Overview
ABSTRACT
Industrial Control Systems (ICSs) are used to monitor and control different installations, services, processes, applications, and systems. ICSs are vulnerable to cyberattacks because they are designed to address safety challenges without taking into account security issues. In this paper, the different forms of cyberattacks that can affect ICSs will be presented and their risks and consequences will be assessed. Then, the paper overviews the methods used to detect these attacks and intrusions. The advantages and drawbacks of these methods within the context of energy transition are discussed. Several examples are used in order to illustrate the different concepts and methods used.
Read this article from a comprehensive knowledge base, updated and supplemented with articles reviewed by scientific committees.
Read the articleAUTHOR
-
Moamar SAYED MOUCHAWEH : Full Professor Institute Mines-Telecom (IMT) Lille Douai, Douai, France
INTRODUCTION
Industrial control systems (ICSs) are cyber-physical systems that combine computational, communication and physical layers to perform a set of tasks. They are used to monitor and control various installations, services, processes, applications, and systems such as energy production and distribution (electricity, gas, etc.), transportation networks, and advanced communication systems. The use of ICSs is especially critical in the context of energy transition owing to the increasingly dense communication and exchange of data and information between consumers and utilities, and the services provided (micro-grids, demand side management, etc.). The role of ICSs thus becomes critical since they monitor the stability and reliability of energy production and distribution, optimize the energy consumption and production at centralized/distributed scales, increase the penetration of renewable energy into the grid, etc. However, ICSs are vulnerable to cyberattacks because they are designed to perform predefined tasks of production and ensure safety, but not to address security issues. These attacks modify controller programming to cause serious damage to physical equipment. The Stuxnet attack against Iran’s nuclear program is a typical example. It modified the program controlling the uranium centrifuges to make them spin too fast and for too long, causing their destruction. It is accordingly of prime importance to develop cyberattack detection systems that will spot these attacks early to stop them or limit their catastrophic consequences for critical physical equipment. This paper deals with the problem of cyberattack detection in ICSs in the context of energy transition. It is structured as follows. First the structure of a cyber-physical system and the components of its cyber and physical layers are presented, the different cyber-attacks made against the various components of a cyber-physical system are classified, and their impacts on the system integrity and performance are assessed. The approaches used to design an intrusion detection system are then listed. They belong to three main families: model-based, signature-based and anomaly detection approaches. The advantages and drawbacks of the approaches in each family are discussed according to the attack type and the information available to the attacker about the system structure. An example of a cyber-physical system composed of a pump, a valve, a tank, sensors, and a controller is used throughout to illustrate the different concepts and methods presented.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!
KEYWORDS
Cyberattacks and vulnerabilities | Cyberphysical systems | Industrial control systems | Intrusion detection systems
Protection against cyberattacks in industrial control systems
Article included in this offer
"Security of information systems"
(
92 articles
)
Updated and enriched with articles validated by our scientific committees
A set of exclusive tools to complement the resources
Bibliography
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!