Understanding Indicators of Compromise against Cyber-attacks in Industrial Control Systems: A Security Perspective

被引:9
|
作者
Asiri, Mohammed [1 ]
Saxena, Neetesh [1 ]
Gjomemo, Rigel [2 ]
Burnap, Pete [1 ]
机构
[1] Cardiff Univ, 8600 Datapoint Dr, Cardiff, Wales
[2] Univ Illinois, 8600 Datapoint Dr, Chicago, IL 60607 USA
关键词
Industrial Control Systems; indicators of compromise; forensic readiness; threat intelligence; SCADA; Cyber-Physical Systems; ADVANCED PERSISTENT THREATS; FORENSIC ANALYSIS; CHALLENGES; INTERNET; ISSUES;
D O I
10.1145/3587255
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Numerous sophisticated and nation-state attacks on Industrial Control Systems (ICSs) have increased in recent years, exemplified by Stuxnet and Ukrainian Power Grid. Measures to be taken post-incident are crucial to reduce damage, restore control, and identify attack actors involved. By monitoring Indicators of Compromise (IOCs), the incident responder can detect malicious activity triggers and respond quickly to a similar intrusion at an earlier stage. However, to implement IOCs in critical infrastructures, we need to understand their contexts and requirements. Unfortunately, there is no survey paper in the literature on IOC in the ICS environment, and only limited information is provided in research articles. In this article, we describe different standards for IOC representation and discuss the associated challenges that restrict security investigators from developing IOCs in the industrial sectors. We also discuss the potential IOCs against cyber-attacks in ICS systems. Furthermore, we conduct a critical analysis of existing works and available tools in this space. We evaluate the effectiveness of identified IOCs' by mapping these indicators to the most frequently targeted attacks in the ICS environment. Finally, we highlight the lessons to be learned from the literature and the future problems in the domain along with the approaches that might be taken.
引用
收藏
页数:33
相关论文
共 50 条
  • [31] Stabilization for networked control systems under stochastic cyber-attacks
    Wei, Lili
    Liu, Jinliang
    PROCEEDINGS OF THE 36TH CHINESE CONTROL CONFERENCE (CCC 2017), 2017, : 8020 - 8025
  • [32] Framework for enhancing the operational resilience of cyber-manufacturing systems against cyber-attacks
    Espinoza-Zelaya, Carlos
    Moon, Young Bai
    MANUFACTURING LETTERS, 2023, 35 : 843 - 850
  • [33] Framework for enhancing the operational resilience of cyber-manufacturing systems against cyber-attacks
    Espinoza-Zelaya, Carlos
    Moon, Young Bai
    MANUFACTURING LETTERS, 2023, 35 : 843 - 850
  • [34] Safety securing approach against cyber-attacks for process control system
    Hashimoto, Yoshihiro
    Toyoshima, Takeshi
    Yogo, Shuichi
    Koike, Masato
    Hamaguchi, Takashi
    Jing, Sun
    Koshijima, Ichiro
    COMPUTERS & CHEMICAL ENGINEERING, 2013, 57 : 181 - 186
  • [35] Defending Against Cyber-Attacks on the Internet of Things
    Abdalrahman, Ghazi Abdalla
    Varol, Hacer
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [36] Cyber Security for Industrial Control Systems
    Cunningham, Steve
    POWER ENGINEERING, 2011, 115 (11) : 142 - +
  • [37] Event-Triggered Security Output Feedback Control for Networked Interconnected Systems Subject to Cyber-Attacks
    Gu, Zhou
    Park, Ju H.
    Yue, Dong
    Wu, Zheng-Guang
    Xie, Xiangpeng
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2021, 51 (10): : 6197 - 6206
  • [38] Dynamic event-triggered security control for networked control systems with cyber-attacks: A model predictive control approach
    Li, Bin
    Zhou, Xinglian
    Ning, Zhaoke
    Guan, Xiaoyi
    Yiu, Ka-Fai Cedric
    INFORMATION SCIENCES, 2022, 612 : 384 - 398
  • [39] Resilient Distributed Optimization Against Cyber-Attacks
    Gusrialdi, Azwirman
    Qu, Zhihua
    IEEE CONTROL SYSTEMS LETTERS, 2023, 7 : 3956 - 3961
  • [40] Securing Industrial Control Systems From Cyber-Attacks: A Stacked Neural-Network-Based Approach
    Jagtap, Sujeet S.
    Sriram, V. S. Shankar
    Subramaniyaswamy, V.
    Kotecha, Ketan
    IEEE CONSUMER ELECTRONICS MAGAZINE, 2024, 13 (01) : 30 - 38