Proceedings 2014 Workshop on Security of Emerging Networking Technologies 2014
DOI: 10.14722/sent.2014.23012
|View full text |Cite
|
Sign up to set email alerts
|

Communication Pattern Monitoring: Improving the Utility of Anomaly Detection for Industrial Control Systems

Abstract: Attacks on Industrial Control Systems (ICS) continue to grow in number and complexity, and well-crafted cyber attacks are aimed at both commodity and ICS-specific contexts. It has become imperative to create efficient ICS-specific defense mechanisms that complement traditional enterprise solutions. Most commercial solutions are not designed for ICS environments, rely only on pre-defined signatures and do not handle zeroday attacks. We propose a threat detection framework that aims to detect zero-day attacks by… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
25
0

Year Published

2015
2015
2020
2020

Publication Types

Select...
4
3

Relationship

0
7

Authors

Journals

citations
Cited by 43 publications
(26 citation statements)
references
References 19 publications
0
25
0
Order By: Relevance
“…Works such as [9,27] attempt to answer to this last issue. Goldenberg et al [9] focus on a industrial application protocol (Modbus) and use a deterministic finite automaton (DFA) to build a model from real traffic traces.…”
Section: Related Workmentioning
confidence: 99%
“…Works such as [9,27] attempt to answer to this last issue. Goldenberg et al [9] focus on a industrial application protocol (Modbus) and use a deterministic finite automaton (DFA) to build a model from real traffic traces.…”
Section: Related Workmentioning
confidence: 99%
“…Some researchers have attempted to address this issue [5,26]. Goldenberg and Wool [5] used a deterministic finite state automaton to create a model from real Modbus traffic.…”
Section: Related Workmentioning
confidence: 99%
“…Yoon et al [26] have also focused on Modbus, but they modeled communications using dynamic Bayesian networks and probabilistic suffix trees. Each communications channel is reduced to a sequence of elements by parsing Modbus messages and pairing requests and responses.…”
Section: Related Workmentioning
confidence: 99%
“…Works such as [162,163] focus on this last issue. Goldenberg et al analyze Modbus messages and use deterministic finite automata (DFAs) to build communication models from real traffic traces [162].…”
Section: State Of the Artmentioning
confidence: 99%
“…In the same way, Yoon et al focus on Modbus but they model communications using dynamic Bayesian networks (DBNs) and probabilistic suffix trees (PSTs) [163]. When a network communication is observed, the system looks at the likelihood of generating the related sequence of messages from the PST model.…”
Section: State Of the Artmentioning
confidence: 99%