Understanding Indicators of Compromise against Cyber-attacks in Industrial Control Systems: A Security Perspective

被引:9
|
作者
Asiri, Mohammed [1 ]
Saxena, Neetesh [1 ]
Gjomemo, Rigel [2 ]
Burnap, Pete [1 ]
机构
[1] Cardiff Univ, 8600 Datapoint Dr, Cardiff, Wales
[2] Univ Illinois, 8600 Datapoint Dr, Chicago, IL 60607 USA
关键词
Industrial Control Systems; indicators of compromise; forensic readiness; threat intelligence; SCADA; Cyber-Physical Systems; ADVANCED PERSISTENT THREATS; FORENSIC ANALYSIS; CHALLENGES; INTERNET; ISSUES;
D O I
10.1145/3587255
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Numerous sophisticated and nation-state attacks on Industrial Control Systems (ICSs) have increased in recent years, exemplified by Stuxnet and Ukrainian Power Grid. Measures to be taken post-incident are crucial to reduce damage, restore control, and identify attack actors involved. By monitoring Indicators of Compromise (IOCs), the incident responder can detect malicious activity triggers and respond quickly to a similar intrusion at an earlier stage. However, to implement IOCs in critical infrastructures, we need to understand their contexts and requirements. Unfortunately, there is no survey paper in the literature on IOC in the ICS environment, and only limited information is provided in research articles. In this article, we describe different standards for IOC representation and discuss the associated challenges that restrict security investigators from developing IOCs in the industrial sectors. We also discuss the potential IOCs against cyber-attacks in ICS systems. Furthermore, we conduct a critical analysis of existing works and available tools in this space. We evaluate the effectiveness of identified IOCs' by mapping these indicators to the most frequently targeted attacks in the ICS environment. Finally, we highlight the lessons to be learned from the literature and the future problems in the domain along with the approaches that might be taken.
引用
收藏
页数:33
相关论文
共 50 条
  • [41] Asynchronous secure control for singular nonhomogeneous Markov jump cyber-physical systems against dual cyber-attacks
    Zhang, Shuyu
    Wang, Yanqian
    Zhuang, Guangming
    Lv, Chengxing
    OPTIMAL CONTROL APPLICATIONS & METHODS, 2024, 45 (01): : 106 - 137
  • [43] Research on secure control and communication for cyber-physical systems under cyber-attacks
    Li, Wei
    Shi, Yahong
    Li, Yajie
    TRANSACTIONS OF THE INSTITUTE OF MEASUREMENT AND CONTROL, 2019, 41 (12) : 3421 - 3437
  • [44] Guest Editorial: Cyber-Attacks, Strategic Cyber-Foresight, and Security
    Fischer, Bruno
    Meissner, Dirk
    Nyuur, Richard
    Sarpong, David
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2022, 69 (06) : 3660 - 3663
  • [45] 1-Order-Smooth Explicit-Time Nonsingular Terminal Sliding Mode Control of Industrial Cyber-Physical Systems Against Cyber-Attacks
    Yan, Wen
    Zhao, Tao
    Yang, Haixin
    Wang, Xin
    Niu, Ben
    IEEE Transactions on Industrial Cyber-Physical Systems, 2023, 1 : 371 - 380
  • [46] Cyber-Attacks on Wheeled Mobile Robotic Systems with Visual Servoing Control
    Jokic, Aleksandar
    Khazraei, Amir
    Petrovic, Milica
    Jakovljevic, Zivana
    Pajic, Miroslav
    2023 IEEE/RSJ INTERNATIONAL CONFERENCE ON INTELLIGENT ROBOTS AND SYSTEMS (IROS), 2023, : 6342 - 6348
  • [47] A Resilient Frequency Regulation for Enhancing Power System Security Against Hybrid Cyber-Attacks
    Saxena, Abhishek
    Shankar, Ravi
    Kumar, Chandan
    Parida, S. K.
    IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, 2024, 60 (03) : 4583 - 4597
  • [48] Cyber-attacks on health-care systems
    Devi, Sharmila
    LANCET ONCOLOGY, 2023, 24 (04): : 148 - 148
  • [49] Secure smart contract-enabled control of battery energy storage systems against cyber-attacks
    Mhaisen, Naram
    Fetais, Noora
    Massoud, Ahmed
    ALEXANDRIA ENGINEERING JOURNAL, 2019, 58 (04) : 1291 - 1300
  • [50] TAXONOMY OF SEVERITY OF CYBER-ATTACKS IN CYBER-MANUFACTURING SYSTEMS
    Espinoza-Zelaya, Carlos
    Moon, Young
    PROCEEDINGS OF ASME 2022 INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION, IMECE2022, VOL 2B, 2022,