Physics Reasoning for Intrusion Detection in Industrial Networks

被引:2
作者
Yahya, Mohammad [1 ]
Sharaf, Nasir [1 ]
Rrushi, Julian L. [1 ]
Tay, Ho Ming [2 ]
Liu, Bing [2 ]
Xu, Kai [2 ]
机构
[1] Oakland Univ, Dept Comp Sci & Engn, Rochester, MI 48309 USA
[2] Fortinet, Vancouver, BC, Canada
来源
2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020) | 2020年
关键词
Intrusion detection; industrial control systems; knowledge representation and reasoning; semantic web rule language;
D O I
10.1109/TPS-ISA50397.2020.00043
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Industrial control systems (ICS) exchange network traffic carrying payloads that are closely related to the physics of industrial equipment and processes. We leverage this factor to develop a machine reasoning approach that inspects network packet payloads in terms of their relationship to physics. We found that exploits and malware are unambiguously detected, since they inject machine instructions, addresses, and other data that clearly depart from physics. We developed an ontology integrated with the knowledge of physics, which we tested against exploits of a large number of public vulnerabilities that affect industrial control systems. We also ran our approach in several case studies that involved ICS control of an electrical motor, which we describe in the paper.
引用
收藏
页码:273 / 283
页数:11
相关论文
共 26 条
[1]  
[Anonymous], PLC BLASTER WORM LIV
[2]  
[Anonymous], 2010, IEEE Std, DOI [DOI 10.1109/IEEESTD.2010.5518537, 10.1109/IEEESTD.2010.5518537]
[3]  
[Anonymous], 2006, STAT ANAL EXECUTABLE
[4]  
Barnett B., 2012, EXPERIENCES USING SE
[5]  
Boivin A., 2018, THESIS UTLCA COLL
[6]  
Brunner C, 2008, TRANS DISTRIB CONF, P1342
[7]  
Case D.U, 2016, Electricity Information Sharing and Analysis Center (EISAC), V388
[8]  
Choras M, 2010, LECT NOTES ARTIF INT, V6096, P671, DOI 10.1007/978-3-642-13022-9_67
[9]  
Christodorescu M., 2004, Software Engineering Notes, V29, P34, DOI 10.1145/1013886.1007518
[10]  
[Earley M. NFPA NFPA], 2010, National Electrical Code 2011 handbook, V12th