Cross-domain alert correlation methodology for industrial control systems

被引:0
|
作者
Koucham, Oualid [1 ]
Mocanu, Stéphane [2 ]
Hiet, Guillaume [3 ]
Thiriet, Jean-Marc [1 ]
Majorczyk, Frédéric [4 ]
机构
[1] GIPSA-Lab, Univ. Grenoble Alpes, France
[2] LIG, Univ. Grenoble Alpes, CNRS, Inria, Grenoble-INP, France
[3] CentraleSupélec, Inria, CNRS, IRISA, France
[4] DGA, Inria, France
来源
Computers and Security | 2022年 / 118卷
关键词
Alert correlation - Alert enrichment - Correlation methodology - Cross-domain - Industrial control systems - Intrusion Detection Systems - Intrusion-Detection - Physical domain - Physical process - Run-time verification;
D O I
暂无
中图分类号
学科分类号
摘要
Alert correlation is a set of techniques that process alerts raised by intrusion detection systems to eliminate redundant alerts, reduce the number of false positives, and reconstruct attack scenarios. Since Industrial Control Systems (ICSs) exhibit both a physical and a cyber domain, they present unique challenges for alert correlation. The presence of heterogeneous domains each with its specific threats has led to the development of multi-domain detection techniques. Indeed, some detection approaches rely solely on observations at the level of the cyber domain, while other approaches will monitor the physical process. Although these two approaches are complementary, the nature of the information carried by the detection alerts differs. In this article, we develop an alert correlation framework tailored explicitly for ICSs. We combine physical domain intrusion detection alerts with more classical cyber domain intrusion detection alerts. We develop a correlation approach that maps physical domain alerts into the cyber domain using alert enrichment. We also propose a specific alert selection for correlation that adapts to the state of the physical process by dynamically adjusting the size of the selected alert window. We test our approach on a realistic experimental setup with and we publicly release all datasets used to derive our results. Our cross-domain correlation methodology achieves better correlation metrics compared to classical temporal-based correlation approaches in terms of false correlation rate, missing correlation rate and alert reduction. © 2022 Elsevier Ltd
引用
收藏
相关论文
共 50 条
  • [31] Blockchain-Assisted Cross-Domain Data Sharing in Industrial IoT
    Zeng, Shulei
    Cao, Bin
    Sun, Yao
    Sun, Chen
    Wan, Zhiguo
    Peng, Mugen
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (16): : 26778 - 26792
  • [32] Distributed Cross-Domain Optimization for Software Defined Industrial Internet of Things
    Huang, Yunjing
    Luo, Shuyun
    Xu, Weiqiang
    INFORMATION, 2023, 14 (02)
  • [33] Cross-domain secure data sharing using blockchain for industrial IoT
    Singh, Parminder
    Masud, Mehedi
    Hossain, M. Shamim
    Kaur, Avinash
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 156 (156) : 176 - 184
  • [34] Web Multimedia Object Classification Using Cross-Domain Correlation Knowledge
    Lu, Wenting
    Li, Jingxuan
    Li, Tao
    Guo, Weidong
    Zhang, Honggang
    Guo, Jun
    IEEE TRANSACTIONS ON MULTIMEDIA, 2013, 15 (08) : 1920 - 1929
  • [35] A Dual Perspective Framework of Knowledge-correlation for Cross-domain Recommendation
    Wang, Yuhan
    Xie, Qing
    Tang, Mengzi
    Li, Lin
    Yuan, Jingling
    Liu, Yongjian
    ACM TRANSACTIONS ON KNOWLEDGE DISCOVERY FROM DATA, 2024, 18 (06)
  • [36] Cross-domain recommender system using generalized canonical correlation analysis
    Hashemi, Seyed Mohammad
    Rahmati, Mohammad
    KNOWLEDGE AND INFORMATION SYSTEMS, 2020, 62 (12) : 4625 - 4651
  • [37] Cross-Domain Sentiment Classification with Word Embeddings and Canonical Correlation Analysis
    Ngo Xuan Bach
    Vu Thanh Hai
    Tu Minh Phuong
    PROCEEDINGS OF THE SEVENTH SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY (SOICT 2016), 2016, : 159 - 166
  • [38] Optical correlation-based cross-domain image retrieval system
    Ikeda, Kanami
    Suzuki, Hidenori
    Watanabe, Eriko
    OPTICS LETTERS, 2017, 42 (13) : 2603 - 2606
  • [39] Sliced Wasserstein based Canonical Correlation Analysis for Cross-Domain Recommendation
    Zhao, Zian
    Nie, Jie
    Wang, Chenglong
    Huang, Lei
    PATTERN RECOGNITION LETTERS, 2021, 150 : 33 - 39
  • [40] Cross-domain recommender system using generalized canonical correlation analysis
    Seyed Mohammad Hashemi
    Mohammad Rahmati
    Knowledge and Information Systems, 2020, 62 : 4625 - 4651