Dynamic rule generation for SCADA intrusion detection
Jeyasingam Nivethan, Mauricio Papa · 2016
Security of Supervisory Control and Data Acquisition (SCADA) systems remains a vital issue due to the criticality of the systems they control. They are used in various critical infrastructures, including electric power, oil & gas and others. The protocols used in this domain were designed to satisfy operational requirements without much consideration for security issues. Most SCADA protocols in use today have the ability to transport control messages over TCP/IP networks, leaving them open to attacks that may have a catastrophic impact on the physical systems they control. This paper describes a research effort to improve the current state intrusion detection solutions for SCADA systems. Intrusion Detection Systems (IDS) used in this domain are typically extensions of IT tools, such as Snort, that have been extended with generic static signatures. The main limitation of this approach is its inability to adapt to system changes and it only offers partial support for deep-packet inspection. The proposed approach improves on existing IDS solutions by developing a framework that allows (i) dynamic rule generation and (ii) fine-tuned deep-packet inspection. A simple language grammar allows network engineers to describe system characteristics that include network topology, protocol and the roles of the different control nodes. A compiler, instrumented with SCADA-specific semantic rules, recognizes monitoring needs and generates network signatures that are specific to the system monitored by the IDS. An organization using our approach has the ability to adapt to system changes by simply updating the system description and its monitoring needs.