loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Venesa Watson 1 ; Xinxin Lou 2 and Yuan Gao 3

Affiliations: 1 Areva GmbH and University of Siegen, Germany ; 2 Areva GmbH and Bielefeld University, Germany ; 3 Areva GmbH and Otto-von-Guericke University, Germany

Keyword(s): PROFIBUS, Industrial Networks, Security, OPC UA, Defense-In-Depth.

Related Ontology Subjects/Areas/Topics: Data and Application Security and Privacy ; Data Protection ; Information and Systems Security ; Network Security ; Security Deployment ; Security in Information Systems ; Wireless Network Security

Abstract: PROFIBUS is a standard for fieldbus communication, used in industrial networks to support real-time command and control. Similar to network protocols developed then, availability is the security objective prioritized in the PROFIBUS design. Confidentiality and integrity were of lesser importance, as industrial protocols were not intended for public access. However, the publicized weaknesses in industrial technologies, including the inclusion of publicly available technology and protocols in industrial networks, presents major risks to industrial networks. This paper investigates the security risks of and provides suggested security solutions for PROFIBUS. The objective is to review the PROFIBUS protocol, to establish the purposefulness of the design and its suitability for the applications where it forms a core part of the infrastructure. The security risks of this protocol are then assessed from successful and possible attacks, based on the vulnerabilities. Proposed securit y solutions are reviewed and additional recommendations made concerning the use of OPC UA, accompanied by an analysis of the cost of these solutions to the efficiency and safety of the PROFIBUS. The findings of this paper indicate that a defense-in-depth approach is more feasible security solution, with strong security controls being implemented at networks interconnecting with the PROFIBUS networks. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.149.234.251

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Watson, V.; Lou, X. and Gao, Y. (2017). A Review of PROFIBUS Protocol Vulnerabilities - Considerations for Implementing Authentication and Authorization Controls. In Proceedings of the 14th International Joint Conference on e-Business and Telecommunications (ICETE 2017) - SECRYPT; ISBN 978-989-758-259-2; ISSN 2184-3236, SciTePress, pages 444-449. DOI: 10.5220/0006426504440449

@conference{secrypt17,
author={Venesa Watson. and Xinxin Lou. and Yuan Gao.},
title={A Review of PROFIBUS Protocol Vulnerabilities - Considerations for Implementing Authentication and Authorization Controls},
booktitle={Proceedings of the 14th International Joint Conference on e-Business and Telecommunications (ICETE 2017) - SECRYPT},
year={2017},
pages={444-449},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0006426504440449},
isbn={978-989-758-259-2},
issn={2184-3236},
}

TY - CONF

JO - Proceedings of the 14th International Joint Conference on e-Business and Telecommunications (ICETE 2017) - SECRYPT
TI - A Review of PROFIBUS Protocol Vulnerabilities - Considerations for Implementing Authentication and Authorization Controls
SN - 978-989-758-259-2
IS - 2184-3236
AU - Watson, V.
AU - Lou, X.
AU - Gao, Y.
PY - 2017
SP - 444
EP - 449
DO - 10.5220/0006426504440449
PB - SciTePress