Cross-domain alert correlation methodology for industrial control systems

被引:0
|
作者
Koucham, Oualid [1 ]
Mocanu, Stéphane [2 ]
Hiet, Guillaume [3 ]
Thiriet, Jean-Marc [1 ]
Majorczyk, Frédéric [4 ]
机构
[1] GIPSA-Lab, Univ. Grenoble Alpes, France
[2] LIG, Univ. Grenoble Alpes, CNRS, Inria, Grenoble-INP, France
[3] CentraleSupélec, Inria, CNRS, IRISA, France
[4] DGA, Inria, France
来源
Computers and Security | 2022年 / 118卷
关键词
Alert correlation - Alert enrichment - Correlation methodology - Cross-domain - Industrial control systems - Intrusion Detection Systems - Intrusion-Detection - Physical domain - Physical process - Run-time verification;
D O I
暂无
中图分类号
学科分类号
摘要
Alert correlation is a set of techniques that process alerts raised by intrusion detection systems to eliminate redundant alerts, reduce the number of false positives, and reconstruct attack scenarios. Since Industrial Control Systems (ICSs) exhibit both a physical and a cyber domain, they present unique challenges for alert correlation. The presence of heterogeneous domains each with its specific threats has led to the development of multi-domain detection techniques. Indeed, some detection approaches rely solely on observations at the level of the cyber domain, while other approaches will monitor the physical process. Although these two approaches are complementary, the nature of the information carried by the detection alerts differs. In this article, we develop an alert correlation framework tailored explicitly for ICSs. We combine physical domain intrusion detection alerts with more classical cyber domain intrusion detection alerts. We develop a correlation approach that maps physical domain alerts into the cyber domain using alert enrichment. We also propose a specific alert selection for correlation that adapts to the state of the physical process by dynamically adjusting the size of the selected alert window. We test our approach on a realistic experimental setup with and we publicly release all datasets used to derive our results. Our cross-domain correlation methodology achieves better correlation metrics compared to classical temporal-based correlation approaches in terms of false correlation rate, missing correlation rate and alert reduction. © 2022 Elsevier Ltd
引用
收藏
相关论文
共 50 条
  • [41] A Contrastive Representation Domain Adaptation Method for Industrial Time-Series Cross-Domain Prediction
    Jia, Zidi
    Ren, Lei
    Tang, Yang
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2025,
  • [42] Semantics for Cyber-Physical Systems: A cross-domain perspective
    Sabou, Marta
    Biffl, Stefan
    Einfalt, Alfred
    Krammer, Lukas
    Kastner, Wolfgang
    Ekaputra, Fajar J.
    SEMANTIC WEB, 2020, 11 (01) : 115 - 124
  • [43] Context-Aware Techniques for Cross-Domain Recommender Systems
    Veras, Douglas
    Prudencio, Ricardo
    Ferraz, Carlos
    Bispo, Alysson
    Prota, Thiago
    2015 BRAZILIAN CONFERENCE ON INTELLIGENT SYSTEMS (BRACIS 2015), 2015, : 282 - 287
  • [44] Tags and Item Features as a Bridge for Cross-Domain Recommender Systems
    Sahu, Ashish K.
    Dwivedi, Pragya
    Kant, Vibhor
    6TH INTERNATIONAL CONFERENCE ON SMART COMPUTING AND COMMUNICATIONS, 2018, 125 : 624 - 631
  • [45] Causal Inference-Based Adversarial Domain Adaptation for Cross-Domain Industrial Intrusion Detection
    Chen, Yongle
    Ji, Yubo
    Wang, Haoran
    Hao, Xiaoyan
    Yang, Yuli
    Ma, Yao
    Yu, Dan
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2025, 21 (01) : 970 - 979
  • [46] Assessment Model of the Resilience of Industrial Pollutant Emissions to Urban Atmospheric Systems from the Perspective of Cross-Domain Transmission
    Su, Jia
    Wu, Xi
    Huang, Guangqiu
    He, Tong
    JOURNAL OF URBAN PLANNING AND DEVELOPMENT, 2024, 150 (01)
  • [47] The Research of Cross-Domain Access Control Based on Attribute Mapping
    Mu, Ling-ling
    Gao, Yan-yan
    INTERNATIONAL CONFERENCE ON COMPUTER, NETWORK SECURITY AND COMMUNICATION ENGINEERING (CNSCE 2014), 2014, : 95 - 100
  • [48] Cross-domain trust management mechanism for internet of things systems
    Xu Wu
    Peer-to-Peer Networking and Applications, 2021, 14 : 933 - 947
  • [49] A Cross-Domain Recommendation Model for Cyber-Physical Systems
    Gao, Sheng
    Luo, Hao
    Chen, Da
    Li, Shantao
    Gallinari, Patrick
    Ma, Zhanyu
    Guo, Jun
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2013, 1 (02) : 384 - 393
  • [50] A privacy-preserving framework for cross-domain recommender systems
    Ogunseyi, Taiwo Blessing
    Bo, Tang
    Yang, Cheng
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 93