首页> 外文期刊>IEEE transactions on dependable and secure computing >Industrial Control System Network Intrusion Detection by Telemetry Analysis
【24h】

Industrial Control System Network Intrusion Detection by Telemetry Analysis

机译:遥测分析的工业控制系统网络入侵检测

获取原文
获取原文并翻译 | 示例

摘要

Until recently, industrial control systems (ICSs) used “air-gap” security measures, where every node of the ICS network was isolated from other networks, including the Internet, by a physical disconnect. Attaching ICS networks to the Internet benefits companies and engineers who use them. However, as these systems were designed for use in the air-gapped security environment, protocols used by ICSs contain little to no security features and are vulnerable to various attacks. This paper proposes an approach to detect the intrusions into network attached ICSs by measuring and verifying data that is transmitted through the network but is not inherently the data used by the transmission protocol—network telemetry. Using simulated PLC units, the developed IDS was able to achieve 94.3 percent accuracy when differentiating between machines of an attacker and engineer on the same network, and 99.5 percent accuracy when differentiating between attacker and engineer on the Internet.
机译:直到最近,工业控制系统(ICS)仍采用“气隙”安全措施,其中ICS网络的每个节点都通过物理断开与其他网络(包括Internet)隔离。将ICS网络连接到Internet将使使用它们的公司和工程师受益。但是,由于这些系统是为在具有空隙的安全性环境中使用而设计的,因此ICS使用的协议几乎没有安全性,甚至没有安全性,并且容易受到各种攻击。本文提出了一种通过测量和验证通过网络传输但不是传输协议固有使用的数据(网络遥测)的数据来检测对连接到ICS的入侵的方法。使用模拟的PLC单元,当在同一网络上区分攻击者和工程师的机器时,开发的IDS能够达到94.3%的精度,而在Internet上区分攻击者和工程师的时候,则可以达到99.5%的精度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号