In recent years, several important initiatives have appeared worldwide, aimed at bringing significant innovation in next generations of industrial networked systems (INSs). For example, the Industry 4.0 and Factory of the Future frameworks are paving the way to modern intelligent factories, where issues such as the communication complexity between smart devices or the system on-the-fly reconfiguration are dealt with in efficient and cost-effective ways. However, global connectivity also implies constant increase of cyber menaces targeting industrial systems, so that security must be considered since the very beginning when new appealing solutions are conceived. In this paper, we exploit the innovative Software Defined Networking (SDN) paradigm to introduce improvements in managing the network infrastructure of INSs, as this can help in reducing the management costs and complexity. In particular, enhanced SDN functionalities are adopted, which are able to provide security support in additions to their native switching/routing functionalities. The paper also shows how this approach can overcome some limitations of many current INS security architectures. The feasibility of the proposed solution is confirmed by the development of a simple laboratory prototype based on commodity hardware, and used to obtain some preliminary evaluation of the achievable functionality and performance benefits.

Leveraging SDN To Improve Security in Industrial Networks / Cheminod, Manuel; Durante, Luca; Seno, Lucia; Valenza, Fulvio; Valenzano, Adriano; Zunino, Claudio. - ELETTRONICO. - (2017). (Intervento presentato al convegno 13th IEEE International Workshop on Factory Communication Systems tenutosi a Trondheim (NO) nel May 31 - June 2) [10.1109/WFCS.2017.7991960].

Leveraging SDN To Improve Security in Industrial Networks

CHEMINOD, MANUEL;DURANTE, LUCA;VALENZA, FULVIO;VALENZANO, ADRIANO;ZUNINO, CLAUDIO
2017

Abstract

In recent years, several important initiatives have appeared worldwide, aimed at bringing significant innovation in next generations of industrial networked systems (INSs). For example, the Industry 4.0 and Factory of the Future frameworks are paving the way to modern intelligent factories, where issues such as the communication complexity between smart devices or the system on-the-fly reconfiguration are dealt with in efficient and cost-effective ways. However, global connectivity also implies constant increase of cyber menaces targeting industrial systems, so that security must be considered since the very beginning when new appealing solutions are conceived. In this paper, we exploit the innovative Software Defined Networking (SDN) paradigm to introduce improvements in managing the network infrastructure of INSs, as this can help in reducing the management costs and complexity. In particular, enhanced SDN functionalities are adopted, which are able to provide security support in additions to their native switching/routing functionalities. The paper also shows how this approach can overcome some limitations of many current INS security architectures. The feasibility of the proposed solution is confirmed by the development of a simple laboratory prototype based on commodity hardware, and used to obtain some preliminary evaluation of the achievable functionality and performance benefits.
2017
978-150905788-7
File in questo prodotto:
File Dimensione Formato  
07991960.pdf

non disponibili

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Non Pubblico - Accesso privato/ristretto
Dimensione 288.4 kB
Formato Adobe PDF
288.4 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
2017WFCS_SDN_author.pdf

accesso aperto

Tipologia: 2. Post-print / Author's Accepted Manuscript
Licenza: PUBBLICO - Tutti i diritti riservati
Dimensione 339.73 kB
Formato Adobe PDF
339.73 kB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/2673926