Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

On the detection of replay attacks in industrial automation networks operated with profinet IO

: Pfrang, Steffen; Meier, David


Mori, P. ; IEEE Systems, Man and Cybernetics Society -SMC-; Institute for Systems and Technologies of Information, Control and Communication -INSTICC-, Setubal:
ICISSP 2017, 3rd International Conference on Information Systems Security and Privacy. Proceedings : Porto, Portugal, February 19-21, 2017
SciTePress, 2017
ISBN: 978-989-758-209-7
International Conference on Information Systems Security and Privacy (ICISSP) <3, 2017, Porto>
Conference Paper
Fraunhofer IOSB ()
industrial network; replay attack; port stealing; DCP Reconfiguration; intrusion detection; attack detection modeling

Modern industrial facilities consist of controllers, actuators and sensors that are connected via traditional IT equipment. The ongoing integration of these systems into the communication network yields to new threats and attack possibilities. In industrial networks, often distinct communication protocols like Profinet IO (PNIO) are used. These protocols are often not supported by typical network security tools. In this paper, we present two attack techniques that allow to take over the control of a PNIO device, enabling an attacker to replay formerly recorded traffic. We model attack detection rules and propose an intrusion detection system (IDS) for industrial networks which is capable of detecting those replay attacks by correlating alerts from traditional IT IDS with specific PNIO alarms. Thereafter, we evaluate our IDS in a physical demonstrator and compare it with another IDS dedicated to securing PNIO networks.