A real-time anomaly-based IDS for cyber-attack detection at the industrial process level of Critical Infrastructures

被引:25
作者
Clotet, Xavier [1 ]
Moyano, Jose [1 ]
Leon, Gladys [1 ]
机构
[1] Aplicac Informat Avanzada SL, Sant Cugat Del Valles, Spain
关键词
Critical Infrastructure Protection; Cyber security; Negative selection algorithm; Intrusion detection system; Anomaly detection; Industrial process level of critical; infrastructures;
D O I
10.1016/j.ijcip.2018.08.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This work presents a real time anomaly-based detection system designed to work at the industrial process level of Critical Infrastructures (CI). The system's core algorithm is based on negative selection and works in two phases: it first learns from the normal behaviour of the process, and then performs detection and raises alarms each time an abnormal behaviour is found. The main goal of the proposed tool is the detection of attacks targeting the physical components or devices composing the industrial process level of CI such as electric, gas or water utilities. The proposed IDS uses a multi-agent approach to tackle the complex problem of monitoring large amounts of data coming from measurements recorded by Industrial Control Systems. It was built on an open source distributed computation system for real time analysis. This tool was developed, tested, and validated during the EU-funded project PREEMPTIVE. Detection results obtained on a water treatment plant laboratory are presented and discussed. (C) 2018 Elsevier B.V. All rights reserved.
引用
收藏
页码:11 / 20
页数:10
相关论文
共 25 条
[21]  
Urbina D.I., 2016, SURVEY NEW DIRECTION
[22]  
Wang Y, 2014, LECT NOTES COMPUT SC, V8713, P401, DOI 10.1007/978-3-319-11212-1_23
[23]  
Zaki Mohammed J., 2014, Data Mining and Analysis: Fundamental Concepts and Algorithms
[24]  
Zamor M.-A., 2016, INTRUSION DETECTION
[25]   Distributed Intrusion Detection System in a Multi-Layer Network Architecture of Smart Grids [J].
Zhang, Yichi ;
Wang, Lingfeng ;
Sun, Weiqing ;
Green, Robert C., II ;
Alam, Mansoor .
IEEE TRANSACTIONS ON SMART GRID, 2011, 2 (04) :796-808