Abstract
The integration of cyber technologies (computing and communication) with the physical world gives rise to complex systems referred to as Cyber Physical Systems (CPS). CPS are complex systems that interact with the physical world therefore, it is necessary that those perform safely, reliably, securely and dependably in real time. The Industrial Control Systems (ICS) are a particular class of CPS. This dissertation focuses on the design of secure ICS. An ICS is composed of resource-constrained real-time devices, e.g., sensors, actuators and controllers. The data generated in an ICS is not authenticated, specially in legacy devices due to the computational constraints. An attacker can inject false data in the cyber and the physical domain. The traditional means for authentication relies on using passwords and cryptography. Resource-limited industrial devices might not support these solutions therefore, alternative authentication techniques based on device fingerprints are proposed in this dissertation. The first part of the dissertation is focused on the authentication of the sensors in an ICS. A combined fingerprint based on the sensor and process noise is used to uniquely identify the sensors. In the second part, unique features of a Programmable Logic Controller (PLC) are used to authenticate a PLC. A PLC watermarking technique is proposed to detect replay attacks. The proposed techniques are tested on operational water treatment and water distribution testbeds available at the Singapore University of Technology and Design. The results indicate that ICS devices can be authenticated without disturbing the operation of an industrial process plant.