Visible to the public Privacy and Integrity Protection of Data in SCADA Systems

TitlePrivacy and Integrity Protection of Data in SCADA Systems
Publication TypeConference Paper
Year of Publication2018
Authorsde Lima, Davi Ferreira, Bezerra, José Roberto, de Macedo Costa da Silva, Jorge Fredericson
Conference NameProceedings of the 10th Latin America Networking Conference
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-5922-1
Keywordscomposability, cyber security, Human Behavior, pubcrawl, Resiliency, SCADA, SCADA Systems Security, traffic obfuscation, Virtual private networks
AbstractThe critical infrastructure of a country, due to its relevance and complexity, demands systems to facilitate the user interaction to correctly deal and share the information related to the monitored processes. The systems currently applied to monitor such infrastructures are based on SCADA architecture. The advent of the Internet jointly to the needs of fast information exchange at any place in order to support accurate decision-making processes, demands increasing interconnection among SCADA and management systems. However, such interconnection may expose sensitive data manipulated by such systems to hackers which may cause massive damages, financial loses, threats to human lives among others. Therefore, unprotected data may expose the systems to cyber-criminals by affecting any of the cyber-security principles, Confidentiality, Integrity, and Authenticity. This article presents four study cases using Wireshark to analyze a popular SCADA software to check user authentication process. The result of this research was the reading in plain text of the user authentication data used to access the control and monitoring system. As an immediate and minimal solution, this work presents low cost, easy setup and open source solutions are proposed using VPN and protocol obfuscator to improve security applying cryptography and hide the data passing through Virtual Private Network.
URLhttp://doi.acm.org/10.1145/3277103.3277136
DOI10.1145/3277103.3277136
Citation Keyde_lima_privacy_2018