An architecture for SCADA network forensics

被引:0
作者
Kilpatrick, T. [1 ]
Gonzalez, J. [1 ]
Chandia, R. [1 ]
Papa, M. [1 ]
Shenoi, S. [1 ]
机构
[1] Univ Tulsa, Tulsa, OK 74104 USA
来源
ADVANCES IN DIGITAL FORENSICS II | 2006年 / 222卷
关键词
process control systems; SCADA networks; network forensics;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Supervisory control and data acquisition (SCADA.) systems are widely used in industrial control and automation. Modern SCADA protocols often employ TCP/IP to transport sensor data and control signals. Meanwhile, corporate IT infrastructures are interconnecting with previously isolated SCADA networks. The use of TCP/IP as a carrier protocol and the interconnection of IT and SCADA networks raise serious security issues. This paper describes an architecture for SCADA network forensics. In addition to supporting forensic investigations of SCADA network incidents, the architecture incorporates mechanisms for monitoring process behavior, analyzing trends and optimizing plant performance.
引用
收藏
页码:273 / +
页数:3
相关论文
共 24 条
  • [1] *AM GAS ASS, 2005, 1I AGA 1
  • [2] *AM NAT STAND I IN, 2004, ANSIISATR9900012004
  • [3] *AM NAT STAND I IN, 2004, ANSIISATR9900022004
  • [4] *AM PETR I, 2004, 1164 API
  • [5] American Gas Association, 2005, 12 AGA 2
  • [6] [Anonymous], TRISRL0401 U LOUISV
  • [7] [Anonymous], 2004, SCADA: Supervisory controlo and data aquisition
  • [8] [Anonymous], SYST PROT PROF IND C
  • [9] [Anonymous], 2004, MODBUS MESS TCP IP I
  • [10] Berg M., 2005, SAND20051000C SAND N