首页> 外文OA文献 >Modeling message sequences for intrusion detection in industrial control systems
【2h】

Modeling message sequences for intrusion detection in industrial control systems

机译:为工业控制系统中的入侵检测建模消息序列

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Compared with standard information technology systems, industrial control systems show more consistent and regular communications patterns. This characteristic contributes to the stability of controlled processes in critical infrastructures such as power plants, electric grids and water treatment facilities. However, Stuxnet has demonstrated that skilled attackers can strike critical infrastructures by leveraging knowledge about these processes. Sequence attacks subvert infrastructure operations by sending misplaced industrial control system messages. This chapter discusses four main sequence attack scenarios against industrial control systems. Real Modbus, Manufacturing Message Specification and IEC 60870-5-104 traffic samples were used to test sequencing and modeling techniques for describing industrial control system communications. The models were then evaluated to verify the feasibility of identifying sequence attacks. The results create the foundation for developing “sequence-aware‿ intrusion detection systems.
机译:与标准信息技术系统相比,工业控制系统显示出更加一致和常规的通信模式。此特性有助于在关键基础设施(例如电厂,电网和水处理设施)中控制过程的稳定性。但是,Stuxnet已经证明,熟练的攻击者可以利用关于这些过程的知识来攻击关键的基础架构。顺序攻击通过发送错误的工业控制系统消息来破坏基础架构的运行。本章讨论针对工业控制系统的四种主要顺序攻击方案。真实的Modbus,制造消息规范和IEC 60870-5-104交通样本用于测试描述工业控制系统通信的排序和建模技术。然后评估模型以验证鉴定序列攻击的可行性。研究结果为开发“序列感知”入侵检测系统奠定了基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号