Anomaly Detection Based on Burst Characteristics for DNP3

Anomaly Detection Based on Burst Characteristics for DNP3

초록

The SCADA (supervisory control and data acquisition) system has many existing security vulnerabilities because the systems are connected on network-based communications. Whereas conventional attacks concentrate on the server or master in the internet environment, direct attacks to outstations or slaves may cause significant damage in the SCADA system. If an attacker has a good knowledge of the control protocols of the SCADA system, it could attack an outstation disguised as a master. In this situation, the rule-based intrusion detection system might not be able to classify the malicious control message as intrusion because the message appears as a normal message. In this paper, an intrusion detection model based on the burst characteristics of the SCADA system with DNP3 (distributed network protocol) is proposed for outstations. Using the challenge-response authentication of the DNP3 protocol, the proposed model automatically updates a white list used to determine the control message.

키워드

Anomaly DetectionBurst-basedDNP3Intrusion DetectionSCADAWhite List
제목
Anomaly Detection Based on Burst Characteristics for DNP3
제목 (타언어)
Anomaly Detection Based on Burst Characteristics for DNP3
저자
하기웅임대운장민호장지웅
DOI
10.7840/kics.2018.43.7.1084
발행일
2018-07
저널명
한국통신학회논문지
43
7
페이지
1084 ~ 1099