A three-tiered intrusion detection system for industrial control systems

A three-tiered intrusion detection system for industrial control systems
复制标题

工业控制系统的三层入侵检测系统

DOI:
10.1093/cybsec/tyab006
复制
发表时间:
2021
影响因子:
3.9
通讯作者:
Anthi E
Anthi E
中科院分区:
--
文献类型:
--
作者:
Anthi E

文献摘要

参考文献

被引文献

相似文献

本文介绍了三层入侵检测系统,它使用监督的方法来检测工业控制系统网络中的网络攻击。所提出的方法不仅旨在识别网络上的恶意数据包,而且还试图识别网络上发生的一般和更细粒度的攻击类型。这在工业控制系统环境中至关重要,因为识别准确攻击类型的能力将提高对事件的响应率和基础设施的防御能力。更具体地说,所提出的系统包括三个阶段,旨在分类:(i)数据包是否是恶意的;(ii)恶意数据包的一般攻击类型(例如拒绝服务);以及(iii)更细粒度的网络攻击(例如坏循环冗余校验攻击)。从一个真实的工业气体管道系统收集的网络数据的建议入侵检测系统的有效性进行评估。此外,还提供了关于哪些功能在检测此类恶意行为时最相关的见解。该系统的性能结果在一个F-措施:(i)87.4%,(ii)74.5%和(iii)41.2%,分别为每一层。这表明,所提出的架构可以成功地区分网络活动是否是恶意的,并检测出部署了哪种一般攻击。
This article presents three-tiered intrusion detection systems, which uses a supervised approach to detect cyber-attacks in industrial control systems networks. The proposed approach does not only aim to identify malicious packets on the network but also attempts to identify the general and finer grain attack type occurring on the network. This is key in the industrial control systems environment as the ability to identify exact attack types will lead to an increased response rate to the incident and the defence of the infrastructure. More specifically, the proposed system consists of three stages that aim to classify: (i) whether packets are malicious; (ii) the general attack type of malicious packets (e.g. Denial of Service); and (iii) finer-grained cyber-attacks (e.g. bad cyclic redundancy check, attack). The effectiveness of the proposed intrusion detection systems is evaluated on network data collected from a real industrial gas pipeline system. In addition, an insight is provided as to which features are most relevant in detecting such malicious behaviour. The performance of the system results in anF-measure of: (i) 87.4%, (ii) 74.5% and (iii) 41.2%, for each of the layers, respectively. This demonstrates that the proposed architecture can successfully distinguish whether network activity is malicious and detect which general attack was deployed.
DOI: --
发表时间: 2006
期刊: --
影响因子: --
作者:
K. Stouffer;J. Falco;K. Kent;T. Grance;R. Ross
通讯作者: K. Stouffer;J. Falco;K. Kent;T. Grance;R. Ross
对工业控制系统的零残留攻击和状态对策
DOI: --
发表时间: 2019
期刊: ARES
影响因子: --
作者:
H. R. Ghaeini;Nils Ole Tippenhauer;Jianying Zhou
通讯作者: Jianying Zhou
用于入侵检测系统研究的新 SCADA 数据集
DOI: --
发表时间: 2021
期刊:
影响因子: --
作者:
Ian P. Turnipseed
通讯作者: Ian P. Turnipseed