상세 보기
Anomaly Detection Based on Burst Characteristics for DNP3
- 하기웅;
- 임대운;
- 장민호;
- 장지웅
초록
The SCADA (supervisory control and data acquisition) system has many existing security vulnerabilities because the systems are connected on network-based communications. Whereas conventional attacks concentrate on the server or master in the internet environment, direct attacks to outstations or slaves may cause significant damage in the SCADA system. If an attacker has a good knowledge of the control protocols of the SCADA system, it could attack an outstation disguised as a master. In this situation, the rule-based intrusion detection system might not be able to classify the malicious control message as intrusion because the message appears as a normal message. In this paper, an intrusion detection model based on the burst characteristics of the SCADA system with DNP3 (distributed network protocol) is proposed for outstations. Using the challenge-response authentication of the DNP3 protocol, the proposed model automatically updates a white list used to determine the control message.
키워드
- 제목
- Anomaly Detection Based on Burst Characteristics for DNP3
- 제목 (타언어)
- Anomaly Detection Based on Burst Characteristics for DNP3
- 저자
- 하기웅; 임대운; 장민호; 장지웅
- 발행일
- 2018-07
- 저널명
- 한국통신학회논문지
- 권
- 43
- 호
- 7
- 페이지
- 1084 ~ 1099