首页> 外文会议>IEEE Power and Energy Society General Meeting >Intrusion Detection System for IEC 60870-5-104 based SCADA networks
【24h】

Intrusion Detection System for IEC 60870-5-104 based SCADA networks

机译:基于IEC 60870-5-104的SCADA网络入侵检测系统

获取原文

摘要

Increased complexity and interconnectivity of Supervisory Control and Data Acquisition (SCADA) systems in Smart Grids potentially means greater susceptibility to malicious attackers. SCADA systems with legacy communication infrastructure have inherent cyber-security vulnerabilities as these systems were originally designed with little consideration of cyber threats. In order to improve cyber-security of SCADA networks, this paper presents a rule-based Intrusion Detection System (IDS) using a Deep Packet Inspection (DPI) method, which includes signature-based and model-based approaches tailored for SCADA systems. The proposed signature-based rules can accurately detect several known suspicious or malicious attacks. In addition, model-based detection is proposed as a complementary method to detect unknown attacks. Finally, proposed intrusion detection approaches for SCADA networks are implemented and verified via Snort rules.
机译:在智能电网中提高了监督控制和数据采集(SCADA)系统的复杂性和互连性,可能对恶意攻击者的易感性更大。具有遗留通信基础设施的SCADA系统具有固有的网络安全漏洞,因为这些系统最初设计,几乎没有考虑网络威胁。为了提高SCADA网络的网络安全,本文介绍了一种使用深度分组检查(DPI)方法的基于规则的入侵检测系统(ID),包括为SCADA系统量身定制的基于签名和基于模型的方法。所提出的基于签名的规则可以准确地检测几种已知的可疑或恶意攻击。此外,提出基于模型的检测作为检测未知攻击的互补方法。最后,通过Snort规则实现并验证了SCADA网络的提出的入侵检测方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号