Scenario Fingerprint of an Industrial Control System and Abnormally Detection

PENG Yong,XIANG Chong,ZHANG Miao,CHEN Dongqing,GAO Haihui,XIE Feng,DAI Zhonghua
DOI: https://doi.org/10.16511/j.cnki.qhdxxb.2016.23.013
2016-01-01
Abstract:Industrial control systems (ICSs) are cyberphysical systems (CPSs) which supervise and control physical processes in critical infrastructure industries such as electric power,water treatment,oil & natural gas exploration,transportation,and chemical industry.Based on the observation of ICS'stable and persistent communication data flow control patterns,a concept and a methodology of ICS scenario fingerprinting were proposed which analyze industrial control protocol interactive behavior to represent ICS system-level normal behavior characteristics.ICS scenario fingerprint can identify unique ICS installation,while being used as a more generalized method to establish ICS systems'behavior benchmark and further being used to identify ICS systems'abnormal behavior.Experiments were made to validate the proposed viewpoint,which use real equipment for ICS cyber domain and use simulation for ICS physical domain.Experimental results demonstrate that ICS scenario fingerprinting technique provides ICS security research with a promising method.
What problem does this paper attempt to address?