While achieving security for Industrial Internet of Things (IIoT) is a critical and non-trivial task, more attention is required for brownfield IIoT systems. This is a consequence of long life cycles of their legacy devices which were initially designed without considering security and IoT connectivity, but they are now becoming more connected and integrated with emerging IoT technologies and messaging communication protocols. Deploying today's methodologies and solutions in brownfield IIoT systems is not viable, as security solutions must co-exist and fit these systems requirements. This necessitates a realistic standardized IIoT testbed that can be used as an optimal format to measure the credibility of security solutions of IIoT networks, analyze IIoT attack landscapes and extract threat intelligence. Developing a testbed for brownfield IIoT systems is considered a significant challenge as these systems are comprised of legacy, heterogeneous devices, communication layers and applications that need to be implemented holistically to achieve high fidelity. In this paper, we propose a new generic end-to-end IIoT security testbed, with a particular focus on the brownfield system and provide details of the testbed's architectural design and the implementation process. The proposed testbed can be easily reproduced and reconfigured to support the testing activities of new processes and various security scenarios. The proposed testbed operation is demonstrated on different connected devices, communication protocols and applications. The experiments demonstrate that this testbed is effective in terms of its operation and security testing. A comparison with existing testbeds, including a table of features is provided.
翻译:虽然实现物业工业互联网安全是一项关键和非三重任务,但需要更加重视褐色野外IIOT系统,这是其遗留装置的寿命周期长的结果,最初设计这些装置时没有考虑到安全和IOT连接性,但现在这些装置与新兴的IOT技术和传送通信协议的联系和一体化日益加强。在褐色野外IIOT系统中部署今天的方法和解决方案并不可行,因为安全解决方案必须同时存在并符合这些系统的要求。这需要有一个现实的标准化IIOT测试台,可以用作衡量IIOT网络安全解决方案的可信度的最佳格式,分析IIOT攻击场景和提取威胁情报。开发棕色野外IIOT系统测试台的测试台是一个重大挑战,因为这些系统由遗产、不同设备、通信层和应用程序组成,需要整体地实施,以实现高度的忠诚。在本文件中,我们提议一个新的通用的终端至终端IIOT安全测试台测试台测试台,特别侧重于棕色地系统,并提供测试台测试台测试台运行系统特征的详情,包括测试台式测试台式设计、测试程序。