Virtual Industrial Control System Testbed

Authors:

  • Hannes Holm
  • Martin Karresand
  • Arne Vidström
  • Erik Westring

Publish date: 2015-04-13

Report number: FOI-R--4073--SE

Pages: 81

Written in: English

Keywords:

  • Industrial Control Systems
  • testbed
  • IT security
  • cyber security
  • systematic literature review

Abstract

Critical societal functions such as electricity and water purification depend on Industrial Control Systems (ICS) to properly function. Not long ago, these ICS were realized by specially constructed isolated devices. Along with the rest of our society, ICS have evolved and are now often delivered by complex interconnected IT solutions including commercial-off-the-shelf technologies that in one way or another are connected to the Internet. As a consequence, ICS are vulnerable to IT attacks similarly to most other IT systems. Due to the extreme availability requirements on ICS in operation, it is difficult to perform cyber security experiments on them, such as vulnerability discovery or tests of defense mechanisms. To accommodate such experiments, researchers and practitioners turn to testbeds that mimic real ICS. This study first surveys ICS testbeds that have been proposed for scientific research. Special focus is given to field devices, a kind of ICS component that is considered particularly challenging to implement in testbeds. It then compares these results with findings from product surveys, practical experiences, and interviews with a manufacturer. The outcomes of this comparison are methods and tools for creating a high-fidelity ICS testbed. The study was conducted in collaboration with other actors, in particular, the Idaho National Laboratory.