Understanding Indicators of Compromise against Cyber-attacks in Industrial Control Systems: A Security Perspective

被引:9
|
作者
Asiri, Mohammed [1 ]
Saxena, Neetesh [1 ]
Gjomemo, Rigel [2 ]
Burnap, Pete [1 ]
机构
[1] Cardiff Univ, 8600 Datapoint Dr, Cardiff, Wales
[2] Univ Illinois, 8600 Datapoint Dr, Chicago, IL 60607 USA
关键词
Industrial Control Systems; indicators of compromise; forensic readiness; threat intelligence; SCADA; Cyber-Physical Systems; ADVANCED PERSISTENT THREATS; FORENSIC ANALYSIS; CHALLENGES; INTERNET; ISSUES;
D O I
10.1145/3587255
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Numerous sophisticated and nation-state attacks on Industrial Control Systems (ICSs) have increased in recent years, exemplified by Stuxnet and Ukrainian Power Grid. Measures to be taken post-incident are crucial to reduce damage, restore control, and identify attack actors involved. By monitoring Indicators of Compromise (IOCs), the incident responder can detect malicious activity triggers and respond quickly to a similar intrusion at an earlier stage. However, to implement IOCs in critical infrastructures, we need to understand their contexts and requirements. Unfortunately, there is no survey paper in the literature on IOC in the ICS environment, and only limited information is provided in research articles. In this article, we describe different standards for IOC representation and discuss the associated challenges that restrict security investigators from developing IOCs in the industrial sectors. We also discuss the potential IOCs against cyber-attacks in ICS systems. Furthermore, we conduct a critical analysis of existing works and available tools in this space. We evaluate the effectiveness of identified IOCs' by mapping these indicators to the most frequently targeted attacks in the ICS environment. Finally, we highlight the lessons to be learned from the literature and the future problems in the domain along with the approaches that might be taken.
引用
收藏
页数:33
相关论文
共 50 条
  • [1] Modeling cyber-attacks on Industrial Control Systems
    Paliath, Vivin
    Shakarian, Paulo
    IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS: CYBERSECURITY AND BIG DATA, 2016, : 316 - 318
  • [2] Interval forecasting of cyber-attacks on industrial control systems
    Ivanyo, Y. M.
    Krakovsky, Y. M.
    Luzgin, A. N.
    INTERNATIONAL CONFERENCE ON MECHANICAL ENGINEERING, AUTOMATION AND CONTROL SYSTEMS 2017, 2018, 327
  • [3] On the Security of Cyber-Physical Systems Against Stochastic Cyber-Attacks Models
    Abu Al-Haija, Qasem
    2021 IEEE INTERNATIONAL IOT, ELECTRONICS AND MECHATRONICS CONFERENCE (IEMTRONICS), 2021, : 155 - 160
  • [4] Event-based security tracking control for networked control systems against stochastic cyber-attacks
    Liu, Jinliang
    Dong, Yanhui
    Zha, Lijuan
    Tian, Engang
    Xie, Xiangpeng
    INFORMATION SCIENCES, 2022, 612 : 306 - 321
  • [5] Integrated Approach to Diagnostics of Failures and Cyber-Attacks in Industrial Control Systems
    Syfert, Michal
    Ordys, Andrzej
    Koscielny, Jan Maciej
    Wnuk, Pawel
    Mozaryn, Jakub
    Kukielka, Krzysztof
    ENERGIES, 2022, 15 (17)
  • [6] Dynamic event-triggered security control of cyber-physical systems against missing measurements and cyber-attacks
    Zha, Lijuan
    Liao, Rongfei
    Liu, Jinliang
    Cao, Jinde
    Xie, Xiangpeng
    NEUROCOMPUTING, 2022, 500 : 405 - 412
  • [7] A Control and Attack Detection Scheme for Fuzzy Systems against Cyber-attacks
    Zhang, Haili
    Li, Linlin
    Qiao, Liang
    2023 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS, FUZZ, 2023,
  • [8] A Comprehensive Review of the Cyber-Attacks and Cyber-Security on Load Frequency Control of Power Systems
    Mohan, Athira M.
    Meskin, Nader
    Mehrjerdi, Hasan
    ENERGIES, 2020, 13 (15)
  • [9] Cyber-attacks against cyber-physical power systems security: State estimation, attacks reconstruction and defense strategy
    Su, Qingyu
    Wang, Handong
    Sun, Chaowei
    Li, Bo
    Li, Jian
    APPLIED MATHEMATICS AND COMPUTATION, 2022, 413
  • [10] Key Vulnerabilities of Industrial Automation and Control Systems and Recommendations to Prevent Cyber-Attacks
    Calvo, I.
    Etxeberria-Agiriano, I.
    Inigo, M. A.
    Gonzalez-Nalda, P.
    INTERNATIONAL JOURNAL OF ONLINE ENGINEERING, 2016, 12 (01) : 9 - 16