Industrial Control System Fingerprinting and Anomaly Detection - Critical Infrastructure Protection IX
Conference Papers Year : 2015

Industrial Control System Fingerprinting and Anomaly Detection

Abstract

Industrial control systems are cyber-physical systems that supervise and control physical processes in critical infrastructures such as electric grids, water and wastewater treatment plants, oil and natural gas pipelines, transportation systems and chemical plants and refineries. Leveraging the stable and persistent control flow communications patterns in industrial control systems, this chapter proposes an innovative control system fingerprinting methodology that analyzes industrial control protocols to capture normal behavior characteristics. The methodology can be used to identify specific physical processes and control system components in industrial facilities and detect abnormal behavior. An experimental testbed that incorporates real systems for the cyber domain and simulated systems for the physical domain is used to validate the methodology. The experimental results demonstrate that the fingerprinting methodology holds promise for detecting anomalies in industrial control systems and cyber-physical systems used in the critical infrastructure.
Fichier principal
Vignette du fichier
978-3-319-26567-4_5_Chapter.pdf (1.52 Mo) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-01431014 , version 1 (10-01-2017)

Licence

Identifiers

Cite

Yong Peng, Chong Xiang, Haihui Gao, Dongqing Chen, Wang Ren. Industrial Control System Fingerprinting and Anomaly Detection. 9th International Conference on Critical Infrastructure Protection (ICCIP), Mar 2015, Arlington, VA, United States. pp.73-85, ⟨10.1007/978-3-319-26567-4_5⟩. ⟨hal-01431014⟩
128 View
664 Download

Altmetric

Share

More