Understanding Indicators of Compromise against Cyber-attacks in Industrial Control Systems: A Security Perspective


연구 분야: Infrastructure



학회: ACM Transactions on Cyber-Physical Systems, Volume 7, Issue 2


초록

Numerous sophisticated and nation-state attacks on Industrial Control Systems (ICSs) have increased in recent years, exemplified by Stuxnet and Ukrainian Power Grid. Measures to be taken post-incident are crucial to reduce damage, restore control, and identify attack actors involved. By monitoring Indicators of Compromise (IOCs), the incident responder can detect malicious activity triggers and respond quickly to a similar intrusion at an earlier stage. However, to implement IOCs in critical infrastructures, we need to understand their contexts and requirements. Unfortunately, there is no survey paper in the literature on IOC in the ICS environment, and only limited information is provided in research articles. In this article, we describe different standards for IOC representation and discuss the associated challenges that restrict security investigators from developing IOCs in the industrial sectors. We also discuss the potential IOCs against cyber-attacks in ICS systems. Furthermore, we conduct a critical analysis of existing works and available tools in this space. We evaluate the effectiveness of identified IOCs’ by mapping these indicators to the most frequently targeted attacks in the ICS environment. Finally, we highlight the lessons to be learned from the literature and the future problems in the domain along with the approaches that might be taken.


Author Profile
Mohammed Asiri

Cardiff University Cardiff Cardiff UK

정보 없음
Author Profile
Neetesh Saxena

Cardiff University Cardiff Cardiff UK

정보 없음
Author Profile
Rigel Gjomemo

University of Illinois at Chicago Chicago Illinois USA

Austria

📄 논문 정보

발행 연도 2023년
인용수 39
출판 국가 Austria
사이트 ACM
좋아요 수 0

연관 논문 목록 (254건)