首页> 外文学位 >Cyberthreats, attacks and intrusion detection in supervisory control and data acquisition networks.
【24h】

Cyberthreats, attacks and intrusion detection in supervisory control and data acquisition networks.

机译:监控和数据采集网络中的网络威胁,攻击和入侵检测。

获取原文
获取原文并翻译 | 示例

摘要

Supervisory Control and Data Acquisition (SCADA) systems are computer-based process control systems that interconnect and monitor remote physical processes. There have been many real world documented incidents and cyber-attacks affecting SCADA systems, which clearly illustrate critical infrastructure vulnerabilities. These reported incidents demonstrate that cyber-attacks against SCADA systems might produce a variety of financial damage and harmful events to humans and their environment. This dissertation documents four contributions towards increased security for SCADA systems. First, a set of cyber-attacks was developed. Second, each attack was executed against two fully functional SCADA systems in a laboratory environment; a gas pipeline and a water storage tank. Third, signature based intrusion detection system rules were developed and tested which can be used to generate alerts when the aforementioned attacks are executed against a SCADA system. Fourth, a set of features was developed for a decision tree based anomaly based intrusion detection system. The features were tested using the datasets developed for this work.;This dissertation documents cyber-attacks on both serial based and Ethernet based SCADA networks. Four categories of attacks against SCADA systems are discussed: reconnaissance, malicious response injection, malicious command injection and denial of service. In order to evaluate performance of data mining and machine learning algorithms for intrusion detection systems in SCADA systems, a network dataset to be used for benchmarking intrusion detection systems was generated. This network dataset includes different classes of attacks that simulate different attack scenarios on process control systems. This dissertation describes four SCADA network intrusion detection datasets; a full and abbreviated dataset for both the gas pipeline and water storage tank systems. Each feature in the dataset is captured from network flow records. This dataset groups two different categories of features that can be used as input to an intrusion detection system. First, network traffic features describe the communication patterns in a SCADA system. This research developed both signature based IDS and anomaly based IDS for the gas pipeline and water storage tank serial based SCADA systems. The performance of both types of IDS were evaluates by measuring detection rate and the prevalence of false positives.
机译:监督控制和数据采集(SCADA)系统是基于计算机的过程控制系统,可互连和监视远程物理过程。现实世界中有许多记录在案的事件和网络攻击都影响着SCADA系统,这些事件和网络攻击清楚地说明了关键的基础设施漏洞。这些已报告的事件表明,针对SCADA系统的网络攻击可能会对人类及其环境造成各种财务损失和有害事件。本文记录了对SCADA系统安全性的四项贡献。首先,开发了一系列网络攻击。其次,每次攻击都是在实验室环境中针对两个功能齐全的SCADA系统执行的;天然气管道和储水箱。第三,开发并测试了基于签名的入侵检测系统规则,当针对SCADA系统执行上述攻击时,可用于生成警报。第四,为基于决策树的基于异常的入侵检测系统开发了一组功能。使用为该工作开发的数据集对这些功能进行了测试。;本论文记录了基于串行和基于以太网的SCADA网络上的网络攻击。讨论了针对SCADA系统的四类攻击:侦察,恶意响应注入,恶意命令注入和拒绝服务。为了评估SCADA系统中入侵检测系统的数据挖掘和机器学习算法的性能,生成了用于对入侵检测系统进行基准测试的网络数据集。该网络数据集包括不同类型的攻击,这些攻击模拟了过程控制系统上的不同攻击场景。本文描述了四个SCADA网络入侵检测数据集。天然气管道和储水罐系统的完整且简短的数据集。从网络流记录中捕获数据集中的每个特征。该数据集将可以用作入侵检测系统输入的两种不同类别的特征进行分组。首先,网络流量功能描述了SCADA系统中的通信模式。这项研究为基于天然气管道和储水罐系列的SCADA系统开发了基于签名的IDS和基于异常的IDS。两种类型的IDS的性能均通过测量检测率和假阳性率来评估。

著录项

  • 作者

    Gao, Wei.;

  • 作者单位

    Mississippi State University.;

  • 授予单位 Mississippi State University.;
  • 学科 Engineering Computer.
  • 学位 Ph.D.
  • 年度 2013
  • 页码 145 p.
  • 总页数 145
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号