MITRE ICS Attack Simulation and Detection on EtherCAT Based Drinking Water System
MITRE ICS Attack Simulation and Detection on EtherCAT Based Drinking Water System
复制标题
基于 EtherCAT 饮用水系统的 MITRE ICS 攻击模拟与检测
DOI:
10.1109/isdfs52919.2021.9486331
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
I. Özçelik
中科院分区:
文献类型:
--
作者:
Firdevs Sevde Toker;Kevser Ovaz Akpinar;I. Özçelik
Industrial control systems (ICSs) are complex systems due to the technology and protocol diversity they contain. Operational Technology (OT), an ICS operating structure, has different performance and security requirements than the standard IT infrastructure. ICS systems consist of field devices where operational processes take place and control systems that provide management of these devices. Attackers are involved in the whole process after gaining access from the control layer. As a result, critical infrastructure systems are threatened by cyber-attacks. Therefore, continuous monitoring and security audits are also necessary processes for critical infrastructures. In this study, studies on the cyberattack and detection system were carried out on the critical infrastructures of the water management process. On the EtherCAT-based water management process, six different attack vectors for field devices were developed by the techniques in the MITRE ICS ATT&CK matrix, and these attacks were separated by data obtained from network traffic and determined by the SVM algorithm. Attack scenarios were created by selecting seven different MITRE ICS ATT&CK matrix techniques for attacks on the SCADA system in the control center via the engineering computer on the same process. Wazuh HIDS was used for the intrusion detection system for the SCADA system. Visualization of both attacks was done on ELK.