DocumentCode :
2445725
Title :
Detection, correlation, and visualization of attacks against critical infrastructure systems
Author :
Briesemeister, Linda ; Cheung, Steven ; Lindqvist, Ulf ; Valdes, Alfonso
Author_Institution :
SRI Int., Menlo Park, CA, USA
fYear :
2010
fDate :
17-19 Aug. 2010
Firstpage :
15
Lastpage :
22
Abstract :
Digital control systems are essential to the safe and efficient operation of a variety of industrial processes in sectors such as electric power, oil and gas, water treatment, and manufacturing. Modern control systems are increasingly connected to other control systems as well as to corporate systems. They are also increasingly adopting networking technology and system and application software from conventional enterprise systems. These trends can make control systems vulnerable to cyber attack, which in the case of control systems may impact physical processes causing environmental harm or injury. We present some results of the DATES (Detection and Analysis of Threats to the Energy Sector) project, wherein we adapted and developed several intrusion detection technologies for control systems. The suite of detection technologies was integrated and connected to a commercial security event correlation framework from ArcSight. We demonstrated the efficacy of our detection and correlation solution on two coupled testbed environments. We particularly focused on detection, correlation, and visualization of a network traversal attack, where an attacker penetrates successive network layers to compromise critical assets that directly control the underlying process. Such an attack is of particular concern in the layered architectures typical of control system implementations.
Keywords :
security of data; DATES; commercial security event correlation framework; cyber attack; digital control systems; intrusion detection technologies; network traversal attack; Control systems; Correlation; Intrusion detection; Monitoring; Process control; Servers; alert correlation; anomaly detection; control system security; critical infrastructure security; intrusion; security information event management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy Security and Trust (PST), 2010 Eighth Annual International Conference on
Conference_Location :
Ottawa, ON
Print_ISBN :
978-1-4244-7551-3
Electronic_ISBN :
978-1-4244-7549-0
Type :
conf
DOI :
10.1109/PST.2010.5593242
Filename :
5593242
Link To Document :
بازگشت