• DocumentCode
    2445725
  • Title

    Detection, correlation, and visualization of attacks against critical infrastructure systems

  • Author

    Briesemeister, Linda ; Cheung, Steven ; Lindqvist, Ulf ; Valdes, Alfonso

  • Author_Institution
    SRI Int., Menlo Park, CA, USA
  • fYear
    2010
  • fDate
    17-19 Aug. 2010
  • Firstpage
    15
  • Lastpage
    22
  • Abstract
    Digital control systems are essential to the safe and efficient operation of a variety of industrial processes in sectors such as electric power, oil and gas, water treatment, and manufacturing. Modern control systems are increasingly connected to other control systems as well as to corporate systems. They are also increasingly adopting networking technology and system and application software from conventional enterprise systems. These trends can make control systems vulnerable to cyber attack, which in the case of control systems may impact physical processes causing environmental harm or injury. We present some results of the DATES (Detection and Analysis of Threats to the Energy Sector) project, wherein we adapted and developed several intrusion detection technologies for control systems. The suite of detection technologies was integrated and connected to a commercial security event correlation framework from ArcSight. We demonstrated the efficacy of our detection and correlation solution on two coupled testbed environments. We particularly focused on detection, correlation, and visualization of a network traversal attack, where an attacker penetrates successive network layers to compromise critical assets that directly control the underlying process. Such an attack is of particular concern in the layered architectures typical of control system implementations.
  • Keywords
    security of data; DATES; commercial security event correlation framework; cyber attack; digital control systems; intrusion detection technologies; network traversal attack; Control systems; Correlation; Intrusion detection; Monitoring; Process control; Servers; alert correlation; anomaly detection; control system security; critical infrastructure security; intrusion; security information event management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy Security and Trust (PST), 2010 Eighth Annual International Conference on
  • Conference_Location
    Ottawa, ON
  • Print_ISBN
    978-1-4244-7551-3
  • Electronic_ISBN
    978-1-4244-7549-0
  • Type

    conf

  • DOI
    10.1109/PST.2010.5593242
  • Filename
    5593242