Modbus/TCP için hafif sıklet şifrelemeli donanım modülü ile yeni bir güvenlik yaklaşımı
A new security approach with lightweight encrypted hardware module for Modbus/TCP
- Tez No: 988624
- Danışmanlar: DOÇ. DR. MURAT İSKEFİYELİ
- Tez Türü: Doktora
- Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
- Anahtar Kelimeler: Endüstriyel kontrol sistemleri, Kritik altyapıların korunması, Siber güvenlik, Veri şifreleme, Industrial control systems, Critical infrastructure protection, Cyber security, Data encryption
- Yıl: 2025
- Dil: Türkçe
- Üniversite: Sakarya Üniversitesi
- Enstitü: Fen Bilimleri Enstitüsü
- Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Belirtilmemiş.
- Sayfa Sayısı: Belirtilmemiş.
Özet
Endüstriyel kontrol sistemleri, hayatımızı doğrudan etkileyen elektrik, su, enerji gibi kritik alt yapıları yönetmek için kullanılmaktadır. Bu sistemlerde kullanılan haberleşme protokolleri tasarlandıkları yıl itibarıyla güvenlik parametreleri göz önüne bulundurulmadan geliştirilmiştir. Teknolojinin sürekli gelişiminden ötürü bu sistemler artık internete bağlı hale gelmişlerdir. Dolayısıyla bu sistemlerin yapısı birçok güvenlik tehdidine karşı savunmasız durumda olabilmektedir. Bu tezde, endüstriyel kontrol sistemlerinde en çok kullanılan Modbus/TCP protokolünün güvenlik açıklarını kapatmaya yönelik çalışma yapılmıştır. Modbus/TCP protokolü yapısı gereği, veri bütünlüğü, veri gizliliği ve oturum açma gibi temel güvenlik kontrollerine sahip değildir. Bu eksiklikler Modbus/TCP protokolünü kullanan sistemleri; hizmet reddi, ortadaki adam, paket dinleme, paket manipüle etme gibi birçok saldırıya karşı açık hedef haline getirmektedir. Bu durum protokole bir güvenlik katmanı eklenmesi ihtiyacını doğurmuştur. Bu sebeple, protokolün güvenliğini artırmak için endüstriyel sistemin çalışmasını olumsuz yönde etkilemeyecek yaklaşımlar kritik önem arz etmektedir. Bu problemleri çözmek için farklı tekniklerde fazla sayıda çalışma yapılmış ancak bu çalışmaların bir çoğu gerçek zamanlı sistem üzerinde uygulanabilir değildir. Yapılan çalışmalarda; makine öğrenmesi, derin öğrenme, kriptografik şifreleme gibi alanlarda bu sorunları çözmek için değerlendirmeler yapılmıştır. Makine öğrenmesi ve derin öğrenme tabanlı çözümlerde genellikle saldırı tespit veya engelleme sistemlerinin tasarlanması üzerine odaklanılmıştır. Kriptografik şifreleme tabanlı çözümlerin uygulanması esnasında şifreleme işlemlerinin hangi cihaz üzerinde yapılacağı tartışma konusu olmuştur. Endüstriyel cihazlar, düşük işlem kapasitesine sahip kaynak kısıtlı donanımlardır. Bu cihazlar üzerinde şifreleme yapıldığı düşünülürse, işlem gecikmesinden dolayı endüstriyel kontrol sisteminin işleyişi aksayabilir. Ayrıca, endüstriyel sistemlerde bulunan cihazların yazılımını güncellemek veya cihazların yenilenmesi büyük bir maliyet ve iş yükü oluşturmaktadır. Bu noktada, bu çalışmada şifreleme ve şifre çözme işlemleri için endüstriyel cihazların önüne bir modül yerleştirilmesi önerilmiştir. Böylelikle eski cihazlarla yaşanabilecek uyumluluk probleminin de önüne geçilmiştir. Önerilen modülü gerçekleştirmek için Raspberry Pi 4 ve Orange Pi R1 LTS Plus cihazları tercih edilmiştir. Orange Pi R1 LTS Plus cihazı kendi üzerinde çift ethernet portuna sahip olduğundan araya yerleştirme işlemine uygunken Raspberry Pi 4 cihazını araya yerleştirip bağlantı sağlamak için bir USB ethernet dönüştürücü kullanılmıştır. Modülü gerçekleştiren cihazlar üzerindeki ethernet arayüzleri köprü yapısı oluşturularak paketlerin arayüzler arasında yönlendirilmesi sağlanmıştır. Şifreleme işlemi aktif olmadığında gelen paketler direkt olarak hedef adrese doğru yönlendirilir. Şifreleme işlemi aktif olduğunda ise Modbus/TCP paketleri şifrelenmek üzere işleme alınmaktadır. Linux tabanlı işletim sistemi üzerinde Python programlama dili kullanılarak hafif sıklet şifreleme algoritmaları ile Modbus/TCP paketleri iki farklı senaryoda şifrelenmektedir. İlk olarak, Modbus/TCP protokolünün PDU alanı; ikinci olarak ise Modbus/TCP ADU alanı şifrelenmektedir. Her iki senaryoda da IP ve TCP başlık alanları şifrelenmemektedir. Tez