首页> 外文期刊>International Journal on Critical Infrastructure Protection >A real-time anomaly-based IDS for cyber-attack detection at the industrial process level of Critical Infrastructures
【24h】

A real-time anomaly-based IDS for cyber-attack detection at the industrial process level of Critical Infrastructures

机译:基于实时异常的IDS,可在关键基础设施的工业流程级别上进行网络攻击检测

获取原文
获取原文并翻译 | 示例
       

摘要

This work presents a real time anomaly-based detection system designed to work at the industrial process level of Critical Infrastructures (CI). The system's core algorithm is based on negative selection and works in two phases: it first learns from the normal behaviour of the process, and then performs detection and raises alarms each time an abnormal behaviour is found. The main goal of the proposed tool is the detection of attacks targeting the physical components or devices composing the industrial process level of CI such as electric, gas or water utilities. The proposed IDS uses a multi-agent approach to tackle the complex problem of monitoring large amounts of data coming from measurements recorded by Industrial Control Systems. It was built on an open source distributed computation system for real time analysis. This tool was developed, tested, and validated during the EU-funded project PREEMPTIVE. Detection results obtained on a water treatment plant laboratory are presented and discussed. (C) 2018 Elsevier B.V. All rights reserved.
机译:这项工作提出了一个实时的基于异常的检测系统,旨在在关键基础设施(CI)的工业过程级别上工作。该系统的核心算法基于否定选择,并且分两个阶段工作:首先从过程的正常行为中学习,然后执行检测,并在发现异常行为时发出警报。提出的工具的主要目标是检测针对构成CI工业过程级别的物理组件或设备的攻击,例如电力,天然气或自来水公司。提议的IDS使用多主体方法来解决监视工业控制系统记录的测量结果中的大量数据这一复杂问题。它建立在用于实时分析的开源分布式计算系统上。该工具是在欧盟资助的PREEMPTIVE项目中开发,测试和验证的。介绍并讨论了在水处理厂实验室获得的检测结果。 (C)2018 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号