Automated testing of industrial control devices: the delphi database

  • Authors:
  • Nate Kube;Kevin Yoo;Daniel Hoffman

  • Affiliations:
  • Wurldtech Security Technologies, Vancouver, BC, Canada;Wurldtech Security Technologies, Vancouver, BC, Canada;University of Victoria, Victoria, BC, Canada

  • Venue:
  • Proceedings of the 6th International Workshop on Automation of Software Test
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Delphi is a database designed to centralize and distribute current industrial automation vulnerability information. Over the past two years, with the aid of many of the world's largest equipment vendors and operators, we have populated this databse through extensive testing of industrial control devices. Delphi stores over 500 vulnerabilities on 31 popular distributed control system and safety instrumented system controllers. There are two primary reasons why Delphi data is useful: to distribute vulnerability data and to improve mitigation strategies. With detailed knowledge of which vulnerabilities are present, vendors can produce more robust devices and operators can construct business cases and calculate return-on-investment when considering investments in security measures. Furthermore, known vulnerabilities can be mitigated without applying device patches and shutting down plant operations.