SCADA Security Testbed
A Live, Virtual and Constructive (LVC) SCADA Security testbed to simulate/analyze attack scenarios.
Brief Description
Supervisory Control and Data Acquisition (SCADA) Testbed is modeled in defense-in-depth architecture and used to simulate attacks. SCADA Testbed can be used to assess the vulnerabilities and analyze the impact of attacks on the performance and availability of SCADA systems.
The LVC based approach provides a high degree of fidelity and is also cost effective. Constructing a SCADA testbed is a challenging and tedious process even with the aid of the advanced modern computing technologies; it can be difficult to obtain a realistic testbed scale and configuration. Based on the requirements provided by utilities, the testbed will be modeled. After modeling, the testbed can be used as a service also for vulnerability/ impact analysis .
Use Cases
1.Vulnerability analysis – find weaknesses in the OT system and analyze the impact of attacks on the performance & availability of SCADA systems.
2.Disturbance scenarios – simulate different attack scenarios
3.Training and education – operators can be trained to understand attacks
4.Data and logs analysis – analyze the characteristics of different hackers
5. Mitigation module – evaluate different mitigation strategies
Salient Features
1.Provides a complete attack simulation, monitoring and management environment for various SCADA attacks
2. Provides tools such as SPADE for SCADA Protocol analysis and anomaly detection. Enabled with Protocol level DPI and DCI.
3. Tailor-made for SCADA Systems and supports MODBUS and IEC 104 protocol.
4. Uses automated log collection, correlation, data aggregation, analysis of attack logs and retention for anomaly detection and forensics investigation
5. Supports Behavior analysis and Network analysis of malwares
6.Provides operational dashboard for analysis, retention of events data and web based administration
Technical Specifications
Model Specification
Level 0 -
Software - Simulators for Actuators/Sensors
Level 1 -
Hardware Components - Physical & Virtual RTU and PLC, AMT Sensor, Switch, Firewall, AMT Local Server
Software Components - SCADA Protocol Anomaly Detector(SPADE), Firewall, AMT Local Server.
Level 2 -
Hardware Components - MTU, HMI, Log Collector
Software Components - Log Collector Agents
Level 3 -
Hardware Components - AMT Centralized Server, SOC Server
Software Components - AMT Centralized Server, SOC Server
Operational Specification
SCADA testbed follows the Live, Virtual and Constructive (LVC) model.
Real time simulation of attacks in a controlled environment
Monitoring and analysis of networks with the standard Purdue Model based segmentation.
Scalable architecture
Contact Details
Name : L Mahendra
E-mail Id : rtsg@cdac.in