首页> 外文学位 >Field intrusion detection system for SCADA networks
【24h】

Field intrusion detection system for SCADA networks

机译:SCADA网络的现场入侵检测系统

获取原文
获取原文并翻译 | 示例

摘要

This dissertation presents a new approach for detecting electronic intrusions in the SCADA networks used to control chemical plants. The approach has combined network intrusion detection and field intrusion detection systems in a way that significantly enhances system performance, and also greatly reduces false positives and false negatives. The major contribution, however, of this dissertation is in the development, implementation testing and evaluation of a novel field intrusion detection unit.;The network intrusion detection system (NIDS) is applied to data transmitted using the distributed network protocol (DNP3) over TCP/IP. Rule-base security is used to implement NIDS for incoming and outgoing data transmissions from a master terminal unit (MTU) to a remote terminal unit (RTU). The field intrusion detection system (FIDS) presented here is based on PCA and hierarchical principal component analysis (HPCA). HPCA is a fast data reduction technique which has been designed to avoid the problem of evaluating eigenvectors for high dimension data. Reliance on outputs of these methods depends on a decision tree which is constructed to provide FID the ability to detect intruded variables. Also, a mathematical model for group assignment algorithm of HPCA is presented to improve the intrusion detection rate.;For testing purposes, network traffic from an actual SCADA system in Chemical Engineering Department at the University of Louisville, which controls a chemical distillation process, was used for offline analysis. To perform real-time evaluation, a mathematical model of the process was utilized. Detailed analysis of the FIDS unit is discussed in this dissertation, including the ROC curve, scalability considerations, clustering input parameters, implementation of a low-pass filter for reducing high noise, and the sensitivity of hierarchical principal component analysis (HPCA) versus PCA. The experimental results are found to provide acceptable detection for real-time systems, and the projected scalability of the detection system to larger installations is also acceptable.
机译:本文提出了一种用于控制化工厂的SCADA网络中的电子入侵检测新方法。该方法将网络入侵检测和现场入侵检测系统结合在一起,可以显着提高系统性能,并且还可以大大减少误报和误报。然而,本文的主要贡献在于新型现场入侵检测单元的开发,实施测试和评估。网络入侵检测系统(NIDS)应用于通过TCP使用分布式网络协议(DNP3)传输的数据/ IP。基于规则的安全性用于为从主终端单元(MTU)到远程终端单元(RTU)的传入和传出数据传输实现NIDS。此处介绍的现场入侵检测系统(FIDS)基于PCA和分层主成分分析(HPCA)。 HPCA是一种快速的数据缩减技术,旨在避免评估高维数据的特征向量的问题。对这些方法的输出的依赖取决于决策树,该决策树被构造为向FID提供检测入侵变量的能力。此外,还提出了一种用于HPCA的组分配算法的数学模型,以提高入侵检测率。为了进行测试,使用了路易斯维尔大学化学工程系控制化学蒸馏过程的实际SCADA系统的网络流量。用于离线分析。为了执行实时评估,使用了该过程的数学模型。本文讨论了FIDS单元的详细分析,包括ROC曲线,可扩展性,聚类输入参数,用于降低高噪声的低通滤波器的实现以及相对PCA的层次主成分分析(HPCA)的敏感性。实验结果被发现可以为实时系统提供可接受的检测,并且该检测系统针对较大安装的可扩展性也是可以接受的。

著录项

  • 作者

    Ashikhmin, Aleksey.;

  • 作者单位

    University of Louisville.;

  • 授予单位 University of Louisville.;
  • 学科 Computer science.
  • 学位 Ph.D.
  • 年度 2009
  • 页码 129 p.
  • 总页数 129
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号