DocumentCode
3582696
Title
A Network Protection Framework for DNP3 over TCP/IP protocol
Author
Jin Bai ; Hariri, Salim ; Al-Nashif, Youssif
Author_Institution
NSF Center for Cloud & Autonomic Comput., Univ. of Arizona, Tucson, AZ, USA
fYear
2014
Firstpage
9
Lastpage
15
Abstract
The pervasive deployment of intelligent devices in the critical infrastructures sector and the high dependency of these devices on the Internet motivated attackers to target the communication and control protocols of these devices. DNP3 over TCP/IP is among those protocols that are widely used as communication and control protocols in critical infrastructures. Due to the facts that security was not part of the goals for designing the DNP3 and the incompetent of current protection systems, adversary can easily succeed in attacking DNP3 devices and network. In this paper, we present an Autonomic Network Protection Framework for DNP3 over TCP/IP that detects old attacks that cannot be prevented by the legacy DNP3 security devices as well as new attacks. The system´s detection module is based on rule-based anomaly intrusion detection. We evaluated the effectiveness of the generated rules in detecting anomalies through both offline and online testing. Both the false positive and the false negative rates of our approach are quite low. In addition, we present a classification technique and an access control mechanism to provide autonomic network protection.
Keywords
Internet; authorisation; computer network security; data protection; transport protocols; DNP3 security; Internet; TCP/IP protocol; access control mechanism; attack detection; autonomic network protection framework; classification technique; communication protocol; control protocol; intelligent device deployment; rule-based anomaly intrusion detection; IP networks; Intrusion detection; Monitoring; Protocols; SCADA systems; Training; Anomaly Detection; Autonomic Network Protection; Critical infrastructures; DNP3 over TCP/IP;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Systems and Applications (AICCSA), 2014 IEEE/ACS 11th International Conference on
Type
conf
DOI
10.1109/AICCSA.2014.7073172
Filename
7073172
Link To Document