首页> 外文会议>Biennial Symposium on Communications >Evaluation of Industrial Firewall Performance Issues in Automation and Control Networks
【24h】

Evaluation of Industrial Firewall Performance Issues in Automation and Control Networks

机译:评估自动化和控制网络中的工业防火墙性能问题

获取原文

摘要

The IEC 62443 security standards introduce the concepts of zones, conduits, and security levels as a way of segmenting and isolating the sub-systems of an industrial control network. Network segmentation logically partition the control network into separate communication zones to restrict unnecessary flow of traffic between zones of different trust level. Firewalls with deep packet inspection capabilities for filtering industrial control protocols are indispensable elements in implementing important security principles, standards, and best practices of IEC 62443. While partitioning of the industrial control network and placement of multiple firewalls at various locations provides defense in-depth against cyber-attacks, it is important to consider the impact of these firewalls on nodes distributing time critical communications. This paper attempts to (i) study network performance impact introduced by the implementation of multiple firewalls in Modbus TCP/IP industrial control networks following IEC 62443 security standards and (ii) evaluate if time constraint requirements for communications are achievable. The results reveal that the latency and jitters introduced by multilayered firewalls makes it challenging to achieve real-time communications in some industrial applications when strict IEC 62443 security standards are followed.
机译:IEC 62443安全标准引入了区域,管道和安全级别的概念,作为对工业控制网络的子系统进行分段和隔离的一种方式。网络分段在逻辑上将控制网络划分为单独的通信区域,以限制不同信任级别的区域之间不必要的通信流。具有深层数据包检查功能以过滤工业控制协议的防火墙是实现IEC 62443重要安全原则,标准和最佳实践的必不可少的元素。尽管对工业控制网络进行分区并在不同位置放置多个防火墙可提供深度防御网络攻击,重要的是要考虑这些防火墙对分发时间紧迫的通信的节点的影响。本文试图(i)研究遵循IEC 62443安全标准的Modbus TCP / IP工业控制网络中的多个防火墙的实现对网络性能的影响,以及(ii)评估是否可以满足通信的时间限制要求。结果表明,当遵循严格的IEC 62443安全标准时,多层防火墙引入的延迟和抖动使其难以在某些工业应用中实现实时通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号