Designing snort rules to detect abnormal DNP3 network data

Hao Li, Guangjie Liu, Weiwei Jiang, Yuewei Dai · 2015

Vulnerability of industrial control network communication protocol is the most important reason leading to industrial control network attacks. In this paper, the vulnerability of DNP3, the typical industrial control network communication protocol, is analyzed. The abnormal behaviors of DNP3 are categorized according to the Snort detection mechanisms. The Snort detection rule template for anomaly DNP3 data is constructed and the rules are designed according the template. The rule designing method can be generally extended to other network-based industrial control protocols.

Read the paper · More papers on PaperTik