SCADA Networks Anomaly-based Intrusion Detection System

被引:0
作者
Almehmadi, Abdulaziz [1 ]
机构
[1] Univ Tabuk, Tabuk, Saudi Arabia
来源
11TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS (SIN 2018) | 2018年
关键词
Anomaly-based Intrusion Detection System; SCADA;
D O I
10.1145/3264437.3264471
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intentional attacks(1) that cause country wide blackouts, gas and water systems malfunction are actions that can be carried out by a nation to impact on another nation in a mean of war. Supervisory control and data acquisition (SCADA) networks that allow for communication for the utilities companies were designed with no security in mind causing the systems that a nation relies on to fall vulnerable to exploitation. Since SCADA networks are static in nature with pre-defined signatures of network traffic, we propose to design an anomaly-based intrusion detection system to detect abnormality in SCADA network traffic and protocols. We gather normal SCADA network traffic via tapping on the network for 30 days and then attack the network using Denial of Service (DoS) attack, message spoofing attack and man-in-the middle attack. We then train a classifier with two classes, normal and abnormal and report the classifier accuracy in detecting abnormal SCADA network traffic.
引用
收藏
页数:4
相关论文
共 18 条
[1]  
Alder R., 2007, SNORT IDS IPS TOOLKI
[2]  
[Anonymous], 2006, Securing SCADA Systems
[3]  
[Anonymous], 2010, P 1 WORKSH SEC CONTR
[4]  
Axelsson S., 2000, ACM Transactions on Information and Systems Security, V3, P186, DOI 10.1145/357830.357849
[5]  
Barbosa RRR, 2010, LECT NOTES COMPUT SC, V6155, P163, DOI 10.1007/978-3-642-13986-4_23
[6]  
Bigham J, 2003, LECT NOTES COMPUT SC, V2776, P171
[7]  
Carcano A, 2010, LECT NOTES COMPUT SC, V6027, P138
[8]  
Fovino IN, 2010, IFIP ADV INF COMM TE, V342, P95
[9]  
Fovino Igor Nai, 2010, ADV INF NETW APPL AI
[10]  
Hink RCB, 2014, INT SYMP RESIL CONTR