Intrusion detection in SCADA networks

  • Authors:
  • Rafael Ramos Regis Barbosa;Aiko Pras

  • Affiliations:
  • University of Twente, Design and Analysis of Communication Systems, Enschede, The Netherlands;University of Twente, Design and Analysis of Communication Systems, Enschede, The Netherlands

  • Venue:
  • AIMS'10 Proceedings of the Mechanisms for autonomous management of networks and services, and 4th international conference on Autonomous infrastructure, management and security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Supervisory Control and Data Acquisition (SCADA) systems are a critical part of large industrial facilities, such as water distribution infrastructures. With the goal of reducing costs and increasing efficiency, these systems are becoming increasingly interconnected. However, this has also exposed them to a wide range of network security problems. Our research focus on the development of a novel flow-based intrusion detection system. Based on the assumption that SCADA networks are well-behaved, we believe that it is possible to model the normal traffic by establishing relations between network flows. To improve accuracy and provide more information on the anomalous traffic, we will also research methods to derive a flow-based model for anomalous flows.