Smart Device Profiling for Smart SCADA

D. Hadziosmanovic, D. Bolzoni, Pieter H. Hartel

    Research output: Contribution to conferencePaper

    38 Downloads (Pure)

    Abstract

    SCADA (Supervisory Control and Data Acquisition) systems are computer systems used for monitoring and controlling industrial processes such as power plants and power grid systems, water, gas and oil distribution systems, production systems for food, cars and other products. We propose a new approach for regulating and detecting malicious behaviour of network devices in SCADA systems. Our approach consists of building proles that describe normal communication between pairs of devices in the network. Each prole describes four aspects of network communication: device ngerprint, connectivity pattern, pseudo-protocol pattern and packet content. We validate our approach using network trac from two real-life SCADA installations.
    Original languageUndefined
    Number of pages2
    Publication statusPublished - Sept 2011
    Event14th International Symposium on Recent Advances in Intrusion Detection - Menlo Park, United States
    Duration: 20 Sept 201121 Sept 2011

    Conference

    Conference14th International Symposium on Recent Advances in Intrusion Detection
    Abbreviated titleRAID 2011
    Country/TerritoryUnited States
    CityMenlo Park
    Period20/09/1121/09/11

    Keywords

    • IR-78072

    Cite this