Transactions of the Society of Instrument and Control Engineers
Online ISSN : 1883-8189
Print ISSN : 0453-4654
ISSN-L : 0453-4654
Paper
Low and Deterministic Latency Firewall for Cybersecurity in Real-time Control Systems
Hiroshi IWASAWAHiromichi ENDOHTatsuya MARUYAMANoritaka MATSUMOTOTsutomu YAMADA
Author information
JOURNAL FREE ACCESS

2020 Volume 56 Issue 2 Pages 51-56

Details
Abstract

Considering cybersecurity for industrial control systems (ICS), the latency of a firewall could affect a timing restriction of a real-time control loops. To solve this issue, we propose the “real-time firewall”, the low and deterministic latency firewall for control networks. It employs on-the-fly rule matching method to minimize the latency of the firewall, which modifies the FCS (Frame Check Sequence) field of Ethernet frames to discard malicious frames. It also employs the Shift-and algorithm for signature pattern matching. We prototyped the real-time firewall using an FPGA and evaluated it, then confirmed that 1) it does not limit the throughput of 100BASE-TX wire speed, and 2) the latency ranges from 2.12µs to 2.2µs regardless of the frame size or the number of matching patterns to be inspected.

Content from these authors
© 2020 The Society of Instrument and Control Engineers
Previous article Next article
feedback
Top