This paper presents SCADASiM, an integrated framework for control system simulation and near-real-time regulatory compliance monitoring with respect to cybersecurity. With numerous legacy control system installations already in place, current approaches for highly detailed simulations demand a significant modeling effort to be useful. Furthermore, the complexity and lack of technical uniformity in legacy SCADA systems often obscures their core operational semantics, making regulatory compliance monitoring only available to personnel with intimate knowledge about the system. To address these issues, the SCADASiM framework includes two parts. First, it allows rapid recreation of message-based interactions between cyber and physical entities. The resulting simulation is geared towards facilitating the development of strategic and near-real-time security related regulatory compliance monitoring capabilities for critical infrastructure owners. Second, it includes new language utilities for collecting and monitoring the system events necessary to demonstrate regulatory compliance in real-time. In an integrated framework, the simulation facilitates policy authoring using the new language utilities, which in turn allow the observance of policy violation with its operational impact using “what-if” scenarios about coordinated attacks on the infrastructure. The two parts of the framework are synchronized by a SCADA taxonomy described using semantic web representation standards. The abstract layers of our taxonomy map to regulatory requirements that mandate security controls in the critical infrastructure, while the lower layers map to actual system components and their events that characterize actual system behavior. Here we describe the design decisions and structure of the SCADASiM framework as well as its initial feasibility using an in-lab control system simulation that replicates a water supply system.
本文介绍了SCADASiM,这是一个用于控制系统模拟以及针对网络安全的近实时法规合规性监测的综合框架。由于已经有大量的遗留控制系统安装到位,当前用于高度详细模拟的方法需要大量的建模工作才能发挥作用。此外,遗留的监控与数据采集(SCADA)系统的复杂性和技术缺乏一致性常常掩盖了其核心操作语义,使得法规合规性监测只有对系统非常了解的人员才能进行。为了解决这些问题,SCADASiM框架包括两个部分。首先,它允许快速重现网络实体和物理实体之间基于消息的交互。由此产生的模拟旨在促进关键基础设施所有者开发战略和近实时的安全相关法规合规性监测能力。其次,它包括新的语言工具,用于收集和监测实时证明法规合规性所需的系统事件。在一个综合框架中,模拟有助于使用新的语言工具制定策略,而这些工具反过来又允许通过对基础设施进行协同攻击的“假设”情景来观察策略违反及其操作影响。该框架的两个部分通过使用语义网表示标准描述的SCADA分类法进行同步。我们分类法的抽象层映射到要求关键基础设施进行安全控制的法规要求,而较低层则映射到表征实际系统行为的实际系统组件及其事件。在这里,我们描述了SCADASiM框架的设计决策和结构,以及通过一个模拟供水系统的实验室内部控制系统模拟所验证的其初步可行性。