State-based network intrusion detection systems for SCADA protocols: a proof of concept

  • Authors:
  • Andrea Carcano;Igor Nai Fovino;Marcelo Masera;Alberto Trombetta

  • Affiliations:
  • University of Insubria, Varese, Italy;Joint Research Centre, Institute for the Protection and Security of the Citizen, Ispra, Italy;Joint Research Centre, Institute for the Protection and Security of the Citizen, Ispra, Italy;University of Insubria, Varese, Italy

  • Venue:
  • CRITIS'09 Proceedings of the 4th international conference on Critical information infrastructures security
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present a novel Intrusion Detection System able to detect complex attacks to SCADA systems. By complex attack, we mean a set of commands (carried in Modbus packets) that, while licit when considered in isolation on a single-packet basis, interfere with the correct behavior of the system. The proposed IDS detects such attacks thanks to an internal representation of the controlled SCADA system and a corresponding rule language, powerful enough to express the system's critical states. Furthermore, we detail the implementation and provide experimental comparative results.