2019-122

2019-122

SCADA Testbed Implementation, Attacks, and Security Solutions

TAPAN SONI, JOHN A. STRANAHAN, JACOB E. CARPENTER

Supervisory Control and Data Acquisition (SCADA) control systems have been in use for decades. They provide remote management and monitoring capabilities for Industrial Control Systems (ICS) such as power plants, trains, water treatment plants, and dams. In recent years, SCADA systems have been the target of malicious attackers. The Modbus TCP/IP protocol, which is the standard communication protocol used by many SCADA systems for network communication, is unecrypted and therefore it is insecure by design. In this research, a cost-effective design and implementation of a custom SCADA testbed is proposed to assess prevalent vulnerabilities and exploits in real-world Industrial Control Systems. A solution is then proposed to prevent these types of vulnerabilities from being exploited on real world systems by implementing an IPSec VPN tunnel.