Abstract
Industrial control systems perform vital cyber-physical functions in critical infrastructure assets. Programmable logic controllers, which are prominently found in industrial control environments, execute the operational control logic of cyber-physical systems. Due to the continued escalation of cyber attacks targeting industrial control systems and programmable logic controllers, strengthening the trust and resilience of these systems is paramount.
This chapter proposes an approach that leverages virtualization, cryptographic attestation, software-defined networking, security orchestration and a proprietary programmable logic controller runtime application to advance programmable logic controller trust and resilience while facilitating integration in deployed systems. A proof-of-concept capability demonstrated on a physical industrial control system testbed validates the approach. The experimental results confirm that the approach is viable for industrial control applications.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
F. Armknecht, A. Sadeghi, S. Schulz and C. Wachsmann, A security framework for the analysis and design of software attestation, Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2013.
J. Cervini, A. Rubin and L. Watkins, A containerization-based backfit approach for industrial control system resiliency, Proceedings of the IEEE Symposium on Security and Privacy Workshops, pp. 246–252, 2021.
T. Cruz, P. Simoes and E. Monteiro, Virtualizing programmable logic controllers: Toward a convergent approach, IEEE Embedded Systems Letters, vol. 8(4), pp. 69–72, 2016.
T. Dawson, Who were the leading vendors of industrial controls in 2017? Interact Analysis, Raunds, United Kingdom (interactanalysis.com/who-were-the-leading-vendors-of-industrial-controls-in-2017), November 2018.
A. Francillon, Q. Nguyen, K. Rasmussen and G. Tsudik, A minimalist approach to remote attestation, Proceedings of the Design, Automation and Test in Europe Conference and Exhibition, 2014.
S. Fujita, K. Hata, A. Mochizuki, K. Sawada, S. Shin and S. Hosokawa, OpenPLC-based control system testbed for PLC whitelisting, Artificial Life and Robotics, vol. 26(1), pp. 149–154, 2021.
H. Ghaeini, M. Chan, R. Bahmani, F. Brasser, L. Garcia, J. Zhou, A. Sadeghi, N. Tippenhauer and S. Zonouz, PAtt: Physics-based attestation of control systems, Proceedings of the Twenty-Second International Symposium on Research in Attacks, Intrusions and Defenses, pp. 165–180, 2019.
O. Givehchi, J. Imtiaz, H. Trsek and J. Jasperneite, Control-as-a-service from the cloud: A case study for using virtualized PLCs, Proceedings of the Tenth IEEE Workshop on Factory Communication Systems, 2014.
M. Salehi and S. Bayat-Sarmadi, PLCDefender: Improving remote attestation techniques for PLCs using a physical model, IEEE Internet of Things Journal, vol. 8(9), pp. 7372–7379, 2021.
A. Seshadri, A. Perrig, L. van Doorn and P. Khosla, SWATT: Software-based attestation for embedded devices, Proceedings of the IEEE Symposium on Security and Privacy, pp. 272–282, 2004.
tpm2-software community, Remote attestation (tpm2-software.github.io/tpm2-tss/getting-started/2019/12/18/Remote-Attestation.html), December 18, 2019.
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2022 IFIP International Federation for Information Processing
About this paper
Cite this paper
Cervini, J., Muller, D., Beall, A., Maurio, J., Rubin, A., Watkins, L. (2022). TRUSTED VIRTUALIZATION-BASED PROGRAMMABLE LOGIC CONTROLLER RESILIENCE USING A BACKFIT APPROACH. In: Staggs, J., Shenoi, S. (eds) Critical Infrastructure Protection XVI. ICCIP 2022. IFIP Advances in Information and Communication Technology, vol 666. Springer, Cham. https://doi.org/10.1007/978-3-031-20137-0_4
Download citation
DOI: https://doi.org/10.1007/978-3-031-20137-0_4
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-031-20136-3
Online ISBN: 978-3-031-20137-0
eBook Packages: Computer ScienceComputer Science (R0)