Standard specification-based intrusion detection for hierarchical industrial control systems

计算机科学 工业控制系统 可扩展性 入侵检测系统 过程(计算) 分布式计算 访问控制 计算机安全 编码(集合论) 控制(管理) 嵌入式系统 数据库 操作系统 人工智能 集合(抽象数据类型) 程序设计语言
作者
Estelle Hotellier,Franck Sicard,Julien Francq,Stéphane Mocanu
出处
期刊:Information Sciences [Elsevier BV]
卷期号:659: 120102-120102 被引量:6
标识
DOI:10.1016/j.ins.2024.120102
摘要

In this paper, we develop a specification-based, process-aware, Intrusion Detection System (IDS) for complex Industrial Control Systems (ICSs). Complex ICSs are distributed and hierarchical control systems built on top of local control loops which are the system's elementary building blocks. Process-aware attacks are sophisticated cyberattacks that aim to compromise the safety of the controlled physical process. Our approach aims to link safety specifications and security properties. Thus, we use international and industry standards specifications concerning local safety, global safety and networks of the industrial process, in order to obtain security properties. The obtained security properties are cybersecurity related requirements. They are translated into security patterns in order to be runtime monitored by our network IDS. This latter relies on a distributed monitoring framework, capturing network traffic between the local loops and the distributed control level, as well as between distributed control and supervisory control. We implemented and evaluated our IDS on a real ICS. We experimentally show that our IDS detects a large spectrum of attacks. We also show that our distributed IDS is scalable since its detection response time as a function of the number of monitored security patterns, is linear. A demonstrator comprising code extracts is made available.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
内向汉堡完成签到,获得积分10
刚刚
秋天发布了新的文献求助10
刚刚
刚刚
科目三应助甜美的大船采纳,获得30
刚刚
1秒前
CES_SH完成签到,获得积分10
3秒前
精明凌旋完成签到,获得积分10
3秒前
Juan发布了新的文献求助10
5秒前
ZeyiWang完成签到,获得积分20
5秒前
quan完成签到,获得积分10
5秒前
7秒前
7秒前
lixm发布了新的文献求助10
7秒前
科研通AI6.4应助熊大采纳,获得10
8秒前
Ally完成签到,获得积分10
9秒前
9秒前
复杂静珊发布了新的文献求助10
10秒前
11秒前
秋天完成签到,获得积分10
11秒前
十一发布了新的文献求助10
12秒前
俏皮凝梦发布了新的文献求助10
13秒前
13秒前
在水一方应助晓晓鹤采纳,获得10
13秒前
13秒前
14秒前
15秒前
15秒前
Fair发布了新的文献求助10
16秒前
祁尒完成签到,获得积分10
16秒前
杨子怡完成签到 ,获得积分10
16秒前
ASD发布了新的文献求助10
16秒前
KJQ完成签到,获得积分10
16秒前
脑洞疼应助王木木采纳,获得10
17秒前
ZJH发布了新的文献求助10
17秒前
mlg1552003完成签到,获得积分10
17秒前
17秒前
18秒前
典雅的若雁完成签到,获得积分10
18秒前
现实的断缘完成签到,获得积分10
19秒前
小太阳发布了新的文献求助10
20秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
卤化钙钛矿人工突触的研究 1000
Engineering for calcareous sediments : proceedings of the International Conference on Calcareous Sediments, Perth 15-18 March 1988 / edited by R.J. Jewell, D.C. Andrews 1000
Wolffs Headache and Other Head Pain 9th Edition 1000
Continuing Syntax 1000
Harnessing Lymphocyte-Cytokine Networks to Disrupt Current Paradigms in Childhood Nephrotic Syndrome Management: A Systematic Evidence Synthesis 700
Signals, Systems, and Signal Processing 610
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6252754
求助须知:如何正确求助?哪些是违规求助? 8075588
关于积分的说明 16866378
捐赠科研通 5327100
什么是DOI,文献DOI怎么找? 2836254
邀请新用户注册赠送积分活动 1813626
关于科研通互助平台的介绍 1668408