메뉴 건너뛰기




Volumn 16, Issue 4, 2008, Pages 398-414

Securing SCADA systems

Author keywords

Data security; Electric power systems; Gas industry; Oil industry; Water supply

Indexed keywords

COMPUTER CRIME; DATA ACQUISITION; ELECTRIC GENERATORS; ELECTRIC POWER MEASUREMENT; ELECTRIC POWER SYSTEMS; ELECTRICITY; GAS INDUSTRY; GAS SUPPLY; INTERNET PROTOCOLS; LIQUEFIED PETROLEUM GAS; NETWORK PROTOCOLS; OFFSHORE OIL WELL PRODUCTION; PETROLEUM REFINERIES; SECURITY OF DATA; SOLUTIONS; WATER SUPPLY;

EID: 54949110261     PISSN: 09685227     EISSN: None     Source Type: Journal    
DOI: 10.1108/09685220810908804     Document Type: Article
Times cited : (28)

References (64)
  • 1
    • 84903312177 scopus 로고    scopus 로고
    • AGA AGA Report No. 12-1 (draft), American Gas Association, Washington, DC, March
    • AGA (2003), "Cryptographic protection of SCADA communications", AGA Report No. 12-1 (draft), American Gas Association, Washington, DC, March.
    • (2003) "Cryptographic Protection of SCADA Communications"
  • 2
    • 54949154740 scopus 로고    scopus 로고
    • "Hackers penetrate Gazprom"
    • Bellovin, S. (2000), "Hackers penetrate Gazprom", The Risk Digest, Vol. 20 No. 87.
    • (2000) The Risk Digest , vol.20 , Issue.87
    • Bellovin, S.1
  • 5
    • 33746407003 scopus 로고
    • "Axiomatic specification and logic programming: Fast prototyping of correct designs"
    • Boriani, D.V. (1995), "Axiomatic specification and logic programming: Fast prototyping of correct designs", ISA Transactions, Vol. 34 No. 1, pp. 53-65.
    • (1995) ISA Transactions , vol.34 , Issue.1 , pp. 53-65
    • Boriani, D.V.1
  • 7
    • 54949093431 scopus 로고    scopus 로고
    • CERT Carnegie Mellon University, Pittsburgh, PA, available at: (accessed April, 2008)
    • CERT (2003), "Advisory CA-2003-26", Carnegie Mellon University, Pittsburgh, PA, available at: www.cert.org/advisories/ CA-2003-26.html (accessed April, 2008).
    • (2003) "Advisory CA-2003-26"
  • 8
    • 54949127735 scopus 로고    scopus 로고
    • CVE National Cyber Security Division of Department of Homeland Security, Washington, DC, Common Vulnerabilities and Exposures, available at: (accessed April, 2008)
    • CVE (2007), "CVE ID: CAN-2003-0543", National Cyber Security Division of Department of Homeland Security, Washington, DC, Common Vulnerabilities and Exposures, available at: http://cve.mitre.org/ cgi-bin/cvename.cgi?name=CAN-2003-0543 (accessed April, 2008).
    • (2007) "CVE ID: CAN-2003-0543"
  • 10
    • 33748887114 scopus 로고    scopus 로고
    • DHS US Department of Homeland Security, Washington, DC, Presidential Directive/Hspd-7 December, available at: (accessed April, 2008)
    • DHS (2003), "Critical infrastructure identification, prioritization, and protection", US Department of Homeland Security, Washington, DC, Presidential Directive/Hspd-7 December, available at: www.whitehouse.gov/news/releases/2003/12/20031217-5.html (accessed April, 2008).
    • (2003) "Critical Infrastructure Identification, Prioritization, and Protection"
  • 11
    • 54949123284 scopus 로고    scopus 로고
    • DHS US Department of Homeland Security, Washington, DC, August, available at: (accessed April, 2008)
    • DHS (2006), "Homeland security advisories and information bulletins", US Department of Homeland Security, Washington, DC, August, available at: www.dhs.gov/xinfoshare/publications/ editorial_0335.shtm (accessed April, 2008).
