SCADA PLC False Telemetry Detection via Sensor Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SCADA systems lack effective mechanisms to detect false telemetry data sent by maliciously re-programmed Programmable Logic Controllers (PLCs), which can compromise the integrity and availability of the system, as they are not equipped with modern security measures like encryption and authentication, making them vulnerable to attacks that manipulate or send false commands to physical devices.
Innovation Solution
A method and system that compares data signals from sensors to those sent by the PLC to the Human Machine Interface (HMI), using a passive tap and cryptographic message authentication codes (MAC) to monitor and verify the integrity of the data, issuing alerts if alterations are detected, thereby preventing false information from being sent back to the HMI.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If modern security measures like encryption and authentication are implemented in SCADA systems, then system security and integrity are improved, but system complexity and cost increase
Solution Approach 1:
The patent implements security measures by inserting a security device in the communication path between sensor and PLC that performs authentication and encryption/decryption operations before data reaches the PLC. This preliminary security processing ensures data integrity and authenticity without requiring the entire SCADA system to be redesigned with complex security infrastructure.
Solution Approach 2:
The patent introduces a security device as an intermediary component between the sensor and PLC. This mediator performs authentication of the sensor and encryption/decryption of data, isolating the complex security functions from the main SCADA system components and reducing overall system complexity while maintaining security.
2Difficulty of detecting and measuring
If security measures are added to SCADA systems to detect false telemetry data, then detection capability is improved, but operational simplicity and ease of use deteriorate
Solution Approach 1:
The security device performs authentication and encryption/decryption operations automatically without requiring operator intervention. The device self-manages security protocols, key management, and data verification, maintaining operational simplicity while enabling sophisticated detection of false telemetry data.
Solution Approach 2:
The security device provides automatic feedback regarding data authenticity and integrity status. When false data is detected, the system can trigger alerts or reject the data automatically, maintaining ease of operation by handling detection and response without complex manual procedures.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed herein are embodiments of systems and methods of detecting whether an attacker has re-programmed a Programmable Logic Controller (PLC) in a Supervisory Control And Data Acquisition (SCADA) system in order to send false information back to the Human Machine Interface (HMI).