...
首页> 外文期刊>International Journal on Critical Infrastructure Protection >SIDS: State-based intrusion detection for stage-based cyber physical systems
【24h】

SIDS: State-based intrusion detection for stage-based cyber physical systems

机译:SIDS:基于阶段的网络物理系统的基于状态的入侵检测

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Attacks to Cyber Physical Systems (CPSs) are detected by Industrial Intrusion Detection Systems (IIDSs). Operation of stage-based CPSs (those for which their underlying process is batch) consists of three parts: normal states, normal transitions between the normal states, and normal time-intervals for transitions. Unfortunately, state-of-the-art IIDSs directly ad-dress cyber-attacks that result in anomalous states whereas anomalous transitions or time-intervals can also indicate cyber-attacks. In this paper, a State-based IDS (SIDS) is proposed to detect all three anomalies. For doing this, SIDS first automatically extracts the normal behavior of CPS. Then it monitors current CPS behavior and detects intrusions by directly looking at the data of field layer. A small-scale but real CPS (a mixer process) is provided to illustrate how SIDS works. In addition, experimental results on three cyber-attacks orchestrated on a simulated milk pasteurization process indicate that SIDS can successfully detect cyber-attacks to large I/O CPSs. (C) 2018 Elsevier B.V. All rights reserved.
机译:工业入侵检测系统(IIDS)可以检测对网络物理系统(CPS)的攻击。基于阶段的CPS(对其基础过程是批量处理的)的操作包括三个部分:正常状态,正常状态之间的正常转换以及转换的正常时间间隔。不幸的是,最先进的IIDS直接解决了导致异常状态的网络攻击,而异常过渡或时间间隔也可能表示网络攻击。在本文中,提出了一种基于状态的IDS(SIDS)以检测所有这三个异常。为此,SIDS首先自动提取CPS的正常行为。然后,它监视当前的CPS行为并通过直接查看字段层的数据来检测入侵。提供了一个小规模但真实的CPS(混合器过程)来说明SIDS的工作方式。此外,在模拟的牛奶巴氏灭菌过程中精心策划的三个网络攻击的实验结果表明,小岛屿发展中国家可以成功检测到对大型I / O CPS的网络攻击。 (C)2018 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号