On Using Physical Based Intrusion Detection in SCADA Systems

被引:12
|
作者
Al-Asiri, Majed [1 ]
El-Alfy, El-Sayed M. [1 ]
机构
[1] King Fahd Univ Petr & Minerals, Dhahran 31261, Saudi Arabia
关键词
Information Security; SCADA; Industrial Control Systems; Cyber Physical Systems (CPS); Industrial Internet of Things (IIoT); Intrusion Detection; Taxonomy; SECURITY;
D O I
10.1016/j.procs.2020.03.007
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Intrusion detection in SCADA systems has received increased attention from researchers as connectivity to public networks became a necessity in many industries. The nature and characteristics of SCADA systems call for special considerations and techniques of intrusion detection. Many works have been made in this field, ranging from generic intrusion detection techniques to customized solutions designed specifically for SCADA systems. In the recent years, some works have focused on using physical metrics in addition to the popular network-based and host-based intrusion detection approaches. This paper presents a taxonomy that considers the special features of cyberphysical intrusion detection systems (IDSs) with examples from the literature. Moreover, a case study is presented for a simulated gas pipeline dataset to compare the effectiveness of decision tree classifiers for various categories of features in SCADA systems. The results show that an IDS that uses a combination of physical and network metrics significantly outperforms an IDS that only uses network metrics or physical metrics. (C) 2020 The Authors. Published by Elsevier B.V.
引用
收藏
页码:34 / 42
页数:9
相关论文
共 50 条
  • [21] State-Based Network Intrusion Detection Systems for SCADA Protocols: A Proof of Concept
    Carcano, Andrea
    Fovino, Igor Nai
    Masera, Marcelo
    Trombetta, Alberto
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, 2010, 6027 : 138 - +
  • [22] A Framework for Improving the Accuracy of Unsupervised Intrusion Detection for SCADA Systems
    Almalawi, Abdulmohsen
    Tari, Zahir
    Fahad, Adil
    Khalil, Ibrahim
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 292 - 301
  • [23] Intrusion Detection in SCADA Systems by Traffic Periodicity and Telemetry Analysis
    Zhang, Jiexin
    Gan, Shaoduo
    Liu, Xiaoxue
    Zhu, Peidong
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 318 - 325
  • [24] Security and Intrusion Detection on Critical SCADA Systems for Water Management
    Stoian, I.
    Ignat, S.
    Capatina, D.
    Ghiran, O.
    2014 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS, 2014,
  • [25] The Effect of Dataset Imbalance on the Performance of SCADA Intrusion Detection Systems
    Balla, Asaad
    Habaebi, Mohamed Hadi
    Elsheikh, Elfatih A. A.
    Islam, Md. Rafiqul
    Suliman, F. M.
    SENSORS, 2023, 23 (02)
  • [26] Accurate modeling of Modbus/TCP for intrusion detection in SCADA systems
    Goldenberg, Niv
    Wool, Avishai
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2013, 6 (02) : 63 - 75
  • [27] Comparison of the Intrusion Detection System Rules in Relation with the SCADA Systems
    Vavra, Jan
    Hromada, Martin
    SOFTWARE ENGINEERING PERSPECTIVES AND APPLICATION IN INTELLIGENT SYSTEMS, VOL 2, 2016, 465 : 159 - 169
  • [28] Intrusion Detection in SCADA Networks
    Barbosa, Rafael Ramos Regis
    Pras, Aiko
    MECHANISMS FOR AUTONOMOUS MANAGEMENT OF NETWORKS AND SERVICES, 2010, 6155 : 163 - 166
  • [29] A cyber-physical model for SCADA system and its intrusion detection
    Sheng, Chuan
    Yao, Yu
    Fu, Qiang
    Yang, Wei
    COMPUTER NETWORKS, 2021, 185
  • [30] Intrusion Detection in Cyber Physical Systems Based on Process Modelling
    Holczer, Tamas
    Gazdag, Andras
    Miru, Gyorgy
    PROCEEDINGS OF THE 15TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2016), 2016, : 127 - 135