DTE Access Control Model for Integrated ICS Systems
Title | DTE Access Control Model for Integrated ICS Systems |
Publication Type | Conference Paper |
Year of Publication | 2019 |
Authors | Es-Salhi, Khaoula, Espes, David, Cuppens, Nora |
Conference Name | Proceedings of the 14th International Conference on Availability, Reliability and Security |
Publisher | Association for Computing Machinery |
Conference Location | Canterbury, CA, United Kingdom |
ISBN Number | 978-1-4503-7164-3 |
Keywords | Access Control, Domain and Type Enforcement, DTE Firewall, industrial control systems, Industrial Control Systems Anomaly Detection, pubcrawl, resilience, Resiliency, Scalability, security policy, Segregation |
Abstract | Integrating Industrial Control Systems (ICS) with Corporate System (IT) is one of the most important industrial orientations. With recent cybersecurity attacks, the security of integrated ICS systems has become the priority of industrial world. Access control technologies such as firewalls are very important for Integrated ICS (IICS) systems to control communication across different networks to protect valuable resources. However, conventional firewalls are not always fully compatible with Industrial Control Systems. In fact, firewalls can introduce significant latency while ICS systems usually are very demanding in terms of timing requirements. Besides, most of existing firewalls do not support all industrial protocols. This paper proposes a new access control model for integrated ICS systems based on Domain and Type Enforcement (DTE). This new model allows to define and apply enforced access controls with respect of ICS timing requirements. Access controls definition is based on a high level language that can be used by ICS administrators with ease. This paper also proposes an initial generic ruleset based on the ISA95 functional model. This generic ruleset simplifies the deployment of DTE access controls and provides a good introduction to the DTE concepts for administrators. |
DOI | 10.1145/3339252.3340498 |
Citation Key | es-salhi_dte_2019 |