Standard specification-based intrusion detection for hierarchical industrial control systems

被引:2
|
作者
Hotellier, Estelle [1 ,2 ]
Sicard, Franck [1 ]
Francq, Julien [1 ]
Mocanu, Stephane [2 ]
机构
[1] Naval Grp, Naval Cyber Lab, F-83190 Ollioules, France
[2] Univ Grenoble Alpes, Lab Informat Grenoble, CNRS, Inria,Grenoble INP, F-38000 Grenoble, France
关键词
Industrial control system; Intrusion detection system; Specification; Temporal logic; Runtime monitoring; SECURITY; SAFETY;
D O I
10.1016/j.ins.2024.120102
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we develop a specification -based, process -aware, Intrusion Detection System (IDS) for complex Industrial Control Systems (ICSs). Complex ICSs are distributed and hierarchical control systems built on top of local control loops which are the system's elementary building blocks. Process -aware attacks are sophisticated cyberattacks that aim to compromise the safety of the controlled physical process. Our approach aims to link safety specifications and security properties. Thus, we use international and industry standards specifications concerning local safety, global safety and networks of the industrial process, in order to obtain security properties. The obtained security properties are cybersecurity related requirements. They are translated into security patterns in order to be runtime monitored by our network IDS. This latter relies on a distributed monitoring framework, capturing network traffic between the local loops and the distributed control level, as well as between distributed control and supervisory control. We implemented and evaluated our IDS on a real ICS. We experimentally show that our IDS detects a large spectrum of attacks. We also show that our distributed IDS is scalable since its detection response time as a function of the number of monitored security patterns, is linear. A demonstrator comprising code extracts is made available.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] Specification-based incremental testing of object oriented systems
    Soundarajan, N
    Tyler, B
    [J]. TOOLS 39: TECHNOLOGY OF OBJECT-ORIENTED LANGUAGES AND SYSTEMS, PROCEEDINGS: SOFTWARE TECHNOLOGY FOR THE AGE OF THE INTERNET, 2001, 39 : 35 - 44
  • [42] A Specification-Based Detection for Attacks in the Multi-Area System
    Siu, Jun Yen
    Panda, Sanjib Kumar
    [J]. IECON 2020: THE 46TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2020, : 1526 - 1531
  • [43] On specification-based cyber-attack detection in smart grids
    Sen Ö.
    van der Velde D.
    Lühman M.
    Sprünken F.
    Hacker I.
    Ulbig A.
    Andres M.
    Henze M.
    [J]. Energy Informatics, 2022, 5 (Suppl 1)
  • [44] DEIDS: a novel intrusion detection system for industrial control systems
    Gu, Haoran
    Lai, Yingxu
    Wang, Yipeng
    Liu, Jing
    Sun, Motong
    Mao, Beifeng
    [J]. NEURAL COMPUTING & APPLICATIONS, 2022, 34 (12): : 9793 - 9811
  • [45] A survey of network intrusion detection methods for industrial control systems
    Zhang W.-A.
    Hong Z.
    Zhu J.-W.
    Chen B.
    [J]. Kongzhi yu Juece/Control and Decision, 2019, 34 (11): : 2277 - 2288
  • [46] DEIDS: a novel intrusion detection system for industrial control systems
    Haoran Gu
    Yingxu Lai
    Yipeng Wang
    Jing Liu
    Motong Sun
    Beifeng Mao
    [J]. Neural Computing and Applications, 2022, 34 : 9793 - 9811
  • [47] MODELING MESSAGE SEQUENCES FOR INTRUSION DETECTION IN INDUSTRIAL CONTROL SYSTEMS
    Caselli, Marco
    Zambon, Emmanuele
    Petit, Jonathan
    Kargl, Frank
    [J]. CRITICAL INFRASTRUCTURE PROTECTION IX, 2015, 466 : 49 - 71
  • [48] Distributed Architecture of an Intrusion Detection System in Industrial Control Systems
    Abid, Ahlem
    Jemili, Farah
    Korbaa, Ouajdi
    [J]. ADVANCES IN COMPUTATIONAL COLLECTIVE INTELLIGENCE, ICCCI 2022, 2022, 1653 : 472 - 484
  • [49] Dimension Reduction Technique Based on Supervised Autoencoder for Intrusion Detection of Industrial Control Systems
    Wang, Chao
    Liu, Hongri
    Sun, Yunxiao
    Wei, Yuliang
    Wang, Kai
    Wang, Bailing
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [50] Real-Time Intrusion Detection Based on Decision Fusion in Industrial Control Systems
    Xue, Yawen
    Pan, Jie
    Geng, Yangyang
    Yang, Zeyu
    Liu, Mengxiang
    Deng, Ruilong
    [J]. IEEE Transactions on Industrial Cyber-Physical Systems, 2024, 2 : 143 - 153