Latentziarik gabeko sareko identifikatzaileen aleatorizazioa kontrol industrialerako sistemetan proaktiboki errekonozimendu erasoak mitigatzeko

Authors

  • Xabier Etxezarreta Mondragon Unibertsitatea (MU)
  • Iñaki Garitano Mondragon Unibertsitatea (MU)
  • Mikel Iturbe Mondragon Unibertsitatea (MU)
  • Urko Zurutuza Mondragon Unibertsitatea (MU)

DOI:

https://doi.org/10.26876/ikergazte.v.03.07

Keywords:

Industrial cybersecurity, Software Defined Networking, Moving Target Defense, Proactive intrusion response

Abstract

Industrial Control Systems are used in a wide variety of industrial facilities, including critical infrastructures, becoming the main target of multiple security attacks. Static networks configurations and topologies, which characterize Industrial Control Systems, represent an advantage for attackers, allowing them to scan for vulnerable devices or services before carrying out the attack. This paper presents a proactive network reconnaissance defense mechanism based on the temporal randomization of network IP addresses, MAC addresses and port numbers. The obtained information distortion minimizes the knowledge acquired by the attackers, hindering any attack that relies on network addressing. The temporal randomization of network attributes is performed in an adaptive way, minimizing the overhead introduced in the network and avoiding any error and latency in communications. The implementation as well as the tests have been carried out in a laboratory with real industrial equipment, demonstrating the effectiveness of the presented solution.

Downloads

Published

2023-05-09

How to Cite

Etxezarreta, X., Garitano, I., Iturbe, M., & Zurutuza, U. (2023). Latentziarik gabeko sareko identifikatzaileen aleatorizazioa kontrol industrialerako sistemetan proaktiboki errekonozimendu erasoak mitigatzeko. IkerGazte. Nazioarteko Ikerketa Euskaraz, 3, 55–62. https://doi.org/10.26876/ikergazte.v.03.07