Under the background of industrial intelligence, OPC UA PubSub mode is strongly supported by Industry 4.0 as a protocol designed to meet the communication requirements of industrial control level. With the gradual opening of industrial control network, the PubSub security model in OPC UA protocol alone cannot meet the new security requirements under the background of OT and IT integration. According to the specification, we analyze the possible threats, impacts and countermeasures that PubSub may face in OPC UA deployment environment, and emphasized that PubSub security model is difficult to protect resource-constrained industrial field equipment from the harm caused by DoS and other attacks. In view of the limited resources of industrial control network, this paper proposes that OTG gateway provides protection for PubSub service. Compared with traditional security gateway, OTG gateway can greatly reduce the consumption of industrial control network resources by network attacks. In addition, according to the characteristics of PubSub protocol, a DoS detection algorithm for this architecture is proposed. Compared with the traditional DoS detection algorithm, it has better applicability to PubSub protocol and can detect DoS attacks more accurately to reduce the impact on device performance. Experiments show that the DoS detection algorithm has 100% accuracy and 0.13% false positive rate, and can detect DoS attacks faster than the traditional detection algorithm.
As a new generation of OPC protocol, OPC UA provides a standardized interoperability solution for industrial automation. In order to accelerate the application of OPC UA in industrial control networks, OPC Foundation published OPC UA PubSub protocol. With the gradual opening of industrial control network, the security risks of deep manufacturing facilities are greatly increased, so it is urgent to study the security protection of PubSub protocol. Based on PubSub protocol, we study the characteristics of its deployment environment and the security threats it faces, and point out the defects and solutions of PubSub protocol's own security protection mechanism. At the same time, we propose a security gateway model OSG, which is established between the field equipment layer and the field control layer, in order to deal with the security risks existing in the PubSub protocol.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.
customersupport@researchsolutions.com
10624 S. Eastern Ave., Ste. A-614
Henderson, NV 89052, USA
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Copyright © 2025 scite LLC. All rights reserved.
Made with 💙 for researchers
Part of the Research Solutions Family.