MITRE ICS Attack Simulation and Detection on EtherCAT Based Drinking Water System

MITRE ICS Attack Simulation and Detection on EtherCAT Based Drinking Water System
复制标题

基于 EtherCAT 饮用水系统的 MITRE ICS 攻击模拟与检测

DOI:
10.1109/isdfs52919.2021.9486331
复制
发表时间:
2021
期刊:
International Symposium on Digital Forensics and Security
影响因子:
--
通讯作者:
I. Özçelik
I. Özçelik
中科院分区:
--
文献类型:
--
作者:
Firdevs Sevde Toker;Kevser Ovaz Akpinar;I. Özçelik

文献摘要

被引文献

相似文献

工业控制系统(ICS)是一个复杂的系统,因为它们包含的技术和协议的多样性。运营技术(OT)是一种ICS运营结构,具有与标准IT基础设施不同的性能和安全要求。ICS系统由操作过程发生的现场设备和提供这些设备的管理的控制系统组成。攻击者在从控制层获得访问权后参与整个过程。因此,关键基础设施系统受到网络攻击的威胁。因此,持续监控和安全审计也是关键基础设施的必要流程。在这项研究中,对水管理过程中的关键基础设施进行了网络攻击和检测系统的研究。在基于EtherCAT的水资源管理过程中,利用MITRE ICS ATT&CK矩阵中的技术,开发了6种针对现场设备的攻击向量,并通过从网络流量中获取的数据分离出这些攻击向量,利用SVM算法确定攻击向量。通过选择七种不同的MITRE ICS ATT&CK矩阵技术,通过同一过程中的工程计算机对控制中心的SCADA系统进行攻击,创建了攻击场景。Wazuh HIDS用于SCADA系统的入侵检测系统。两次攻击的可视化都是在ELK上完成的。
Industrial control systems (ICSs) are complex systems due to the technology and protocol diversity they contain. Operational Technology (OT), an ICS operating structure, has different performance and security requirements than the standard IT infrastructure. ICS systems consist of field devices where operational processes take place and control systems that provide management of these devices. Attackers are involved in the whole process after gaining access from the control layer. As a result, critical infrastructure systems are threatened by cyber-attacks. Therefore, continuous monitoring and security audits are also necessary processes for critical infrastructures. In this study, studies on the cyberattack and detection system were carried out on the critical infrastructures of the water management process. On the EtherCAT-based water management process, six different attack vectors for field devices were developed by the techniques in the MITRE ICS ATT&CK matrix, and these attacks were separated by data obtained from network traffic and determined by the SVM algorithm. Attack scenarios were created by selecting seven different MITRE ICS ATT&CK matrix techniques for attacks on the SCADA system in the control center via the engineering computer on the same process. Wazuh HIDS was used for the intrusion detection system for the SCADA system. Visualization of both attacks was done on ELK.