search query: @keyword tietoturva / total: 175
reference: 19 / 175
« previous | next »
Author:Leskinen, Jesse
Title:Assessing security of industrial control system environments
Teollisuuden automaatiojärjestelmien tietoturvan tarkastaminen
Publication type:Master's thesis
Publication year:2014
Pages:64      Language:   eng
Department/School:Perustieteiden korkeakoulu
Main subject:Tietoliikenneohjelmistot   (T3005)
Supervisor:Aura, Tuomas
Instructor:Sinnelä, Harri
Electronic version URL: http://urn.fi/URN:NBN:fi:aalto-201412033120
OEVS:
Electronic archive copy is available via Aalto Thesis Database.
Instructions

Reading digital theses in the closed network of the Aalto University Harald Herlin Learning Centre

In the closed network of Learning Centre you can read digital and digitized theses not available in the open network.

The Learning Centre contact details and opening hours: https://learningcentre.aalto.fi/en/harald-herlin-learning-centre/

You can read theses on the Learning Centre customer computers, which are available on all floors.

Logging on to the customer computers

  • Aalto University staff members log on to the customer computer using the Aalto username and password.
  • Other customers log on using a shared username and password.

Opening a thesis

  • On the desktop of the customer computers, you will find an icon titled:

    Aalto Thesis Database

  • Click on the icon to search for and open the thesis you are looking for from Aaltodoc database. You can find the thesis file by clicking the link on the OEV or OEVS field.

Reading the thesis

  • You can either print the thesis or read it on the customer computer screen.
  • You cannot save the thesis file on a flash drive or email it.
  • You cannot copy text or images from the file.
  • You cannot edit the file.

Printing the thesis

  • You can print the thesis for your personal study or research use.
  • Aalto University students and staff members may print black-and-white prints on the PrintingPoint devices when using the computer with personal Aalto username and password. Color printing is possible using the printer u90203-psc3, which is located near the customer service. Color printing is subject to a charge to Aalto University students and staff members.
  • Other customers can use the printer u90203-psc3. All printing is subject to a charge to non-University members.
Location:P1 Ark Aalto  2452   | Archive
Keywords:industrial control system
security
security assessment
ICS
security audit
SCADA
teollisuusautomaatio
tietoturva
tietoturvatarkastus
Abstract (eng):The security of industrial control systems (ICS) is vital for modern infrastructure.
Unfortunately the security of contemporary installations is often insufficient for the challenges posed by the current, networked and hostile environment.

There are on-going initiatives tasked with designing and creating new, secure ICS systems and standards.
Unfortunately these initiatives often fail to secure existing, legacy environments.
New methods are needed to evaluate and address the security needs of these existing environments to ensure their security in the modern operating environment.

This thesis presents a framework for assessing the security of existing industrial control system environments.
The framework consists of security goals, a risk model and assessment methods as well as guidance on applying these methods.
These tools are then used for evaluating the results of two industrial control system security assessments performed by the Nixu corporation.

The methodology presented in the thesis proved capable of covering and describing the security issues found in the studied environments.
This provides valuable information of the issues affecting the current legacy environments and is a useful starting point for future development on addressing and mitigating the security issues in existing environments.
Abstract (fin):Teollisuuden automaatiojärjestelmät ovat tärkeä osa modernia infrastruktuuria ja niiden turvaaminen on myös yhteiskunnallisesti merkittävä asia.
Tietoturvan osalta tätä tehtävää vaikeuttaa se, että monet näistä järjestelmistä ovat tietoturvaltaan puutteellisia nykyisen verkottuneen ja vihamielisen toimintaympäristön vaatimuksiin nähden.

Automaatiojärjestelmien tietoturvan parantamiseksi on aloitettu useita hankkeita, jotka pyrkivät luomaan sekä uusia, turvallisia standardeja, että näitä toteuttavia järjestelmiä.
Nämä hankkeet eivät kuitenkaan pysty suoraan korjaamaan olemassa olevien järjestelmien puutteita, jotka ovat lähtöisin laitosten suunnittelu vaiheista ja teknologiavalinnoista.

Tämä diplomityö tarjoaa käsitteistön ja mallin olemassa olevien automaatiojärjestelmien tietoturvan arvioimiseksi ja soveltaa näitä työkaluja kahteen Nixu Oy:n suorittamista automaatioympäristöjen tietoturva-arvioinneista.

Työssä esitelty toimintatapa ja menetelmät osoittautuivat soveliaiksi kuvaamaan ja kattamaan kohdeympäristöissä havaitut tietoturvaongelmat ja tarjoaa hyvän lähtökohdan näiden ongelmien korjaamiseen tähtäävään jatkokehitykseen.
ED:2014-12-21
INSSI record number: 50205
+ add basket
« previous | next »
INSSI