Visible to the public Securing Industrial Remote Maintenance Sessions using Software-Defined Networking

TitleSecuring Industrial Remote Maintenance Sessions using Software-Defined Networking
Publication TypeConference Paper
Year of Publication2019
AuthorsKern, Alexander, Anderl, Reiner
Conference Name2019 Sixth International Conference on Software Defined Systems (SDS)
KeywordsABAC, Business, Communication networks, considerable economic advantages, industrial network, industrial networks, industrial remote maintenance, industrial remote maintenance session security, Internet, maintenance engineering, Manufacturing industries, manufacturing industry, Metrics, Network security, Production, production engineering computing, pubcrawl, resilience, Resiliency, Router Systems Security, SDN, security, security of data, Software, software defined networking, software-defined networking, untrustworthy external networks, XACML
AbstractMany modern business models of the manufacturing industry use the possibilities of digitization. In particular, the idea of connecting machines to networks and communication infrastructure is gaining momentum. However, in addition to the considerable economic advantages, this development also brings decisive disadvantages. By connecting previously encapsulated industrial networks with untrustworthy external networks such as the Internet, machines and systems are suddenly exposed to the same threats as conventional IT systems. A key problem today is the typical network paradigm with static routers and switches that cannot meet the dynamic requirements of a modern industrial network. Current security solutions often only threat symptoms instead of tackling the cause. In this paper we will therefore analyze the weaknesses of current networks and security solutions using the example of industrial remote maintenance. We will then present a novel concept of how Software-Defined Networking (SDN) in combination with a policy framework that supports attribute-based access control can be used to meet current and future security requirements in dynamic industrial networks. Furthermore, we will introduce an examplary implementation of this novel security framework for the use case of industrial remote maintenance and evaluate the solution. Our results show that SDN in combination with an Attribute-based Access Control (ABAC) policy framework is perfectly suited to increase flexibility and security of modern industrial networks at the same time.
DOI10.1109/SDS.2019.8768719
Citation Keykern_securing_2019