    • (2006) "Homeland Security Advisories and Information Bulletins"
  • 12
    • 0242314137 scopus 로고    scopus 로고
    • DOE US Department of Energy, Washington, DC, September, available at: (accessed April, 2008)
    • DOE (2002), "21 steps to improve cyber security of SCADA network", US Department of Energy, Washington, DC, September, available at: www.oe.energy.gov/DocumentsandMedia/21_Steps_-_SCADA.pdf (accessed April, 2008).
    • (2002) "21 Steps To Improve Cyber Security of SCADA Network"
  • 13
    • 54949101492 scopus 로고    scopus 로고
    • DOE US Department of Energy, Washington, DC, July 16, available at: (accessed April, 2008)
    • DOE (2003), "Meeting brief: DOE/DHS SCADA meeting", US Department of Energy, Washington, DC, July 16, available at: www.oe.netl.doe.gov/docs/prepare/scada.pdf (accessed April, 2008).
    • (2003) "Meeting Brief: Doe/dhs SCADA Meeting"
  • 14
    • 54949112698 scopus 로고    scopus 로고
    • DOE US Department of Energy, Washington, DC, Computer Incident Advisory Capability, available at: (accessed April, 2008)
    • DOE (2005), "OpenSSL security vulnerabilities in ASN.1 parsing", US Department of Energy, Washington, DC, Computer Incident Advisory Capability, available at: www.ciac.org/ciac/bulletins/ n-159.shtml (accessed April, 2008).
    • (2005) "OpenSSL Security Vulnerabilities in ASN.1 Parsing"
  • 15
    • 54949126577 scopus 로고    scopus 로고
    • DOT US Department of Transportation, Washington, DC, available at: (accessed April, 2008)
    • DOT (2007), "Safety and security", US Department of Transportation, Washington, DC, available at: http:// transit-safety.volpe.dot.gov/ (accessed April, 2008).
    • (2007) "Safety and Security"
  • 18
    • 54949118171 scopus 로고    scopus 로고
    • "Linux in embedded industrial applications: A case study"
    • Fini, L. (2000), "Linux in embedded industrial applications: A case study", Linux Journal, Vol. 2000 No. 77, p. 12.
    • (2000) Linux Journal , vol.2000 , Issue.77 , pp. 12
    • Fini, L.1
  • 20
    • 84867375293 scopus 로고    scopus 로고
    • Frost and Sullivan company news, Frost and Sullivan, San Antonio, TX, available at: (accessed April, 2008), October 11
    • Frost and Sullivan (2001), "European SCADA systems market in dynamic shape", company news, Frost and Sullivan, San Antonio, TX, available at: www.engineeringtalk.com/news/fro/fro144.html (accessed April, 2008), October 11.
    • (2001) "European SCADA Systems Market in Dynamic Shape"
  • 22
    • 31944451961 scopus 로고    scopus 로고
    • "Security of critical control systems sparks concern"
    • Geer, D. (2006), "Security of critical control systems sparks concern", Computer, Vol. 39 No. 1, pp. 20-3.
    • (2006) Computer , vol.39 , Issue.1 , pp. 20-23
    • Geer, D.1
  • 23
    • 0011016060 scopus 로고    scopus 로고
    • "US fears Al Qaeda cyber attacks"
    • June 26
    • Gellman, B. (2002), "US fears Al Qaeda cyber attacks", Washington Post, June 26.
    • (2002) Washington Post
    • Gellman, B.1
  • 24
    • 0029681540 scopus 로고    scopus 로고
    • "A computer network with SCADA and case tools for on-line process control in greenhouses"
    • Gieling, T.H., van Meurs, W.M. and Janssen, H.J. (1996), "A computer network with SCADA and case tools for on-line process control in greenhouses", Advances in Space Research, Vol. 18 Nos 1/2, pp. 171-4.
