Cross-domain alert correlation methodology for industrial control systems

被引:0
|
作者
Koucham, Oualid [1 ]
Mocanu, Stéphane [2 ]
Hiet, Guillaume [3 ]
Thiriet, Jean-Marc [1 ]
Majorczyk, Frédéric [4 ]
机构
[1] GIPSA-Lab, Univ. Grenoble Alpes, France
[2] LIG, Univ. Grenoble Alpes, CNRS, Inria, Grenoble-INP, France
[3] CentraleSupélec, Inria, CNRS, IRISA, France
[4] DGA, Inria, France
来源
Computers and Security | 2022年 / 118卷
关键词
Alert correlation - Alert enrichment - Correlation methodology - Cross-domain - Industrial control systems - Intrusion Detection Systems - Intrusion-Detection - Physical domain - Physical process - Run-time verification;
D O I
暂无
中图分类号
学科分类号
摘要
Alert correlation is a set of techniques that process alerts raised by intrusion detection systems to eliminate redundant alerts, reduce the number of false positives, and reconstruct attack scenarios. Since Industrial Control Systems (ICSs) exhibit both a physical and a cyber domain, they present unique challenges for alert correlation. The presence of heterogeneous domains each with its specific threats has led to the development of multi-domain detection techniques. Indeed, some detection approaches rely solely on observations at the level of the cyber domain, while other approaches will monitor the physical process. Although these two approaches are complementary, the nature of the information carried by the detection alerts differs. In this article, we develop an alert correlation framework tailored explicitly for ICSs. We combine physical domain intrusion detection alerts with more classical cyber domain intrusion detection alerts. We develop a correlation approach that maps physical domain alerts into the cyber domain using alert enrichment. We also propose a specific alert selection for correlation that adapts to the state of the physical process by dynamically adjusting the size of the selected alert window. We test our approach on a realistic experimental setup with and we publicly release all datasets used to derive our results. Our cross-domain correlation methodology achieves better correlation metrics compared to classical temporal-based correlation approaches in terms of false correlation rate, missing correlation rate and alert reduction. © 2022 Elsevier Ltd
引用
收藏
相关论文
共 50 条
  • [21] Coordinated Navigation Control of Cross-Domain Unmanned Systems via Guiding Vector Fields
    Hu, Bin-Bin
    Zhang, Hai-Tao
    Liu, Bin
    Ding, Jianing
    Xu, Yifan
    Luo, Chuanshang
    Cao, Haosen
    IEEE TRANSACTIONS ON CONTROL SYSTEMS TECHNOLOGY, 2024, 32 (02) : 550 - 563
  • [22] Cross-Domain Security of Cyber-Physical Systems
    Chhetri, Sujit Rokka
    Wan, Jiang
    Al Faruque, Mohammad Abdullah
    2017 22ND ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE (ASP-DAC), 2017, : 200 - 205
  • [23] Secure cross-domain positioning architecture for autonomic systems
    Pfeifer, T
    LCN 2005: 30th Conference on Local Computer Networks, Proceedings, 2005, : 507 - 508
  • [24] Improving Serendipity and Accuracy in Cross-Domain Recommender Systems
    Kotkov, Denis
    Wang, Shuaiqiang
    Veijalainen, Jari
    WEB INFORMATION SYSTEMS AND TECHNOLOGIES (WEBIST 2016), 2017, 292 : 105 - 119
  • [25] An Experimental Study of Scalability in Cross-Domain Recommendation Systems
    Srivastava, Akarsh
    Jain, Aman
    Jayadev, Ashwin
    Mukherjee, Rajdeep
    Bhargava, Shronit
    Gupta, Prosenjit
    ADVANCED COMPUTATIONAL AND COMMUNICATION PARADIGMS, VOL 2, 2018, 706 : 473 - 481
  • [26] A Cross-domain Access Control Method for Large Organizations
    Wang Chao
    Chen Ji-zhou
    Liu Yu-jun
    Li An-qi
    APPLIED SCIENCE, MATERIALS SCIENCE AND INFORMATION TECHNOLOGIES IN INDUSTRY, 2014, 513-517 : 941 - 946
  • [27] Cross-domain symbiosis
    Andrea Du Toit
    Nature Reviews Microbiology, 2022, 20 (11) : 638 - 638
  • [28] Cross-Domain Fine-Grained Data Usage Control Service for Industrial Wireless Sensor Networks
    Wu, Jun
    Dong, Mianxiong
    Ota, Kaoru
    Tariq, Muhammad
    Guo, Longhua
    IEEE ACCESS, 2015, 3 : 2939 - 2949
  • [29] Certificate-Free Cross-Domain Fine-Grained Access Control Mechanism for Industrial Internet
    Dong, Jingnan
    Xu, Guangxia
    Ma, Chuang
    Liu, Jun
    Cliff, Uchani Gutierrez Omar
    HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2024, 14
  • [30] A Lightweight Cross-Domain Authentication Protocol for Trusted Access to Industrial Internet
    Zhang, Tiantian
    Zhang, Zhiyong
    Zhao, Kejing
    Gupta, Brij B.
    Arya, Varsha
    INTERNATIONAL JOURNAL ON SEMANTIC WEB AND INFORMATION SYSTEMS, 2023, 19 (01)