A DISTRIBUTED REAL-TIME EVENT CORRELATION ARCHITECTURE FOR SCADA SECURITY

被引:0
|
作者
Deng, Yi [1 ]
Shukla, Sandeep [2 ]
机构
[1] Virginia Polytech Inst & State Univ, Dept Elect & Comp Engn, Arlington Res Ctr, Arlington, VA 22203 USA
[2] Virginia Polytech Inst & State Univ, Elect & Comp Engn, Arlington Res Ctr, Arlington, VA USA
来源
关键词
SCADA systems; event correlation; temporal-spatial correlation; RELIABILITY;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Supervisory control and data acquisition (SCADA) systems require real-time threat monitoring and early warning systems to identify cyber attacks. Organizations typically employ intrusion detection systems to identify attack events and to provide situational awareness. However, as cyber attacks become more sophisticated, intrusion detection signatures of single events are no longer adequate. Indeed, effective intrusion detection solutions require the correlation of multiple events that are temporally and/or spatially separated. This paper proposes an innovative event correlation mechanism for cyber threat detection, which engages a semantic event hierarchy. Cyber attacks are specified via low-level events detected in the communications and computing infrastructure and correlated to identify attacks of a broader scope. The paper also describes a distributed architecture for real-time event capture, correlation and dissemination. The architecture employs a publish/subscribe mechanism, which decentralizes limited computing resources to distributed field agents in order to enhance real-time attack detection while limiting unnecessary communications overhead.
引用
收藏
页码:81 / 93
页数:13
相关论文
共 50 条
  • [1] Distributed Real-time Event Analysis
    Stephen, Julian James
    Gmach, Daniel
    Block, Rob
    Madan, Adit
    AuYoung, Alvin
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON AUTONOMIC COMPUTING, 2015, : 11 - 20
  • [2] A PRACTICAL ARCHITECTURE OF DISTRIBUTED REAL-TIME MAIN-MEMORY DATABASES FOR MODERN SCADA SYSTEMS
    Dai Hong-Bin
    Jin Shu
    [J]. 2011 3RD INTERNATIONAL CONFERENCE ON COMPUTER TECHNOLOGY AND DEVELOPMENT (ICCTD 2011), VOL 1, 2012, : 27 - 31
  • [3] HARTS - A DISTRIBUTED REAL-TIME ARCHITECTURE
    SHIN, KG
    [J]. COMPUTER, 1991, 24 (05) : 25 - 35
  • [4] AN ARCHITECTURE FOR REAL-TIME DISTRIBUTED SCHEDULING
    HADAVI, K
    HSU, WL
    CHEN, T
    LEE, CN
    [J]. AI MAGAZINE, 1992, 13 (03) : 46 - 56
  • [5] HEDRA: Heterogeneous distributed real-time architecture
    Thielemans, H
    Demeestere, L
    Van Brussel, H
    [J]. REAL-TIME SYSTEMS, 1998, 14 (03) : 311 - 323
  • [6] HEDRA: Heterogeneous distributed real-time architecture
    Thielemans, H
    Demeestere, L
    VanBrussel, H
    [J]. CONTROL ENGINEERING PRACTICE, 1996, 4 (02) : 187 - 193
  • [7] HEDRA: Heterogeneous Distributed Real-Time Architecture
    H. Thielemans
    L. Demeestere
    H. Van Brussel
    [J]. Real-Time Systems, 1998, 14 : 311 - 323
  • [8] Distributed Architecture for Real-Time Traffic Analysis
    Morariu, Cristian
    Stiller, Burkhard
    [J]. MECHANISMS FOR AUTONOMOUS MANAGEMENT OF NETWORKS AND SERVICES, 2010, 6155 : 171 - 174
  • [9] Real-time correlation of network security alerts
    Li, Zhitang
    Zhang, Aifang
    Lei, Jie
    Wang, Li
    [J]. ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 73 - +
  • [10] Real-Time Event Framework based on component model for distributed real-time systems
    Yoon, EY
    Yoon, YI
    [J]. PDPTA'2001: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED PROCESSING TECHNIQUES AND APPLICATIONS, 2001, : 1942 - 1948