    • (1996) Advances in Space Research , vol.18 , Issue.1-2 , pp. 171-174
    • Gieling, T.H.1    van Meurs, W.M.2    Janssen, H.J.3
  • 27
    • 0030102388 scopus 로고    scopus 로고
    • "Microcomputer-based remote terminal unit for a SCADA system"
    • Heng, G.T. (1996), "Microcomputer-based remote terminal unit for a SCADA system", Microprocessors and Microsystems, Vol. 20 No. 1, pp. 39-45.
    • (1996) Microprocessors and Microsystems , vol.20 , Issue.1 , pp. 39-45
    • Heng, G.T.1
  • 31
    • 54949112303 scopus 로고    scopus 로고
    • available at: (accessed April, 2008)
    • Kegel, D. (2001), "SSL/TLS", available at: www.kegel.com/ssl/ (accessed April, 2008).
    • (2001) "SSL/TLS"
    • Kegel, D.1
  • 37
    • 54949125545 scopus 로고    scopus 로고
    • NISCC UNIRAS: Computer Emergency Response Team, National Infrastructure Security Co-ordination Centre, London, November
    • NISCC (2003), Vulnerability Advisory 006489/OpenSSL, UNIRAS: Computer Emergency Response Team, National Infrastructure Security Co-ordination Centre, London, November.
    • (2003) Vulnerability Advisory 006489/OpenSSL
  • 38
    • 54949118573 scopus 로고    scopus 로고
    • OpenSSL available at: (accessed April, 2008)
    • OpenSSL (2007), "OpenSSL project homepage", available at: www.openssl.org/ (accessed April, 2008).
    • (2007) "OpenSSL Project Homepage"
  • 40
    • 36248937170 scopus 로고    scopus 로고
    • "Secure internet-based communication protocol for SCADA networks"
    • PhD dissertation, University of Louisville, Louisville, KY
    • Patel, S.C. (2006), "Secure internet-based communication protocol for SCADA networks", PhD dissertation, University of Louisville, Louisville, KY.
    • (2006)
    • Patel, S.C.1
  • 42
    • 67651162241 scopus 로고    scopus 로고
    • "Improving the cyber security of SCADA communication networks"
    • (in press).
    • Patel, S.C., Bhatt, G.D. and Graham, J. (2008), "Improving the cyber security of SCADA communication networks", Communications of ACM (in press)..
    • (2008) Communications of ACM
    • Patel, S.C.1    Bhatt, G.D.2    Graham, J.3
  • 44
    • 54949111847 scopus 로고    scopus 로고
    • "Supervisory control and data acquisition remote terminal unit testbed"
    • Department of Computer Engineering and Computer Science, University of Louisville, Louisville, KY
    • Patel, S., Tantalean, R., Ralston, P. and Graham, J. (2005b), "Supervisory control and data acquisition remote terminal unit testbed", Intelligent Systems Research Laboratory Technical Report TR-ISRL-05-01, Department of Computer Engineering and Computer Science, University of Louisville, Louisville, KY.
    • (2005) Intelligent Systems Research Laboratory Technical Report TR-ISRL-05-01
    • Patel, S.1    Tantalean, R.2    Ralston, P.3    Graham, J.4
  • 45
    • 54949144190 scopus 로고
    • "SCADA-Linux still hard at work"
    • February
    • Petree, V. (1995), "SCADA-Linux still hard at work", Linux Journal, Vol. 1995 No. 10, February.
    • (1995) Linux Journal , vol.1995 , Issue.10
    • Petree, V.1
  • 46
    • 54949101494 scopus 로고    scopus 로고
    • "Linux means business"
    • October
    • Petree, V. (1998), "Linux means business", Linux Journal, Vol. 1998 No. 54, October.
    • (1998) Linux Journal , vol.1998 , Issue.54
    • Petree, V.1
  • 48
    • 21644463808 scopus 로고    scopus 로고
