A Novel IDS Securing Industrial Control System of Critical Infrastructure Using Deception Technology

被引:0
作者
Zhang, Shaobo [1 ]
Liu, Yuhang [2 ]
Yang, Dequan [1 ]
机构
[1] Beijing Inst Technol, Beijing, Peoples R China
[2] Peking Univ, Beijing, Peoples R China
关键词
Critical Infrastructure; Honeypot; Industrial Control System; Intrusion Detection System; INTERNET;
D O I
10.4018/IJDCF.302874
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The industrial control system (ICS) has become the key concept in the modern industrial world, enabling process monitoring and system control for general industrial systems and critical infrastructures. High-skilled hackers can invade an imperfect ICS by existing vulnerabilities without much effort. Conventional defenses (such as encryption and firewall) to keep invaders away are getting less effective when an attack is carried out by exploiting an array of particular vulnerabilities. Under this circumstance, a new-type intrusion detection system (IDS) based on deception strategy using honeypot technique is proposed, which is of dramatic effectiveness in protecting ICSs of critical infrastructures. In this honeypot-based model, the authors capture malicious internet flows and system operations. They analyze the collected data before alerting and preventing the intrusion alike when it affects the system in the future. This paper deals with the model's concept, architecture, deployment, and what else can be achieved in the field of critical infrastructure cybersecurity (CIC).
引用
收藏
页数:20
相关论文
共 26 条