5.1.1 Overview

The following sub-clauses 5.1.2 through 5.1.15 reconcile the threats that were described in 4.3 against the OPC UA functions. Compared to the reconciliation with the objectives that will be given in 5.2, this is a more specific reconciliation that relates OPC UA security functions to specific threats. A summary of the reconciliation is available in Table 1. Only eavesdropping and Server profiling require SignAndEncrypt while all other are mitigated with SignOnly. [ (X) indicates indirectly].

Table 1 – Security Reconciliation Threats Summary
Attacks AuthenticationAuthorizationConfidentialityIntegrityAuditabilityAvailabilityNon-Repudiation
Denial of ServiceX
Eaves DroppingXXX
Message SpoofingX
Message AlterationXXXXX
Message ReplayXX
Malformed MessagesX
Server Profiling(X)(X)(X)(X)(X)(X)(X)
Session HijackingXXXXXXX
Rogue ServerXXXXX
Rogue PublisherXXXX
Rogue Local DiscoveryXXXXX
Compromising User CredentialsXXX
RepudiationX
Message SuppressionXX
Downgrade AttackXX