Industrial IT Security – Development of a holistic security management concept for digital production
text
problem
Due to the future development in the context of Industry 4.0, the networking of the individual components continues to rise sharply, as cyber-physical systems increasingly interact autonomously with each other. Vulnerabilities in production systems in the form of design, implementation and configuration errors can therefore have dramatic consequences for the entire networked application. Vulnerabilities offer potential for unauthorized access and unwanted interventions in the production system and can lead, for example, to faulty production, the standstill of the plant or even to personal injury.
objective
The Industrial IT Security project involves the development of a holistic security management concept for digital production and is part of the doctoral programme ‘Digitalisation of Production’ at Saarland University.
Further information on this project as well as on all other projects of the doctoral college can be found at https://www.pk-digprod.de.
to the project websiteFurther information on this project as well as on all other projects of the doctoral college can be found at https://www.pk-digprod.de.
approach
analysis
Investigation and analysis of selected communication technologies. The focus is on PROFINET and OPC-UA. The risk analysis concerns the protocol structure and the associated services.
Investigation and analysis of selected communication technologies. The focus is on PROFINET and OPC-UA. The risk analysis concerns the protocol structure and the associated services.
expansion
The existing test environment will be extended by additional industrial components in order to be able to analyze both the state of the art and newly emerging Industry 4.0 systems.
Anomaly detection
Development of an anomaly detection and monitoring system to protect against cyberattacks. The communication history is checked in real time and anomaly information is visualized appropriately.
Test specification & Test execution
Test execution based on a real production process. The results can be used to formulate recommendations for action for future Industry 4.0 automation systems.

Category: Industrial security