Intrusion Detection of Industrial Control System based on Modbus TCP Protocol

被引:31
|
作者
Wang Yusheng [1 ]
Fan Kefeng [2 ]
Lai Yingxu [1 ]
Liu Zenghui [3 ]
Zhou Ruikang [2 ]
Yao Xiangzhen [2 ]
Li Lin [2 ]
机构
[1] Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
[2] China Elect Standardizat Inst, Beijing 100007, Peoples R China
[3] Beijing Polytech, Automat Engn Sch, Beijing 100176, Peoples R China
基金
北京市自然科学基金;
关键词
industrial control systems; protocol parsing; semantic analysis; period; deep inspection;
D O I
10.1109/ISADS.2017.29
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modbus over TCP/IP is one of the most popular industrial network protocol that are widely used in critical infrastructures. However, vulnerability of Modbus TCP protocol has attracted widely concern in the public. The traditional intrusion detection methods can identify some intrusion behaviors, but there are still some problems. In this paper, we present an innovative approach, SD-IDS (Stereo Depth IDS), which is designed for perform real-time deep inspection for Modbus TCP traffic. SD-IDS algorithm is composed of two parts: rule extraction and deep inspection. The rule extraction module not only analyzes the characteristics of industrial traffic, but also explores the semantic relationship among the key field in the Modbus TCP protocol. The deep inspection module is based on rule-based anomaly intrusion detection. Furthermore, we use the online test to evaluate the performance of our SD-IDS system. Our approach get a low rate of false positive and false negative.
引用
收藏
页码:156 / 162
页数:7
相关论文
共 50 条
  • [41] Design and Implementation of Industrial Firewall for Modbus/TCP
    Shang, Wenli
    Qiao, Quansheng
    Wan, Ming
    Zeng, Peng
    JOURNAL OF COMPUTERS, 2016, 11 (05) : 432 - 438
  • [42] The Design and Implementation of Wireless Sensor Network Monitoring and Control System Based on Modbus/TCP
    Fu Jingqi
    Guo Jun
    Zheng Xueli
    Du Xin
    Liu Fuwei
    2013 25TH CHINESE CONTROL AND DECISION CONFERENCE (CCDC), 2013, : 3319 - 3323
  • [43] Protecting Modbus/TCP-Based Industrial Automation and Control Systems Using Message Authentication Codes
    Katulic, Filip
    Sumina, Damir
    Gros, Stjepan
    Erceg, Igor
    IEEE ACCESS, 2023, 11 : 47007 - 47023
  • [44] Improve the Security of Industrial Control System: A Fine-Grained Classification Method for DoS Attacks on Modbus/TCP
    Hao Zhang
    Yuandong Min
    Sanya Liu
    Hang Tong
    Yaopeng Li
    Zhihan Lv
    Mobile Networks and Applications, 2023, 28 : 839 - 852
  • [45] A new intrusion detection model for industrial control system based on hierarchical interval-based BRB
    Qian G.
    Hu L.
    Zhang W.
    He W.
    Intelligent Systems with Applications, 2023, 18
  • [46] Improve the Security of Industrial Control System: A Fine-Grained Classification Method for DoS Attacks on Modbus/TCP
    Zhang, Hao
    Min, Yuandong
    Liu, Sanya
    Tong, Hang
    Li, Yaopeng
    Lv, Zhihan
    MOBILE NETWORKS & APPLICATIONS, 2023, 28 (02): : 839 - 852
  • [47] An IoT-Based Intrusion Detection System Approach for TCP SYN Attacks
    Berguiga, Abdelwahed
    Harchay, Ahlem
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 71 (02): : 3839 - 3851
  • [48] Research on Distributed Intrusion Detection System Based on Protocol Analysis
    Qu, Xiaohong
    Liu, Zhijie
    Xie, Xiaoyao
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY, AND IDENTIFICATION IN COMMUNICATION, 2009, : 421 - 424
  • [49] A proposal of protocol and policy-based intrusion detection system
    Baba, T
    Matsuda, S
    7TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL, III, PROCEEDINGS: COMMUNICATION, NETWORK AND CONTROL SYSTEMS, TECHNOLOGIES AND APPLICATIONS, 2003, : 365 - 370
  • [50] Intrusion Detection System in UDP Protocol
    Duraiswamy, K.
    Palanivel, G.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (03): : 1 - 5