【24h】

EDMAND: Edge-Based Multi-Level Anomaly Detection for SCADA Networks

机译:Edmand:SCADA网络的边缘多级异常检测

获取原文

摘要

Supervisory Control and Data Acquisition (SCADA) systems play a critical role in the operation of large-scale distributed industrial systems. There are many vulnerabilities in SCADA systems and inadvertent events or malicious attacks from outside as well as inside could lead to catastrophic consequences. Network-based intrusion detection is a preferred approach to provide security analysis for SCADA systems due to its less intrusive nature. Data in SCADA network traffic can be generally divided into transport, operation, and content levels. Most existing solutions only focus on monitoring and event detection of one or two levels of data, which is not enough to detect and reason about attacks in all three levels. In this paper, we develop a novel edge-based multi-level anomaly detection framework for SCADA networks named EDMAND. EDMAND monitors all three levels of network traffic data and applies appropriate anomaly detection methods based on the distinct characteristics of data. Alerts are generated, aggregated, prioritized before sent back to control centers. A prototype of the framework is built to evaluate the detection ability and time overhead of it.
机译:监督控制和数据采集(SCADA)系统在大规模分布式工业系统的运行中发挥着关键作用。 SCADA系统中有许多漏洞,从外面的外部以及内部的无意的事件或恶意攻击可能导致灾难性的后果。基于网络的入侵检测是由于其侵扰性,因此由于其侵扰性而提供了对SCADA系统的安全分析的优选方法。 SCADA网络流量中的数据通常可以分为传输,操作和内容级别。大多数现有解决方案仅关注监测和事件检测一个或两个级别的数据,这是不足以检测所有三个层次攻击的原因。在本文中,我们开发了一个名为Edmand的SCADA网络的新型边缘的多级异常检测框架。 Edmand监控所有三个级别的网络流量数据,并根据数据的不同特征应用适当的异常检测方法。在发送回控制中心之前生成警报,汇总,优先考虑。构建了框架的原型以评估其检测能力和时间开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号