Generating Abnormal Industrial Control Network Traffic for Intrusion Detection System Testing - Critical Infrastructure Protection XII 12th IFIP WG 11.10 International Conference, ICCIP 2018
Conference Papers Year : 2018

Generating Abnormal Industrial Control Network Traffic for Intrusion Detection System Testing

Abstract

Industrial control systems are widely used across the critical infrastructure sectors. Anomaly-based intrusion detection is an attractive approach for identifying potential attacks that leverage industrial control systems to target critical infrastructure assets. In order to analyze the performance of an anomaly-based intrusion detection system, extensive testing should be performed by considering variations of specific cyber threat scenarios, including victims, attack timing, traffic volume and transmitted contents. However, due to security concerns and the potential impact on operations, it is very difficult, if not impossible, to collect abnormal network traffic from real-world industrial control systems. This chapter addresses the problem by proposing a method for automatically generating a variety of anomalous test traffic based on cyber threat scenarios related to industrial control systems.
Fichier principal
Vignette du fichier
476849_1_En_14_Chapter.pdf (395.47 Ko) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-02076309 , version 1 (22-03-2019)

Licence

Identifiers

Cite

Joo-Yeop Song, Woomyo Lee, Jeong-Han Yun, Hyunjae Park, Sin-Kyu Kim, et al.. Generating Abnormal Industrial Control Network Traffic for Intrusion Detection System Testing. 12th International Conference on Critical Infrastructure Protection (ICCIP), Mar 2018, Arlington, VA, United States. pp.265-281, ⟨10.1007/978-3-030-04537-1_14⟩. ⟨hal-02076309⟩
83 View
118 Download

Altmetric

Share

More