A Linux-based firewall for the DNP3 protocol

被引:0
|
作者
Nivethan, Jeyasingam [1 ]
Papa, Mauricio [1 ]
机构
[1] Univ Tulsa, Tandy Sch Comp Sci, Tulsa, OK 74104 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Firewall solutions, specifically designed for smart power grids and other industrial control systems, are quite limited, with only a few commercial offerings. This paper presents a novel methodology that extends existing Linux-based firewalls for use in systems that use DNP3 protocol for industrial control. The proposed solution uses the u32 byte-matching feature of the iptables firewall, a firewall solution available in most Linux distributions. To demonstrate the approach, filtering rules for common attacks on the DNP3 protocol were developed. DNP3 is an industrial control protocol typically used in the electric power sector. The main goal of our work is to leverage an openly available and robust firewall solution for use in protecting the U.S. smart grid. The prototype was tested on a scaled-down electric power substation which runs the DNP3 protocol for communication between the field devices and the SCADA master.
引用
收藏
页数:5
相关论文
共 50 条
  • [31] Internet firewall based on Linux
    Weng, Guannan
    Wang, Huiqiang
    Jisuanji Gongcheng/Computer Engineering, 2000, 26 (07): : 129 - 132
  • [32] Modeling the Throughput of the Linux-Based Agile-SD Transmission Control Protocol
    Alrshah, Mohamed A.
    Othman, Mohamed
    Ali, Borhanuddin Mohd
    Mohdhanapi, Zurina Binti
    IEEE ACCESS, 2016, 4 : 9724 - 9732
  • [33] Modeling DNP3 Security Using Timed Automata
    Chen, Zhi
    Peng, Chao-Yu
    Yue, Wen-Jing
    INTERNATIONAL CONFERENCE ON MECHANICS AND CONTROL ENGINEERING (MCE 2015), 2015, : 368 - 374
  • [34] Securing DNP3 Broadcast Communications in SCADA Systems
    Amoah, Raphael
    Camtepe, Seyit
    Foo, Ernest
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2016, 12 (04) : 1474 - 1485
  • [35] Traffic control in Linux-based routers
    Zhang, Huan-Qiang
    Wu, Zhi-Mei
    Ruan Jian Xue Bao/Journal of Software, 2005, 16 (03): : 462 - 471
  • [36] Persistence in Linux-Based IoT Malware
    Brierley, Calvin
    Pont, Jamie
    Arief, Budi
    Barnes, David J.
    Hernandez-Castro, Julio
    SECURE IT SYSTEMS, NORDSEC 2020, 2021, 12556 : 3 - 19
  • [37] Clustering software for Linux-based HPC
    Hasegawa, Atsushi
    Matsuoka, Hiroshi
    Nakanishi, Kouichi
    NEC Research and Development, 2003, 44 (01): : 60 - 63
  • [38] Smart Grid DNP3 Vulnerability Analysis and Experimentation
    Darwish, Ihab
    Igbe, Obinna
    Celebi, Orhan
    Saadawi, Tarek
    Soryal, Joseph
    2015 IEEE 2ND INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (CSCLOUD), 2015, : 141 - 147
  • [39] Implementing WIPI for linux-based smartphone
    Lee, J
    Kim, SA
    Lee, S
    Kim, W
    Lee, H
    7th International Conference on Advanced Communication Technology, Vols 1 and 2, Proceedings, 2005, : 692 - 696
  • [40] Clustering software for Linux-based HPC
    Hasegawa, A
    Matsuoka, H
    Nakanishi, K
    NEC RESEARCH & DEVELOPMENT, 2003, 44 (01): : 60 - 63