Modbus/DNP3 State-based Intrusion Detection System

被引:91
作者
Fovino, Igor Nai [1 ]
Carcano, Andrea [2 ]
Murel, Thibault De lacheze [1 ]
Trombetta, Alberto [2 ]
Masera, Marcelo [1 ]
机构
[1] Commiss European Communities, Joint Res Ctr, Inst Protect & Secur Citizen, I-21020 Ispra, Italy
[2] Insubria Univ, DICOM, Varese, Italy
来源
2010 24TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA) | 2010年
关键词
D O I
10.1109/AINA.2010.86
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security of Industrial Critical Infrastructures is become a prominent problem with the advent of modern ICT technologies used to improve the performances and the features of the SCADA systems. In this paper we present an innovative approach to the design of Intrusion Detection Systems. The aim is to be able to detect complex attacks to SCADA systems, by monitoring its state evolution. By complex attack, we mean attacks composed of a set of commands that, while licit when considered in isolation on a single-packet basis, can disrupt the correct behavior of the system when executed in particular operating states. The proposed IDS detects these complex attacks thanks to an internal representation of the controlled SCADA system. We also present the corresponding rule language powerful enough to express the system's critical states. Furthermore, we present a prototype of the proposed IDS, able to monitor systems using the ModBus and DNP3 communication protocols.
引用
收藏
页码:729 / 736
页数:8
相关论文
共 13 条
[1]  
[Anonymous], 2002, Proceedings of the 9th ACM conference on Computer and communications security, CCS'02, DOI DOI 10.1145/586110.586144
[2]  
Carcano A., 2008, P 3 INT WORKSH CRIT
[3]  
Cuppens F., P SEC PRIV 2002
[4]   AN INTRUSION-DETECTION MODEL [J].
DENNING, DE .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1987, 13 (02) :222-232
[5]  
Dondossola G., 2008, INT J CRITICAL INFRA, V4
[6]  
Fovino I.N., 2008, P 2 INT C CRIT INFR
[7]  
Fovino I. Nai, 2006, P 15 EICAR ANN C HAM
[8]  
Fovino Igor Nai, 2007, P 1 ANN IFIP WORK GR
[9]  
Fovino Igor Nai, 2006, P IEEE C SYST MAN CY
[10]  
Gross P., 2004, P INT WORKSH DEBS