çalışmasında, Python programlama dili ile aynı boyutta iki farklı fonksiyona ait Modbus/TCP paketleri oluşturulmuş, yedi adet hafif sıklet şifreleme algoritması ve şifreleme standardı olan AES algoritması ile oluşturulan bu paketler gönderen tarafta şifrelenmiş olup alıcı tarafta ise paketlerin şifresi çözülmüştür. Gönderilen Modbus/TCP paketleri Modbus fonksiyon kodu 15 olan Write Multiple Coils ve Modbus fonksiyon kodu 16 olan Write Multiple Register fonksiyonlarının verilerini içermektedir. Modbus/TCP verilerinin şifrelenmesi, gizlilik parametresinin gerçekleştirilmesini sağlamaktadır. Ancak, paketin değiştirilip değiştirilmediğinin ve tekrar gönderilip gönderilmediğinin bilgisine karşın bir çözüm sunmamaktadır. Bu hususta; bütünlük kontrolü için HMAC kodu ve tekrar gönderimin tespiti için nonce değeri önerilen modül üzerinde şifreleme esnasında Modbus/TCP paketine eklenmektedir. Bu eklenen iki özellikten alıcı taraftaki modül üzerinde öncelikle HMAC koduna bakılır, eğer hesaplanan değer ile uyuşmuyorsa paketin hedefe iletilmesi engellenir. Eğer HMAC kodu ve hesaplanan değer uyuşuyorsa bu sefer paketin şifresi çözülür ve nonce değeri kontrol edilir. Eğer nonce değeri daha önce gönderilen bir değer ise paketin hedefe ulaşması yine engellenir. Ancak daha önce gönderilmemiş bir değer ise paket başarıyla hedefe yönlendirilir. Çalışmada, Modbus master ve Modbus slave cihazlarını temsil etmek için bilgisayarlar üzerinde benzetim programları ve iki adet önerilen modül kullanarak test ortamı oluşturulmuştur. Önerilen şifreleme modülleri, bilgisayarlar arasında yerleştirilerek şifreleme ve şifre çözme için uygun ortam hazırlanmıştır. Önerilen modül çalıştırıldığında kullanıcıdan şifreleme algoritmasını ve şifreleme modunu seçmesini istemektedir. Performans testleri yapılmak üzere, her bir şifreleme algoritması ve şifreleme modu Modbus master cihazından 100 adet aynı boyutlu Write Multiple Coils paketi ve 100 adet aynı boyutlu Write Multiple Register paketi slave cihaza doğru gönderilmiştir. Gönderilen paketler, gönderici taraftaki modül üzerinde şifrelenmiş ve alıcı taraftaki modül üzerinde şifresi çözülmüştür. Tüm bu işlemler yapılırken şifreleme ve şifre çözme işlem süreleri kayıt altına alınmış olup çalışmada detaylı olarak verilmiştir. Yapılan ölçümler neticesinde işlem sürelerinin farklılıkları değerlendirilmiş olup kullanılan donanım, şifreleme algoritması, şifreleme modu ve Modbus fonksiyonu seçimlerinin performansa etkisi karşılaştırılmıştır. Ölçüm sonucunda elde edilen sürelere bakıldığında; AES, Grain, Simon ve XTEA algoritmalarının diğer şifreleme algoritmalarına göre hız açısından öne çıktığı görülmektedir. AES algoritması hafif sıklet şifreleme algoritması olmamasına rağmen bazı hafif sıklet şifreleme algoritmalarından üstün performans göstermiştir. Bu durumun sebebi, AES algoritmasının donanım hızlandırması desteğine sahip olmasıdır. Ayrıca, Raspberry Pi 4 ve Orange Pi R1 LTS Plus cihazlarının performansları karşılaştırıldığında Raspberry Pi 4 cihazının öne çıktığı da görülmektedir. Raspberry Pi 4 cihazının daha üstün donanım özelliklerine sahip olduğu göz önüne alındığında bu durumun normal olduğu anlaşılmaktadır. Elde edilen sonuçlar değerlendirildiğinde, hafif sıklet şifreleme algoritmalarının önerilen modüller kullanılarak Modbus/TCP paketleri üzerinde uygulanmasının performans bakımından kabul edilebilir bir işlem maliyeti oluşturduğu sonucuna varılmıştır. Şifreleme ve şifre çözme sürelerinin milisaniyeler boyutunda olması önerilen modülün gerçek zamanlı çalışan endüstriyel kontrol sistemlerinde kullanılabilir olduğunu göstermektedir. Ayrıca, üzerinde işlem yapılan Modbus/TCP paketinin boyutu sabit olsa dahi şifreleme sürelerinin değişken olabileceği ve bunun sebebinin algoritmaların yapısı, kullanılan donanım, sistemin o anki iş yükü gibi etkenlerle bağlantılı olduğu da çalışmada gösterilmiştir. Sonuç olarak bu tez çalışması, Modbus/TCP tabanlı endüstriyel ağ ortamında güvenliği artırmak için Raspberry Pi 4, Orange Pi R1 LTS Plus ve hafif sıklet şifreleme algoritmalarının kullanılanabilir olduğunu deneysel çalışmalar ile ortaya koymaktadır. Ek olarak, Modbus/TCP protokolüne eklenen alanlar ile birlikte güvenlik katmanı oluşturulmakla birlikte ortadaki adam, yeniden gönderme, yetkisiz erişim, hizmet reddi gibi saldırılara karşı koruma sağladığı gösterilmektedir. Son olarak bu çalışma, EKS güvenliği konusunda literatüre katkı sunarak gelecekte yapılacak donanım tabanlı çalışmalara temel oluşturmaktadır.
