首页> 外文期刊>IEEE transactions on information forensics and security >Temporal Execution Behavior for Host Anomaly Detection in Programmable Logic Controllers
【24h】

Temporal Execution Behavior for Host Anomaly Detection in Programmable Logic Controllers

机译:可编程逻辑控制器中主机异常检测的时间执行行为

获取原文
获取原文并翻译 | 示例

摘要

Programmable logic controllers (PLCs) make up the majority of endpoints on industrial control system (ICS) networks and are the vital bridge between the cyber and physical worlds. Although these devices are critical, they are often insecure by design: communicating over unauthenticated protocols, failing to provide standard password protection, and using trivially spoofed checksums for detecting program changes instead of cryptographic hashes. Furthermore, extreme resource limitations, long life cycles, and strict downtime requirements make it difficult to patch existing devices in the field and virtually impossible to install any kind of endpoint protection. While these limitations have traditionally been considered a security weakness, they may also be leveraged for change and anomaly detection. Specifically, this research proposes to leverage these resource limitations for continuous behavior anomaly detection for the PLCs themselves, using program execution times to detect single-instruction changes to control programs from both the network and local access. The basic techniques are extended to include white box modeling for estimating rare execution behavior from source code, and proof-of-work functions are utilized to increase the techniques' resiliency against mimicry attacks.
机译:可编程逻辑控制器(PLC)构成了工业控制系统(ICS)网络上的大多数端点,并且是网络与物理世界之间的重要桥梁。尽管这些设备很关键,但它们在设计上通常是不安全的:通过未经身份验证的协议进行通信,无法提供标准的密码保护,以及使用伪造的校验和来检测程序更改而不是加密哈希。此外,极端的资源限制,较长的生命周期以及严格的停机时间要求使得很难在现场修补现有设备,并且几乎不可能安装任何类型的端点保护。尽管传统上将这些限制视为安全弱点,但也可以利用它们来进行更改和异常检测。具体而言,这项研究提出利用这些资源限制,对PLC本身进行连续的行为异常检测,使用程序执行时间来检测单指令更改,从而从网络和本地访问中控制程序。基本技术已扩展到包括白盒建模,该白盒建模用于从源代码估计罕见的执行行为,并且使用工作量证明功能来提高该技术抵御模仿攻击的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号