A Blend of Semantic Monitoring and Intrusion Detection Systems for the Protection of Critical Infrastructures: Research efforts within the Greek Cybercrime Center

D. Kostopoulos, Vasilis N. Tsoulkas, George Leventakis, Vasiliki Politopoulou · 2013

The issues of safety and security of Critical Infrastructures (CIs) as a function of their operational continuity, within nominal operational bounds as well as their robust stability properties against perturbations generated by malicious attacks or human error, are considered globally of highest importance for today’s societies. Due to the direct population impact of the CIs physical controlled processes and services, mismanagement faults or cyber attacks against their components can cause severe damage and cascaded performance degradation that can lead to major crises. Therefore, it is imperative to protect these complex and performance critical distributed systems against any threat, by: • protecting CIs against a wide class of threat consequences, • forbidding the threats to occur within the CIs networks and • predicting the occurrence of a threat and quickly react by eliminating its roots. We provide an overview of the monitoring/reasoning components of the event driven architecture. The tool is modular and provides risk analytics for rapid decision making under uncertainty. Monitored data is captured and fed into a Data Stream Management System (DSMS). This data stream is then applied to a sequential inspection scheme that translates raw data events into possible asset behaviors. These behaviors are then added into a semantics ontology through an Incremental Model Generator (IMG). The updated models are injected into the threat classification and estimation modules and the new security map of the system is displayed on the Decision Support Tool (DST) that alerts the CI supervision team of any new threats or faulty situation.

Read the paper · More papers on PaperTik