Özet (Çeviri)
Industrial control systems are used to manage critical infrastructures such as electricity, water, and energy, which directly impact our lives. The communication protocols used in these systems have been developed without considering security parameters since their conception. Due to the continuous advancement of technology, these systems are now connected to the Internet. Consequently, the structure of these systems can be vulnerable to numerous security threats. This thesis aims to address the security vulnerabilities of the Modbus/TCP protocol, one of the most commonly used in industrial control systems. The Modbus/TCP protocol, by its very nature, lacks fundamental security controls such as data integrity, data confidentiality, and login. These deficiencies make systems using the Modbus/TCP protocol vulnerable to numerous attacks, including denial of service, man-in-the-middle attacks, packet sniffing, and packet manipulation. This has led to the need to add a security layer to the protocol. Therefore, approaches that do not negatively impact the operation of industrial systems are critical for enhancing the security of protocol. Numerous studies have been published using various techniques to address these problems, but many are not applicable to real-time systems. Studies have evaluated these issues in areas such as machine learning, deep learning, and cryptographic encryption. Machine learning and deep learning-based solutions generally focus on designing intrusion detection or prevention systems. When implementing cryptographic encryption-based solutions, the appropriate device for encryption operations has been a matter of debate. Industrial devices are resource-constrained hardware with limited processing capacity. Given that encryption is performed on these devices, processing delays can disrupt the operation of the industrial control system. Furthermore, updating or upgrading the software of devices in industrial systems creates significant costs and workloads. Therefore, this study proposes placing a module in front of industrial devices for encryption and decryption. This avoids potential compatibility issues with older devices. Raspberry Pi 4 and Orange Pi R1 LTS Plus were chosen to implement the proposed module. The Orange Pi R1 LTS Plus device has dual Ethernet ports, making it suitable for placement between devices. A USB-to-Ethernet converter was used to connect a Raspberry Pi 4 device to the placement between devices. The Ethernet interfaces on the devices implementing the module are bridged, allowing packets to be routed between them. When encryption is disabled, incoming packets are routed directly to the destination address. When encryption is enabled, Modbus/TCP packets are processed for encryption. On a Linux-based operating system, Modbus/TCP packets are encrypted using lightweight encryption algorithms using the Python programming language in two different scenarios. First, the PDU of the Modbus/TCP protocol is encrypted; second, the ADU of the Modbus/TCP protocol is encrypted. In neither scenario are the IP and TCP header fields encrypted. In this thesis, Modbus/TCP packets of the same size were generated using the Python programming language for two different functions. These packets, generated using seven lightweight encryption algorithms and the AES encryption standard, were encrypted on the sender side and decrypted on the receiver side. The sent Modbus/TCP packets contained data have the Write Multiple Coils function (Modbus function code 15) and the Write Multiple Register function (Modbus function code 16). Encrypting Modbus/TCP data ensures the implementation of confidentiality