Intrusion Detection of Industrial Control System based on Modbus TCP Protocol

被引:31
|
作者
Wang Yusheng [1 ]
Fan Kefeng [2 ]
Lai Yingxu [1 ]
Liu Zenghui [3 ]
Zhou Ruikang [2 ]
Yao Xiangzhen [2 ]
Li Lin [2 ]
机构
[1] Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
[2] China Elect Standardizat Inst, Beijing 100007, Peoples R China
[3] Beijing Polytech, Automat Engn Sch, Beijing 100176, Peoples R China
基金
北京市自然科学基金;
关键词
industrial control systems; protocol parsing; semantic analysis; period; deep inspection;
D O I
10.1109/ISADS.2017.29
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modbus over TCP/IP is one of the most popular industrial network protocol that are widely used in critical infrastructures. However, vulnerability of Modbus TCP protocol has attracted widely concern in the public. The traditional intrusion detection methods can identify some intrusion behaviors, but there are still some problems. In this paper, we present an innovative approach, SD-IDS (Stereo Depth IDS), which is designed for perform real-time deep inspection for Modbus TCP traffic. SD-IDS algorithm is composed of two parts: rule extraction and deep inspection. The rule extraction module not only analyzes the characteristics of industrial traffic, but also explores the semantic relationship among the key field in the Modbus TCP protocol. The deep inspection module is based on rule-based anomaly intrusion detection. Furthermore, we use the online test to evaluate the performance of our SD-IDS system. Our approach get a low rate of false positive and false negative.
引用
收藏
页码:156 / 162
页数:7
相关论文
共 50 条
  • [31] DEIDS: a novel intrusion detection system for industrial control systems
    Haoran Gu
    Yingxu Lai
    Yipeng Wang
    Jing Liu
    Motong Sun
    Beifeng Mao
    Neural Computing and Applications, 2022, 34 : 9793 - 9811
  • [32] Application of Modbus/TCP Protocol in Smart Home
    Xiao, Zeyu
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON MECHATRONICS ENGINEERING AND INFORMATION TECHNOLOGY (ICMEIT 2017), 2017, 70 : 697 - 700
  • [33] Evaluation of Machine Learning-based Anomaly Detection Algorithms on an Industrial Modbus/TCP Data Set
    Anton, Simon Duque
    Kanoor, Suneetha
    Fraunholz, Daniel
    Schotten, Hans Dieter
    13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,
  • [34] Research on remote attestation-based trusted modbus/TCP protocol
    Zhan J.
    Yang J.
    1600, Sichuan University (49): : 197 - 205
  • [35] Distributed Architecture of an Intrusion Detection System in Industrial Control Systems
    Abid, Ahlem
    Jemili, Farah
    Korbaa, Ouajdi
    ADVANCES IN COMPUTATIONAL COLLECTIVE INTELLIGENCE, ICCCI 2022, 2022, 1653 : 472 - 484
  • [36] Industrial Control System Network Intrusion Detection by Telemetry Analysis
    Ponomarev, Stanislav
    Atkison, Travis
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2016, 13 (02) : 252 - 260
  • [37] A Two Stage Intrusion Detection System for Industrial Control Networks Based on Ethernet/IP
    Yu, Wenbin
    Wang, Yiyin
    Song, Lei
    ELECTRONICS, 2019, 8 (12)
  • [38] Explaining the Attributes of a Deep Learning Based Intrusion Detection System for Industrial Control Networks
    Wang, Zhidong
    Lai, Yingxu
    Liu, Zenghui
    Liu, Jing
    SENSORS, 2020, 20 (14) : 1 - 23
  • [39] Industrial Control System Intrusion Detection Based on Feature Selection and Temporal Convolutional Network
    Shi L.
    Hou H.
    Xu X.
    Xu H.
    Chen H.
    Gongcheng Kexue Yu Jishu/Advanced Engineering Sciences, 2022, 54 (06): : 238 - 247
  • [40] Research on Intrusion Detection of Industrial Control System Based on OPSO-BPNN Algorithm
    Yang, Huiting
    Chen, Tao
    Guo, Xuerang
    Wang, Xu
    Li, Feng
    PROCEEDINGS OF 2017 IEEE 2ND INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC), 2017, : 957 - 961