Security-Testing

Security-Testing
Description
Industrial automation and control systems (IACS) play a major role in modern production systems. Their robustness and security are becoming increasingly important as the interconnectivity increases. Highly connected IACS are particularly vulnerable to remote attacks, as they can be reached by an attacker from the network and can also influence the production process. In principle, it is possible for an attacker to cause damage to the production process without physical access. For example, an attacker can achieve this by exploiting vulnerabilities in the IACS. For this reason, it is necessary to avoid vulnerabilities in IACS. One way of doing this is security testing. The aim here is to uncover vulnerabilities during the development of IACS. If the vulnerabilities are found during the development process, they can be closed before the IACS is used in production.
In our security testing laboratory, automation components can be analysed using various types of security testing. We focus on automated black box tests via an Ethernet interface. In black box tests, the system to be tested is only viewed from the outside; knowledge about internal details does not have to be included in the test. In addition to standard network protocols, our laboratory also examines weak points industrial network stacks such as PROFINET or MODBUS/TCP. If the analysed system offers a website, this is also checked for vulnerabilities. The ISuTest security testing framework developed at Fraunhofer IOSB, an Achilles Testing Platform from GE and various other supporting tooles are used to this end.
Our systems are constantly evaluated and further developed through regular security tests of real hardware in our security testing laboratory. This ensures that they fulfil the current requirements for security tests in the field of industrial automation components.
Previous tests have included analysing bus couplers, (safety) controllers, switches, and edge devices for existing vulnerabilities. We have also analysed medical devices and OPC UA environments. It is generally possible to analyse all systems that provide communication via an Ethernet interface.
Our well-equipped security testing laboratory enables us to offer various services. We can carry out security tests for manufacturers in our laboratory for which the above-mentioned test methods can be used. We can also make our laboratory available to manufacturers who wish to have their hardware tested by their own developers using our environment. If the aim is to carry out the hardware tests in-house in the long term, we can also provide advice on setting up a security testing laboratory at the manufacturer's premises.
The topic of security testing and the establishment and further development of a security testing laboratory is also being part of various research projects. Our tools are constantly evaluated and further developed through regular security tests of real hardware in our security testing laboratory. This ensures that they can fulfil the current requirements for security tests in the field of industrial automation components.