• DocumentCode
    3279129
  • Title

    Data fusion-base anomay detection in networked critical infrastructures

  • Author

    Genge, Bela ; Siaterlis, Christos ; Karopoulos, Georgios

  • Author_Institution
    Joint Res. Centre, Inst. for the Protection & Security of the Citizen, Ispra, Italy
  • fYear
    2013
  • fDate
    24-27 June 2013
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    The dramatic increase in the use of Information and Communication Technologies (ICT) within Networked Critical Infrastructures (NCIs), e.g., the power grid, has lead to more efficient and flexible installations as well as new services and features, e.g., remote monitoring and control. Nevertheless, this has not only exposed NCIs to typical ICT systems attacks, but also to a new breed of cyber-physical attacks. To alleviate these issues, in this paper we propose a novel approach for detecting cyber-physical anomalies in NCIs using the concept of Cyber-physical data fusion. By employing Dempster-Shafer´s “Theory of Evidence” we combine knowledge from the cyber and physical dimension of NCIs in order to achieve an Anomaly Detection System (ADS) capable to detect even small disturbances that are not detected by traditional approaches. The proposed ADS is validated in a scenario assessing the consequences of Distributed Denial of Service (DDoS) attacks on Multi Protocol Label Switching (MPLS) Virtual Private Networks (VPNs) and the propagation of such disturbances to the operation of a simulated power grid.
  • Keywords
    computer network security; inference mechanisms; multiprotocol label switching; power grids; virtual private networks; ADS; DDoS attack; Dempster-Shafer theory-of-evidence; ICT system attack; MPLS; NCI; VPN; anomaly detection system; cyber-physical anomaly; cyber-physical attack; cyber-physical data fusion; distributed denial-of-service; information and communication technologies; multiprotocol label switching; networked critical infrastructure; power grid; virtual private network; Feature extraction; Ions; Monitoring; Throughput; Weaving; Anomaly Detection System; DDoS; Data Fusion; MPLS; Networked Critical Infrastructures; SCADA;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks Workshop (DSN-W), 2013 43rd Annual IEEE/IFIP Conference on
  • Conference_Location
    Budapest
  • ISSN
    2325-6648
  • Type

    conf

  • DOI
    10.1109/DSNW.2013.6615505
  • Filename
    6615505