• DocumentCode
    2354744
  • Title

    Detecting cyber intrusions in SCADA networks using multi-agent collaboration

  • Author

    Shosha, Ahmed F. ; Gladyshev, Pavel ; Wu, Shinn-Shyan ; Liu, Chen-Ching

  • Author_Institution
    Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland
  • fYear
    2011
  • fDate
    25-28 Sept. 2011
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Current SCADA (Supervisory Control and Data Acquisition) system architecture increases the interconnectivity to/from other distributed networks and services. In addition, within the SCADA networks there are different types of sub-networks and protocols that are used to monitor and control industrial operations. This complex expansion increases the productivity of SCADA networks; however, it also increases security risks and threats. The state-of-the-art Intrusion Detection Systems (IDSs) are not capable enough of detecting anomalies and intrusions that may be aimed to disrupt the SCADA operations. This paper proposes a Distributed Intrusion Detection System (DIDS) based on a community collaboration between multiple agents of anomaly detectors to identify anomaly behaviors in SCADA networks. The proposed architecture for DIDS incorporates the SCADA network topology and connectivity constraints. In this paper, detailed architecture, components, and functions of DIDS are described and attack scenarios are developed to validate the effectiveness of the proposed methodology.
  • Keywords
    SCADA systems; multi-agent systems; security of data; SCADA network topology; SCADA operation; anomaly detectors; community collaboration; cyber intrusion detection system; data acquisition system architecture; distributed intrusion detection system; distributed networks; industrial operation control; multiagent collaboration; productivity; protocols; security risk; supervisory control; Artificial neural networks; Correlation; Engines; IP networks; Payloads; Protocols; Substations; Anomaly Detection; Cyber Security; Distributed Intrusion Detection Systems; Multi-Agent Systems; Neural Networks; SCADA Networks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligent System Application to Power Systems (ISAP), 2011 16th International Conference on
  • Conference_Location
    Hersonissos
  • Print_ISBN
    978-1-4577-0807-7
  • Electronic_ISBN
    978-1-4577-0808-4
  • Type

    conf

  • DOI
    10.1109/ISAP.2011.6082170
  • Filename
    6082170