Multi-stage Cyber-Attacks Detection in the Industrial Control Systems

Tomáš Bajtoš,Pavol Sokol,Terézia Mézešová
DOI: https://doi.org/10.1007/978-3-030-31328-9_8
2019-10-06
Abstract:Industrial Control Systems are a prestigious target for attackers and the attacks are becoming more sophisticated. Intrusion detection systems can uncover suspicious activity and point towards steps of attacks. Detection systems raise an overwhelming number of alerts, so their aggregation and correlation are necessary. It is important for the security analysts to correlate the alerts raised by detection systems and project the next steps of the attack to better protect critical resources. In this chapter, we search for attack patterns in the correlated alerts from industrial control systems network. Our correlation approach is similarity-based according to IP addresses and ports. We construct a directed graph that describes all possible attack paths between multiple attack stages. Several interesting patterns are discussed.
What problem does this paper attempt to address?