    • "Slammer worm crashed Ohio nuke plant net"
    • available at: (accessed April, 2008)
    • Poulsen, K. (2003a), "Slammer worm crashed Ohio nuke plant net", The Register, available at: www.theregister.co.uk/2003/08/20/ slammer_worm_crashed_ohio_nuke/ (accessed April, 2008).
    • (2003) The Register
    • Poulsen, K.1
  • 49
    • 54949143046 scopus 로고    scopus 로고
    • "Brits found OpenSSL bugs"
    • September
    • Poulsen, K. (2003b), "Brits found OpenSSL bugs", SecurityFocus, September.
    • (2003) SecurityFocus
    • Poulsen, K.1
  • 50
    • 19244385561 scopus 로고    scopus 로고
    • "Implementation procedure of an advanced supervisory and control strategy in the pharmaceutical industry"
    • Preu, K., Le Lann, M-V., Cabassud, M. and Anne-Archard, G. (2003), "Implementation procedure of an advanced supervisory and control strategy in the pharmaceutical industry", Control Engineering Practice, Vol. 11 No. 12, pp. 1449-58.
    • (2003) Control Engineering Practice , vol.11 , Issue.12 , pp. 1449-1458
    • Preu, K.1    Le Lann, M.-V.2    Cabassud, M.3    Anne-Archard, G.4
  • 52
    • 22444432757 scopus 로고    scopus 로고
    • "Hacker jailed for revenge sewage attacks"
    • available at: (accessed April, 2008)
    • Smith, T. (2001), "Hacker jailed for revenge sewage attacks", The Register, available at: www.theregister.co.uk/2001/10/31/ hacker_jailed_for_revenge_sewage/ (accessed April, 2008).
    • (2001) The Register
    • Smith, T.1
  • 55
    • 0038182617 scopus 로고    scopus 로고
    • "A software framework for non-repudiation service in electronic commerce based on the internet"
    • Tak, S., Lee, Y. and Park, E.K. (2003), "A software framework for non-repudiation service in electronic commerce based on the internet", Microprocessors and Microsystems, Vol. 27 Nos 5/6, pp. 265-76.
    • (2003) Microprocessors and Microsystems , vol.27 , Issue.5-6 , pp. 265-276
    • Tak, S.1    Lee, Y.2    Park, E.K.3
  • 57
    • 54949121194 scopus 로고    scopus 로고
    • US-CERT United States Computer Emergency Readiness Team, Washington, DC, September, available at: (accessed April, 2008)
    • US-CERT (2004), "Technical cyber security alert TA04-111A: vulnerabilities in TCP", United States Computer Emergency Readiness Team, Washington, DC, September, available at: www.us-cert.gov/cas/ techalerts/TA04-111A.html (accessed April, 2008).
    • (2004) "Technical Cyber Security Alert TA04-111A: Vulnerabilities in TCP"
  • 58
    • 54949113480 scopus 로고    scopus 로고
    • US-CERT Vulnerability numbers: VU# 255484, VU# 380864, VU#686224, VU#732952, VU#935264, and VU#104280, United States Computer Emergency Readiness Team, Washington, DC, available at: (accessed April, 2008)
    • US-CERT (2007), "Advisory notes", Vulnerability numbers: VU# 255484, VU# 380864, VU#686224, VU#732952, VU#935264, and VU#104280, United States Computer Emergency Readiness Team, Washington, DC, available at: www.kb.cert.org/vuls (accessed April, 2008).
    • (2007) "Advisory Notes"
  • 59
    • 54949131965 scopus 로고    scopus 로고
    • "In bleak Russia, a young man's thoughts turn to hacking"
    • online, June
    • Varoli, J. (2000), "In bleak Russia, a young man's thoughts turn to hacking", The New York Times online, June.
    • (2000) The New York Times
    • Varoli, J.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.