Proceedings of the 11th Annual Cyber and Information Security Research Conference 2016
DOI: 10.1145/2897795.2897814
|View full text |Cite
|
Sign up to set email alerts
|

A SCADA Intrusion Detection Framework that Incorporates Process Semantics

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
12
0

Year Published

2018
2018
2024
2024

Publication Types

Select...
5
2

Relationship

0
7

Authors

Journals

citations
Cited by 16 publications
(12 citation statements)
references
References 13 publications
0
12
0
Order By: Relevance
“…This is in contrast with commonly used terms in literature, such as "process-related", or "process-oriented". Rather than simply capturing and monitoring one process variable (such as temperature) related to an ICS device as what has been done in existing work [8,9], our approach proposed in this article looks beyond changes in a particular variable; instead, it looks at the way in which various sequences of "events" were executed and detect those deviant sequences. This approach allows a more comprehensive assessment of the potential problems (and by extension, security attacks) within the system.…”
Section: Accepted Manuscriptmentioning
confidence: 99%
“…This is in contrast with commonly used terms in literature, such as "process-related", or "process-oriented". Rather than simply capturing and monitoring one process variable (such as temperature) related to an ICS device as what has been done in existing work [8,9], our approach proposed in this article looks beyond changes in a particular variable; instead, it looks at the way in which various sequences of "events" were executed and detect those deviant sequences. This approach allows a more comprehensive assessment of the potential problems (and by extension, security attacks) within the system.…”
Section: Accepted Manuscriptmentioning
confidence: 99%
“…Sequences of packets are modeled as a discrete-time Markov chain and compared to a pre-computed reference model, which represents normal traffic behavior. Nivethan and Papa (2016a) propose a SCADA IDS framework that incorporates process semantics, by implementing extra warning notifications in case process variables exceed some threshold values. A system description language and a mapper for turning requirements into actual Bro policies is also provided.…”
Section: Process-aware Monitoringmentioning
confidence: 99%
“…However, they do not incorporate process information into the decision process. Nivethan and Papa (2016a) propose to incorporate process semantics by mapping the monitoring requirements to the respective PLC registers. The proposed mechanism issues alerts when, e.g., process variables are not within the requested bounds.…”
Section: Related Workmentioning
confidence: 99%
“…However, this complicates security mechanisms as proposed e.g. by Nivethan and Papa (2016a), while process-aware policies, as proposed in this paper, facilitates the use of normalized values.…”
Section: Process Variables In Iec-104mentioning
confidence: 99%
See 1 more Smart Citation