The SAP Link: A Controller Architecture for Secure Industrial Control Systems

Industrial Control Systems are essential to modern life. They are utilized in hundreds of processes including power distribution, water treatment, manufacturing, traffic management, and amusement park ride control. These systems are an essential part of modern life and if compromised, could result i...

Full description

Bibliographic Details
Main Author: Wyman, Matthew Cody
Format: Others
Published: BYU ScholarsArchive 2019
Subjects:
ICS
Online Access:https://scholarsarchive.byu.edu/etd/8815
https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=9824&context=etd
id ndltd-BGMYU2-oai-scholarsarchive.byu.edu-etd-9824
record_format oai_dc
spelling ndltd-BGMYU2-oai-scholarsarchive.byu.edu-etd-98242021-03-25T05:00:48Z The SAP Link: A Controller Architecture for Secure Industrial Control Systems Wyman, Matthew Cody Industrial Control Systems are essential to modern life. They are utilized in hundreds of processes including power distribution, water treatment, manufacturing, traffic management, and amusement park ride control. These systems are an essential part of modern life and if compromised, could result in significant economic loss, safety impacts, damage to the environment, and even loss of life. Unfortunately, many of these systems are not properly secured from a cyber attack. It is likely that a well-funded and motivated attack from a nation-state will successfully compromise an industrial control system's network. As cyber war becomes more prevalent, it is becoming more critical to find new and innovative ways to reduce the physical impacts from a cyber attack.This thesis presents a new architecture for a secure industrial controller. This architecture protects the integrity of the controller logic, including the safety logic which is responsible for keeping the process in a safe condition. In particular, it would prevent malicious or accidental modification or bypassing of the controller logic. This architecture divides the controller into three components; the logic controller, the interface controller and the SAP link. The logic controller is responsible for controlling the equipment and contains the safety logic. The interface controller communicates with the rest of the control system network. The Simple As Possible (SAP) link is a bridge between the logic and interface controllers that ensures the integrity of the logic controller by drastically limiting the external interface of the logic controller. We implement this new architecture on a physical controller to demonstrate the process of implementing the architecture and to demonstrate its feasibility. 2019-02-01T08:00:00Z text application/pdf https://scholarsarchive.byu.edu/etd/8815 https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=9824&context=etd http://lib.byu.edu/about/copyright/ Theses and Dissertations BYU ScholarsArchive SCADA ICS security controller architecture industrial control system cyber war safety logic Electrical and Computer Engineering
collection NDLTD
format Others
sources NDLTD
topic SCADA
ICS
security
controller architecture
industrial control system
cyber war
safety logic
Electrical and Computer Engineering
spellingShingle SCADA
ICS
security
controller architecture
industrial control system
cyber war
safety logic
Electrical and Computer Engineering
Wyman, Matthew Cody
The SAP Link: A Controller Architecture for Secure Industrial Control Systems
description Industrial Control Systems are essential to modern life. They are utilized in hundreds of processes including power distribution, water treatment, manufacturing, traffic management, and amusement park ride control. These systems are an essential part of modern life and if compromised, could result in significant economic loss, safety impacts, damage to the environment, and even loss of life. Unfortunately, many of these systems are not properly secured from a cyber attack. It is likely that a well-funded and motivated attack from a nation-state will successfully compromise an industrial control system's network. As cyber war becomes more prevalent, it is becoming more critical to find new and innovative ways to reduce the physical impacts from a cyber attack.This thesis presents a new architecture for a secure industrial controller. This architecture protects the integrity of the controller logic, including the safety logic which is responsible for keeping the process in a safe condition. In particular, it would prevent malicious or accidental modification or bypassing of the controller logic. This architecture divides the controller into three components; the logic controller, the interface controller and the SAP link. The logic controller is responsible for controlling the equipment and contains the safety logic. The interface controller communicates with the rest of the control system network. The Simple As Possible (SAP) link is a bridge between the logic and interface controllers that ensures the integrity of the logic controller by drastically limiting the external interface of the logic controller. We implement this new architecture on a physical controller to demonstrate the process of implementing the architecture and to demonstrate its feasibility.
author Wyman, Matthew Cody
author_facet Wyman, Matthew Cody
author_sort Wyman, Matthew Cody
title The SAP Link: A Controller Architecture for Secure Industrial Control Systems
title_short The SAP Link: A Controller Architecture for Secure Industrial Control Systems
title_full The SAP Link: A Controller Architecture for Secure Industrial Control Systems
title_fullStr The SAP Link: A Controller Architecture for Secure Industrial Control Systems
title_full_unstemmed The SAP Link: A Controller Architecture for Secure Industrial Control Systems
title_sort sap link: a controller architecture for secure industrial control systems
publisher BYU ScholarsArchive
publishDate 2019
url https://scholarsarchive.byu.edu/etd/8815
https://scholarsarchive.byu.edu/cgi/viewcontent.cgi?article=9824&context=etd
work_keys_str_mv AT wymanmatthewcody thesaplinkacontrollerarchitectureforsecureindustrialcontrolsystems
AT wymanmatthewcody saplinkacontrollerarchitectureforsecureindustrialcontrolsystems
_version_ 1719384260525162496