Published October 25, 2018 | Version preprint

Exploiting System Model for Securing CPS: the Anomaly Based IDS Perspective

  • 1. Università Roma Tre

Description

Industrial Control systems traditionally achieved security by using isolation from the outside and proprietary protocols to communicate inside. This paradigm is changed with the advent of the Industrial Internet of Things that foresees flexible and interconnected systems. In this contribution, the threats coming from this new approach are analyzed and a framework for identify them is proposed. It is based on the common signature based intrusion detection system developed in the information technology domain, however, to cope with the constraints of the operation technology domain, it exploits anomaly based features. Specifically, it is able to analyze the traffic on the network at application layer by mean of deep packet inspection, parsing the information carried by the proprietary protocols. Two different topologies are adopted to cope also with legacy systems. A simple set up is considered to prove the effectiveness of the approach.

Notes

Please find the final version of this paper on the publisher web site: https://ieeexplore.ieee.org/document/8502495

Files

PID5468509.pdf

Files (323.1 kB)

Name Size Download all
md5:0950f08c6a22b3320640fb60eb4122e4
323.1 kB Preview Download

Additional details

Funding

European Commission
ATENA - Advanced Tools to assEss and mitigate the criticality of ICT compoNents and their dependencies over Critical InfrAstructures 700581