Malicious Activity Recognition on SCADA Network IEC 60870-5-104 Protocol

M. Agus Syamsul Arifin, Deris Stiawan, Susanto Susanto, Dwi Prasetya, Mohd. Yazid Idris, Rahmat Budiarto · 2021

As SCADA (Supervisory Control Acquisition Data) has extended to a heterogeneous network, makes it opens to any type of internet attack/malicious activity. Malicious activities in the SCADA network may disrupt the control and monitoring process of industrial equipment. These activities can be in the form of Unauthorized Access, Port Scanning, and SYN flood. Each Malicious Activity has features that can be a way to identify it. This paper attempts to investigate the malicious activities in the SCADA network running the IEC 60870-5-104 protocol. Raw traffic data from the SCADA network were recorded in pcap format. Next, by using Snort and Suricata software the characteristics of malicious activities are identified, and then observed using Wireshark software. The observation will produce attacks characteristics/features. The malicious activities in the SCADA network traffic records revealed in this study are SYN Flood, Port Scan, Unauthorized Access and Invalid data on CoT (Cause of Transmission) packets. Knowing these features will help to classify or to identify the attacks. In turn, the recognized features of the SCADA traffic network can be used to develop a machine learning model as a classifier engine in an intrusion detection system (IDS).

Read the paper · More papers on PaperTik