Abstract :
Security event logs play a role in the early detection of attacks and in after incident investigations. Controllers used in SCADA, DCS and other control systems log almost no security events. This deficiency is addressed by the Quickdraw application, which is a passive security log generator for controllers. Quickdraw monitors communication like a network IDS, detects events that should be logged in a controller, creates the security events, and then sends the event to a historian, SEM or other log aggregator.
Keywords :
SCADA systems; control engineering computing; security of data; system monitoring; Quickdraw; control system devices; intrusion detection system; legacy SCADA; network IDS; security event logs; Communication system control; Communication system security; Computer security; Control systems; Data security; Distributed control; Event detection; Intrusion detection; National security; SCADA systems; Process Control System Security; Real-time security event assessment and mitigation;