A Distributed IDS for Industrial Control Systems

被引:4
|
作者
Cruz, Tiago [1 ]
Proenca, Jorge [1 ]
Simoes, Paulo [1 ]
Aubigny, Matthieu [2 ]
Ouedraogo, Moussa [3 ]
Graziano, Antonio [4 ]
Maglaras, Leandros [5 ]
机构
[1] Univ Coimbra, Coimbra, Portugal
[2] iTrust Consulting, Niederanven, Luxembourg
[3] Luxembourg Inst Sci & Technol, Kirchberg, Luxembourg
[4] Selex ES, Rome, Italy
[5] Univ Surrey, Guildford, Surrey, England
关键词
Critical Infrastructure Protection; ICS Security; Information Management; Information Operations; Perception Management;
D O I
10.4018/ijcwt.2014040101
中图分类号
D0 [政治学、政治理论];
学科分类号
0302 ; 030201 ;
摘要
Cyber-threats are one of the most significant problems faced by modern Industrial Control Systems (ICS), such as SCADA (Supervisory Control and Data Acquisition) systems, as the vulnerabilities of ICS technology become serious threats that can ultimately compromise human lives. This situation demands a domainspecific approach to cyber threat detection within ICS, which is one of the most important contributions of the CockpitCI FP7 project (http://CockpitCI.eu). Specifically, this paper will present the CockpitCI distributed Intrusion Detection System (IDS) for ICS, which provides its core cyber-detection and analysis capabilities, also including a description of its components, in terms of role, operation, integration, and remote management. Moreover, it will also introduce and describe new domain-specific solutions for ICS security such as the SCADA Honeypot and the Shadow Security Unit, which are part of the CockcpitCI IDS framework.
引用
收藏
页码:1 / 22
页数:22
相关论文
共 50 条