parameter. However, no information whether the packet has been altered or retransmitted, this attempt does not provide a solution. In this regard, the HMAC code for integrity checking and the nonce value for retransmission detection are added to the Modbus/TCP packet during encryption in the proposed module. Of these two added features, the receiving module first examines the HMAC code; if it does not match the calculated value, the packet is prevented from being forwarded to the destination. If the HMAC code and the calculated value match, the packet is decrypted and the nonce value is checked. If the nonce value is a value that has been sent before, the packet is still blocked from reaching the destination. However, if it is a value that has not been sent before, the packet is successfully forwarded to the destination. In this study, a test environment is created on two proposed modules and two computers that using simulation programs to represent Modbus master and Modbus slave devices. The proposed encryption modules were placed between the computers to provide a suitable environment for encryption and decryption. When the proposed module is run, it prompts the user to select the encryption algorithm and encryption mode. To conduct performance tests, 100 identically sized Write Multiple Coils packets and 100 identically sized Write Multiple Register packets were sent from the Modbus master device to the slave device for each encryption algorithm and encryption mode. The sent packets were encrypted on the sender module and decrypted on the receiver module. The encryption and decryption processing times for all these processes were recorded and detailed in the study. Differences in processing times were evaluated based on the measurements, and the performance effects of the hardware, encryption algorithm, encryption mode, and Modbus function selections were compared. When looking at the measured times, the AES, Grain, Simon, and XTEA algorithms stand out in terms of speed compared to other encryption algorithms. Although the AES algorithm is not a lightweight encryption algorithm, it outperformed some lightweight encryption algorithms. This is due to the AES algorithm's hardware acceleration support. Furthermore, when comparing the performance of the Raspberry Pi 4 and the Orange Pi R1 LTS Plus devices, the Raspberry Pi 4 stands out. This is understandable given the Raspberry Pi 4's powerful hardware specifications. The results indicate that implementing lightweight encryption algorithms on Modbus/TCP packets using the proposed modules results in an acceptable processing cost in terms of performance. Encryption and decryption times in milliseconds demonstrate the proposed module's suitability for use in real-time industrial control systems. Furthermore, the study demonstrates that even when the Modbus/TCP packet being processed is fixed in size, encryption times can vary, depending on factors such as the algorithm structure, the hardware used, and the system's current workload. In conclusion, this thesis demonstrates through experimental studies that Raspberry Pi 4, Orange Pi R1 LTS Plus, and lightweight encryption algorithms can be used to enhance security in Modbus/TCP-based industrial networks. Furthermore, the addition of fields to the Modbus/TCP protocol provides a security layer, demonstrating protection against attacks such as man-in-the-middle, replay, unauthorized access, and denial of service. Finally, this study contributes to the literature on ICS security and lays the groundwork for future hardware-based studies.
Benzer Tezler
- Soren Aabye Kierkegaard'ın felsefesinde“Estetik Varoluş”un anlamı
Başlık çevirisi yok
AYŞE SERPİL BAHADIRLI
- Batı Ortaçağında hastalık kavramı
Başlık çevirisi yok
BERNA ARDA
Doktora
Türkçe
1993
Deontoloji ve Tıp TarihiAnkara ÜniversitesiDeontoloji Ana Bilim Dalı
PROF.DR. FUAT AZİZ GÖKSEL
- German ostpolitik before and after unification: Continuity and change
Başlık çevirisi yok
MAHMUT ŞENER
Yüksek Lisans
İngilizce
1994
Uluslararası İlişkilerİhsan Doğramacı Bilkent ÜniversitesiDOÇ.DR. GÜLGÜN TUNA