ETRI-Knowledge Sharing Plaform

ENGLISH

성과물

논문 검색
구분 SCI
연도 ~ 키워드

상세정보

학술대회 Detecting Abnormal Behavior in SCADA Networks Using Normal Traffic Pattern Learning
Cited 9 time in scopus Download 1 time Share share facebook twitter linkedin kakaostory
저자
김병구, 강동호, 나중찬, 정태명
발행일
201412
출처
International Conference on Computer Science and its Applications (CSA) 2014 (LNEE 330), v.330, pp.121-126
DOI
https://dx.doi.org/10.1007/978-3-662-45402-2_18
협약과제
14MS6500, 파이프라인 시설의 가용성 확보를 위한 제어시스템 인트라넷 보호용 침해사고 이상징후 탐지 및 다중계층 대응기술 개발, 나중찬
초록
SCADA systems have been upgraded from the standard serial bus systems to modern TCP/IP based systems. The Modbus protocol is one of the most widely used protocols in SCADA networks. However, it provides no inherent security mechanisms. Therefore, the Modbus protocol is susceptible to the type of attack that injects false Modbus commands by fabrication or modification. In this paper, we propose an abnormal behavior detection method by using normal traffic pattern learning on Modbus/TCP transactions. Our approach is based on the characteristics of SCADA networks that are likely to have a regular traffic pattern. Most of all, the proposed method is performed according to the analysis of only Modbus/TCP request messages. Therefore, it has the benefit of detecting abnormal behavior on even with the simple traffic pattern learning.
KSP 제안 키워드
Bus system, Detection Method, MODBUS protocol, Normal traffic, Pattern learning, SCADA Systems, Traffic pattern, abnormal behavior detection, based system, security mechanism, serial bus