Cyber-Physical Systems Security

  1. Network Security for CPS
    1. Network Architecture Design
      1. Network Segmentation
        1. IT/OT Separation
          1. Zone-Based Architecture
            1. VLAN Implementation
            2. The Purdue Model
              1. Level 0 through Level 5
                1. Data Flow Control
                  1. Security Zones
                  2. Industrial DMZ Design
                    1. Purpose and Function
                      1. Component Placement
                        1. Access Control
                      2. Perimeter Security Controls
                        1. Firewalls for Industrial Networks
                          1. Stateful Inspection
                            1. Application Layer Filtering
                              1. Protocol-Aware Filtering
                              2. Intrusion Detection Systems
                                1. Signature-Based Detection
                                  1. Anomaly-Based Detection
                                    1. Behavioral Analysis
                                    2. Intrusion Prevention Systems
                                      1. Active Response Mechanisms
                                        1. Automated Blocking
                                      2. Secure Remote Access
                                        1. VPN Technologies
                                          1. Site-to-Site VPNs
                                            1. Remote Access VPNs
                                              1. VPN Protocols
                                              2. Multi-Factor Authentication
                                                1. Token-Based Authentication
                                                  1. Biometric Authentication
                                                    1. Certificate-Based Authentication
                                                    2. Jump Servers and Bastion Hosts
                                                    3. Network Monitoring and Analysis
                                                      1. Traffic Analysis
                                                        1. Protocol Monitoring
                                                          1. Anomaly Detection
                                                            1. Security Information and Event Management