Network-based Anomaly Detection for SCADA Systems : Traffic Generation and Modeling

Chih‐Yuan Lin · Linköping studies in science and technology. Dissertations · 2022

Supervisory Control and Data Acquisition (SCADA) systems control and monitor critical infrastructure in society, such as electricity transmission and distribution systems.Modern SCADA systems are increasingly adopting open standards and being connected to the Internet to enable remote control.A boost in sophisticated attacks against SCADA systems makes SCADA security a pressing issue.An Intrusion Detection System (IDS) is a security countermeasure that monitors a network and tracks unauthenticated activities inside the network.Most commercial IDSs used in general IT systems are signature-based, by which an IDS compares the system behaviors with known attack patterns.Unfortunately, recent attacks against SCADA systems exploit zero-day vulnerabilities which are undetectable by signature-based IDSs.This thesis aims to enhance SCADA system monitoring by network-based anomaly detection that models normal behaviors and finds deviations from the model.With network-based anomaly detection, zero-day attacks are possible to detect.There are two main challenges for network-based anomaly detection.The first challenge is the potentially large number of false positives coming from benign traffic that just deviates from the trained model due to the noises.To address this challenge, this thesis proposes several traffic modeling approaches based on statistics and machine learning techniques for the regular communication patterns in SCADA traffic.The second challenge is the lack of open datasets to evaluate the proposed approaches.Consequently, this thesis proposes a traffic generation framework.First and foremost, I want to thank my main supervisor Simin Nadjm-Tehrani for enabling this joint work between the

Read the paper · More papers on PaperTik