Generating Abnormal Industrial Control Network Traffic for Intrusion Detection System Testing - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2018

Generating Abnormal Industrial Control Network Traffic for Intrusion Detection System Testing

Résumé

Industrial control systems are widely used across the critical infrastructure sectors. Anomaly-based intrusion detection is an attractive approach for identifying potential attacks that leverage industrial control systems to target critical infrastructure assets. In order to analyze the performance of an anomaly-based intrusion detection system, extensive testing should be performed by considering variations of specific cyber threat scenarios, including victims, attack timing, traffic volume and transmitted contents. However, due to security concerns and the potential impact on operations, it is very difficult, if not impossible, to collect abnormal network traffic from real-world industrial control systems. This chapter addresses the problem by proposing a method for automatically generating a variety of anomalous test traffic based on cyber threat scenarios related to industrial control systems.
Fichier principal
Vignette du fichier
476849_1_En_14_Chapter.pdf (395.47 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02076309 , version 1 (22-03-2019)

Licence

Paternité

Identifiants

Citer

Joo-Yeop Song, Woomyo Lee, Jeong-Han Yun, Hyunjae Park, Sin-Kyu Kim, et al.. Generating Abnormal Industrial Control Network Traffic for Intrusion Detection System Testing. 12th International Conference on Critical Infrastructure Protection (ICCIP), Mar 2018, Arlington, VA, United States. pp.265-281, ⟨10.1007/978-3-030-04537-1_14⟩. ⟨hal-02076309⟩
72 Consultations
85 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More