Intrusion Detection System for IEC 60870-5-104 Based SCADA Networks

被引:0
作者
Yang, Y. [1 ]
McLaughlin, K. [1 ]
Littler, T. [1 ]
Sezer, S. [1 ]
Pranggono, B. [1 ]
Wang, H. F. [2 ]
机构
[1] Queens Univ Belfast, Elect Elect Engn & Comp, Belfast, Antrim, North Ireland
[2] Brunel Univ, Sch Engn & Design, Uxbridge UB8 3PH, Middx, England
来源
2013 IEEE POWER AND ENERGY SOCIETY GENERAL MEETING (PES) | 2013年
基金
英国工程与自然科学研究理事会;
关键词
SCADA; Cyber-security; IEC; 60870-5-104; Intrusion detection system;
D O I
暂无
中图分类号
TE [石油、天然气工业]; TK [能源与动力工程];
学科分类号
0807 ; 0820 ;
摘要
Increased complexity and interconnectivity of Supervisory Control and Data Acquisition (SCADA) systems in Smart Grids potentially means greater susceptibility to malicious attackers. SCADA systems with legacy communication infrastructure have inherent cyber-security vulnerabilities as these systems were originally designed with little consideration of cyber threats. In order to improve cyber-security of SCADA networks, this paper presents a rule-based Intrusion Detection System (IDS) using a Deep Packet Inspection (DPI) method, which includes signature-based and model-based approaches tailored for SCADA systems. The proposed signature-based rules can accurately detect several known suspicious or malicious attacks. In addition, model-based detection is proposed as a complementary method to detect unknown attacks. Finally, proposed intrusion detection approaches for SCADA networks are implemented and verified via Snort rules.
引用
收藏
页数:5
相关论文
共 11 条
[1]  
[Anonymous], 2009, 62351 IEC 5
[2]  
[Anonymous], 60870 IEC 5
[3]  
[Anonymous], 2003, 60870 IEC 5
[4]  
Arboleda A. F., 2005, SNORT DIAGRAMS DEV
[5]   A Multidimensional Critical State Analysis for Detecting Intrusions in SCADA Systems [J].
Carcano, A. ;
Coletta, A. ;
Guglielmi, M. ;
Masera, M. ;
Fovino, I. Nai ;
Trombetta, A. .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2011, 7 (02) :179-186
[6]  
Cheung S., P 2007 SCADA SEC SCI, P127
[7]  
Ghorbani AA, 2010, ADV INFORM SECUR, V47, P27, DOI 10.1007/978-0-387-88771-5_2
[8]  
Morris T., P 2012 45 HAW INT C, P2338
[9]   An Intrusion Detection System for IEC61850 Automated Substations [J].
Premaratne, Upeka Kanchana ;
Samarabandu, Jagath ;
Sidhu, Tarlochan S. ;
Beresh, Robert ;
Tan, Jian-Cheng .
IEEE TRANSACTIONS ON POWER DELIVERY, 2010, 25 (04) :2376-2383
[10]   Using Internet Protocols to Implement IEC 60870-5 Telecontrol Functions [J].
Sanchez, Gemma ;
Gomez, Isabel ;
Luque, Joaquin ;
Benjumea, Jaime ;
Rivera, Octavio .
IEEE TRANSACTIONS ON POWER DELIVERY, 2010, 25 (01) :407-416