A Multidimensional Critical State Analysis for Detecting Intrusions in SCADA Systems

被引:174
作者
Carcano, A. [1 ]
Coletta, A. [2 ]
Guglielmi, M. [1 ]
Masera, M. [2 ]
Fovino, I. Nai [2 ]
Trombetta, A. [1 ]
机构
[1] Insubria Univ, Dept Comp Sci, I-21100 Varese, Italy
[2] Joint Res Ctr, Inst Protect & Secur Citizen, I-21027 Ispra, Italy
关键词
Critical states; intrusion detection; supervisory control and data acquisition (SCADA) systems;
D O I
10.1109/TII.2010.2099234
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A relatively new trend in Critical Infrastructures (e. g., power plants, nuclear plants, energy grids, etc.) is the massive migration from the classic model of isolated systems, to a system-of-systems model, where these infrastructures are intensifying their interconnections through Information and Communications Technology (ICT) means. The ICT core of these industrial installations is known as Supervisory Control And Data Acquisition Systems (SCADA). Traditional ICT security countermeasures (e. g., classic firewalls, anti-viruses and IDSs) fail in providing a complete protection to these systems since their needs are different from those of traditional ICT. This paper presents an innovative approach to Intrusion Detection in SCADA systems based on the concept of Critical State Analysis and State Proximity. The theoretical framework is supported by tests conducted with an Intrusion Detection System prototype implementing the proposed detection approach.
引用
收藏
页码:179 / 186
页数:8
相关论文
共 15 条
[1]  
[Anonymous], 2002, Proceedings of the 9th ACM conference on Computer and communications security, CCS'02, DOI DOI 10.1145/586110.586144
[2]  
[Anonymous], ALCFTR19940085 HUM S
[3]  
Carcano A., 2009, INT J CRITICAL INFRA, V2
[4]  
Clarke G., 2004, MODERN SCADA PROTOCO
[5]  
Cuppens F, 2002, P IEEE S SECUR PRIV, P202, DOI 10.1109/SECPRI.2002.1004372
[6]  
East S, 2009, IFIP ADV INF COMM TE, V311, P67
[7]   Modbus/DNP3 State-based Intrusion Detection System [J].
Fovino, Igor Nai ;
Carcano, Andrea ;
Murel, Thibault De lacheze ;
Trombetta, Alberto ;
Masera, Marcelo .
2010 24TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2010, :729-736
[8]  
Fovino IN, 2010, C HUM SYST INTERACT, P679, DOI 10.1109/HSI.2010.5514494
[9]  
Frank P M., 1987, Triennial World Congress of the International Federation of Automatic Control, V3, P63, DOI DOI 10.1016/S1474-6670(17)55353-7
[10]  
Gross P., 2004, P INT WORKSH DEBS