姚羽(教授)

+

  • 博士生导师  硕士生导师
  • 电子邮箱:
  • 职务:复杂网络系统安全保障技术教育部工程研究中心主任
  • 学历:博士研究生毕业
  • 性别:男
  • 联系方式:yaoyu@mail.neu.edu.cn
  • 学位:博士
  • 毕业院校:东北大学
  • 所属院系:计算机科学与工程学院
  • 学科:
    计算机应用技术
    计算机软件与理论
    计算机系统结构

访问量:

开通时间:..

最后更新时间:..

切换语种:English

手机版
  • 论文成果

A Cyber-Physical Model for SCADA System and Its Intrusion Detection

发布时间:2021-11-26  点击次数:

  • 发表刊物:Computer Networks.
  • 影响因子:5.493
  • 摘要:Supervisory Control and Data Acquisition (SCADA) systems are becoming increasingly susceptible to the sophisticated and targeted cyber attacks which are typically carried out by exploiting the vulnerabilities of industrial control devices or protocols. However, most of the existing network intrusion detection methods only focus on detecting and characterizing cyber attacks against the SCADA system, but cannot fully describe their real impact on the system. In this paper, we propose a cyber-physical model for the SCADA system to detect intrusions from the SCADA network and evaluate their risk levels against the industrial process. The model aims at characterizing the network structure and industrial process of the SCADA system through extracting and correlating the communication patterns and states of ICS devices. And any violation of the model is considered abnormal behavior, which can be caused by false operation or network attacks. Through associating network intrusions with the status of the SCADA system, a risk assessment method is proposed to estimate the potential damage degree of the attack on the system, which provides network administrators with richer information about network attacks. Moreover, the comprehensive performance evaluation conducted on public SCADA network data sets shows that the proposed method outperforms the existing methods in detecting and analyzing various cyber attacks against the SCADA system.
  • 备注:https://www.sciencedirect.com/science/article/abs/pii/S1389128620312883
  • 文献类型:JCR 一区
  • 是否译文: