DocumentCode :
3255696
Title :
Defending malicious attacks in Cyber Physical Systems
Author :
Chia-Mei Chen ; Han-Wei Hsiao ; Peng-Yu Yang ; Ya-Hui Ou
Author_Institution :
Dept. of Inf. Manage., Nat. Sun Yet-sen Univ., Kaohsiung, Taiwan
fYear :
2013
fDate :
19-20 Aug. 2013
Firstpage :
13
Lastpage :
18
Abstract :
An increasing number of security incidents on industrial control systems drew a lot of concerns lately. Many attacks involved multiple attack vectors similar to internet attacks. However, CPS are more vulnerable to attacks. To evade detection, a hacker may apply multiple attack stages to gain the access to a control system. For example, he first employs a group of zombies (compromised machines) to identify the vulnerabilities of the target system and the findings would send back to the hacker through a communication channel. Once the correct access information is found by the zombies, the hacker could gain unauthorized access without violating any detection rules. The control system may be compromised by such multi-stage attacks and an appropriate defense mechanism is desired. In order to detect the sequence of such attack, this study correlates network information and system logs to find the stages of the attack. Finite state model, hidden Markov chain, is adopted to identify the multi-stage attacks and to prevent real damage. The results show that the proposed system can identify the multi-stage attacks in the early stage efficiently to prevent further damage in the networks.
Keywords :
Internet; hidden Markov models; security of data; Internet attacks; access information; appropriate defense mechanism; communication channel; control system; cyber physical systems; defending malicious attacks; detection rules; hidden Markov chain; industrial control systems; multiple attack stages; multistage attacks; target system; unauthorized access; Control systems; Correlation; Hidden Markov models; Joints; Monitoring; Security; Training; Hidden Markov Model; cloud computing; intrusion detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cyber-Physical Systems, Networks, and Applications (CPSNA), 2013 IEEE 1st International Conference on
Conference_Location :
Taipei
Type :
conf
DOI :
10.1109/CPSNA.2013.6614240
Filename :
6614240
Link To Document :
بازگشت