICS, addressing vulnerabilities from legacy devices and denial of service attacks.
Findings
Prototype implementation demonstrates effective attack mitigation.
Enhanced security for legacy ICS components.
Improved resilience against denial of service attacks.
Abstract
Increasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of IT systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation's security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · Smart Grid Security and Resilience · Network Security and Intrusion Detection
