PLC Reprogramming Detection via TAP and Time Deception in SCADA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SCADA systems are vulnerable to malicious reprogramming of PLCs due to lack of security measures, outdated architecture, and connectivity issues, which can lead to unauthorized control and manipulation of physical devices, compromising system integrity and availability.
Innovation Solution
A dedicated system using a Test Access Point (TAP) and Intrusion Detection System (IDS) is installed between the Engineering Workstation and PLC to passively monitor and detect unauthorized reprogramming attempts, alerting the Security Information and Event Management System (SIEM) and allowing for controlled programming windows to prevent malicious changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security measures such as IDS and TAP are installed to detect malicious reprogramming, then system security is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces a Test Access Point (TAP) as an intermediary device that passively monitors communication between the Engineering Workstation and PLC. The TAP captures traffic without interrupting normal operations, allowing security monitoring while maintaining system simplicity. This intermediary approach enables security enhancement without directly modifying the core control system architecture.
Solution Approach 2:
The patent replaces physical security measures (such as locked control rooms or restricted access) with electronic monitoring through IDS and TAP. Instead of mechanically preventing access, the system uses digital surveillance of communication traffic to detect and prevent malicious reprogramming, reducing physical complexity while enhancing security.
2Difficulty of detecting and measuring
If continuous monitoring is implemented to detect unauthorized changes, then detection capability is improved, but loss of time for legitimate programming operations increases
Solution Approach 1:
The system performs preliminary authentication and authorization checks before allowing programming operations. By pre-establishing security credentials and authorization levels, the system can quickly validate legitimate programming requests without time-consuming monitoring delays, while still maintaining continuous detection capability for unauthorized attempts.
Solution Approach 2:
The monitoring system operates periodically rather than continuously blocking operations. It samples communication traffic at intervals and triggers detailed analysis only when suspicious patterns are detected, allowing legitimate programming to proceed uninterrupted while maintaining detection capability. This periodic approach reduces time loss for authorized operations.
Data Source
Figure 1
Figure 2
AI summary
A method for detecting malicious reprogramming of a Programmable Logic Controller (PLC) in a Superiority Control And Data Acquisition (SCADA) system, according to which a dedicated device is located on the communication network between the PLC and an engineering Workstation and the traffic between the PLC and the engineering Workstation is passively collected and checked using a TAP. An alert is generated upon detecting an unauthorized reprogramming in the checked traffic.