Skip to main content

RICS-el: Building a National Testbed for Research and Training on SCADA Security (Short Paper)

  • Conference paper
  • First Online:

Part of the book series: Lecture Notes in Computer Science ((LNSC,volume 11260))

Abstract

Trends show that cyber attacks targeting critical infrastructures are increasing, but security research for protecting such systems are challenging. There is a gap between the somewhat simplified models researchers at universities can sustain contra the complex systems at infrastructure owners that seldom can be used for direct research. There is also a lack of common datasets for research benchmarking. This paper presents a national experimental testbed for security research within supervisory control and data acquisition systems (SCADA), accessible for both research training and experiments. The virtualized testbed has been designed and implemented with both vendor experts and security researchers to balance the goals of realism with specific research needs. It includes a real SCADA product for energy management, a number of network zones, substation nodes, and a simulated power system. This environment enables creation of scenarios similar to real world utility scenarios, attack generation, development of defence mechanisms, and perhaps just as important: generating open datasets for comparative research evaluation.

This work has been supported by the Swedish Civil Contingencies Agency (MSB) in the context of the RICS project.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

Notes

  1. 1.

    https://www.foi.se/en/our-knowledge/information-security-and-communication/information-security/labs-and-resources/crate-cyber-range-and-training-environment.html.

  2. 2.

    https://www.strath.ac.uk/research/subjects/electronicelectricalengineeringinstituteforenergyenvironment/industryengagementresearchcentres/thepowernetworksdemonstrationcentre/.

References

  1. Reaves, B., Morris, T.: An open virtual testbed for industrial control system security research. Int. J. Inf. Secur. 11(4), 215–229 (2012)

    Article  Google Scholar 

  2. Genge, B., Siaterlis, C., Nai Fovino, I., Masera, M.: A cyber-physical experimentation environment for the security analysis of networked industrial control systems. Comput. Electr. Eng. 38(5), 1146–1161 (2012)

    Article  Google Scholar 

  3. Siaterlis, C., Genge, B., Hohenadel, M.: EPIC: a testbed for scientifically rigorous cyber-physical security experimentation. IEEE Trans. Emerg. Topics Comput. 1(2), 319–330 (2013)

    Article  Google Scholar 

  4. Redwood, O., Reynolds, J., Burmester, M.: Integrating simulated physics and device virtualization in control system testbeds. In: Rice, M., Shenoi, S. (eds.) Critical Infrastructure Protection X. IAICT, vol. 485, pp. 185–202. Springer, Cham (2016). https://doi.org/10.1007/978-3-319-48737-3_11

    Chapter  Google Scholar 

  5. Adhikari, U., Morris, T., Pan, S.: WAMS cyber-physical test bed for power system, cybersecurity study, and data mining. IEEE Trans. Smart Grid 8(6), 2744–2753 (2017)

    Article  Google Scholar 

  6. Dondossola, G., Garrone, G., Szanto, J., Deconinck, G., Loix, T., Beitollahi, H.: ICT resilience of power control systems: experimental results from the crutial testbeds, pp. 554–559 (2009)

    Google Scholar 

  7. Holm, H., Karresand, M., Vidström, A., Westring, E.: A survey of industrial control system testbeds. In: Buchegger, S., Dam, M. (eds.) Secure IT Systems. NordSec 2015. LNCS, vol. 9417, pp. 11–26. Springer, Cham (2015). https://doi.org/10.1007/978-3-319-26502-5_2

  8. McLaughlin, S., et al.: The cybersecurity landscape in industrial control systems. Proc. IEEE 104(5), 1039–1057 (2016)

    Article  Google Scholar 

  9. Egerstedt, M., Govindarasu, M.: Accessible remote testbeds: opportunities, challenges, and lessons learned, workshop report (2016)

    Google Scholar 

  10. Vasilomanolakis, E., Cordero, C.G., Milanov, N., Mühlhäuser, M.: Towards the creation of synthetic, yet realistic, intrusion detection datasets. In: IEEE/IFIP Network Operations and Management Symposium (NOMS), pp. 1209–1214, April 2016

    Google Scholar 

  11. Mathur, A.P., Tippenhauer, N.O.: SWaT: a water treatment testbed for research and training on ICS security. In: International Workshop on Cyber-physical Systems for Smart Water Networks (CySWater), pp. 31–36. IEEE (2016)

    Google Scholar 

  12. Lin, C.Y., Nadjm-Tehrani, S., Asplund, M.: Timing-based anomaly detection in SCADA networks. In: D’Agostino G., Scala, A. (eds.) CRITIS 2017. LNCS, vol. 10707, pp. 48–59. Springer, Cham (2018). https://doi.org/10.1007/978-3-319-99843-5_5

  13. Lin, C.-Y., Nadjm-Tehrani, S.: Understanding IEC-60870-5-104 traffic patterns in SCADA networks. In: Proceedings of the 4th Cyber-Physical System Security Workshop (CPSS), AsiaCCS. ACM, June 2018

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Simin Nadjm-Tehrani .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2019 Springer Nature Switzerland AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Almgren, M. et al. (2019). RICS-el: Building a National Testbed for Research and Training on SCADA Security (Short Paper). In: Luiijf, E., Žutautaitė, I., Hämmerli, B. (eds) Critical Information Infrastructures Security. CRITIS 2018. Lecture Notes in Computer Science(), vol 11260. Springer, Cham. https://doi.org/10.1007/978-3-030-05849-4_17

Download citation

  • DOI: https://doi.org/10.1007/978-3-030-05849-4_17

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-030-05848-7

  • Online ISBN: 978-3-030-05849-4

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics