Anomaly Detection in Automation Controllers


연구 분야: Analysis



학회: International Conference on Critical Infrastructure Protection


초록

Cyber-physical systems incorporate powerful devices that are used to monitor and control physical processes. These devices along with collectable statistics can be leveraged as sensors for network-based and host-based anomaly detection. Host-based anomaly detection can be used in a defense-in-depth strategy to complement traditional network-based anomaly detection systems as well in systems for which network-based options are infeasible due to their operating environments. This chapter discusses the development of an anomaly detection system for a SEL-3505 RTAC programmable logic controller using the recommended IEC 61131 programming tools. The required device statistics are harvested by creating a Modbus server on the test system and polling the server to retrieve data. The collected data is used to create a representative fingerprint for the associated task. When the measured behavior differs from the fingerprint, an anomaly is detected and an alarm is raised. This approach is flexible and easily implemented in existing installations. The performance of the anomaly detection system is evaluated against several network-based attacks across multiple firmware revisions and project types. Recommendations are made to improve anomaly detection performance.


Author Profile
Robert Mellish

Computer Engineering Air Force Institute of Technology Wright-Patterson Air Force Base Ohio USA

United States
Author Profile
Scott Graham

Computer Engineering Air Force Institute of Technology Wright-Patterson Air Force Base Ohio USA

United States
Author Profile
Stephen Dunlap

Cyber Security Research Engineer Air Force Institute of Technology Wright-Patterson Air Force Base Ohio USA

United States

📄 논문 정보

발행 연도 2022년
인용수 0
출판 국가 United States
사이트 Springer
좋아요 수 0

연관 논문 목록 (248건)