2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks – Industry Track 2019
DOI: 10.1109/dsn-industry.2019.00008
|View full text |Cite
|
Sign up to set email alerts
|

A Parser for Deep Packet Inspection of IEC-104: A Practical Solution for Industrial Applications

Abstract: We present a practical solution for deep packet inspection for IEC-104 SCADA traffic, which can be used in monitoring approaches to ensure the dependable operation of critical systems. We re-implement an outdated parser and extend it to also parse the content of individual IEC-104 packets and to extract information relevant for monitoring and securing the physical processes being controlled. The deep packet inspection framework Spicy was used for the implementation, which allows for easy extensibility in the f… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
1
0

Year Published

2019
2019
2021
2021

Publication Types

Select...
4
2

Relationship

1
5

Authors

Journals

citations
Cited by 8 publications
(2 citation statements)
references
References 12 publications
0
1
0
Order By: Relevance
“…The most common security countermeasure is the use of intrusion detection and prevention systems with deep packet inspection capabilities or industrial firewalls that have the ability to detect and stop highly specialized attacks hidden deep in the communication flow [83]. For example, Liang et al [84] propose an industrial network intrusion detection algorithm based on a multi feature data clustering optimization model.…”
Section: Attacks In Application Layermentioning
confidence: 99%
“…The most common security countermeasure is the use of intrusion detection and prevention systems with deep packet inspection capabilities or industrial firewalls that have the ability to detect and stop highly specialized attacks hidden deep in the communication flow [83]. For example, Liang et al [84] propose an industrial network intrusion detection algorithm based on a multi feature data clustering optimization model.…”
Section: Attacks In Application Layermentioning
confidence: 99%
“…The actual process information in the Application Service Data Unit (ASDU) part of the Application Protocol Data Unit (APDU) was initially only supported for a small set of only six functions [16]. We extended the parser to trigger events for all IEC-104 function codes used at the Dutch substation [40].…”
Section: Connection To Ids Zeekmentioning
confidence: 99%