ANDVI: Automated Network Device and Vulnerability Identification in SCADA/ICS by Passive Monitoring

被引:0
|
作者
AL Ghazo, Alaa T. [1 ]
Kumar, Ratnesh [2 ]
机构
[1] Hashemite Univ, Fac Engn, Dept Mechatron Engn, Zarqa 13133, Jordan
[2] Iowa State Univ, Dept Elect & Comp Engn, Ames, IA 50014 USA
基金
美国国家科学基金会;
关键词
Databases; Object recognition; Security; TCPIP; Monitoring; SCADA systems; Protocols; Cyber-physical systems (CPSs); device recognition; industrial control systems (ICSs); Internet of Things; Modbus; security; supervisory control and data acquisition (SCADA) TCP/IP;
D O I
10.1109/TSMC.2023.3345254
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Supervisory control and data acquisition (SCADA) and industrial control systems (ICSs) are designed to operate for extended periods of time and can withstand extreme conditions. However, operators, engineers, and offices change over time, which can lead to outdated documentation and references. This can make it difficult to identify system components and their vulnerabilities, which can pose a security risk. In this article, we present an automated passive method for identifying system components based on network traffic structure and network message characteristics. The proposed approach considers both TCP/IP and Modbus, the two primary communication protocols in SCADA, to identify devices. The algorithm was implemented in Python and evaluated using water treatment SCADA data collected from the iTrust facility. Once the system devices have been identified, the algorithm queries the National Vulnerability Database (NVD) and the Common Vulnerabilities and Exposures (CVE) databases to identify each device's known vulnerabilities. Using our research on automated attack graph generation and visualization (A2G2V) and strongly connected component induced min label cut (SCCiMLC), we can map device vulnerabilities to system-level attack graphs and identify the bare minimum of device vulnerabilities to mitigate in order to secure the entire system. The proposed technique has been demonstrated to be beneficial in identifying system components in SCADA and ICS systems to increase their security.
引用
收藏
页码:2539 / 2550
页数:12
相关论文
共 10 条
  • [1] Autonomic Passive IT-OT Device Classification in ICS/SCADA Networks
    Rubin, Benny
    Tekeoglu, Ali
    Rouff, Christopher
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 813 - 818
  • [2] ICS/SCADA Device Recognition: A Hybrid Communication-Patterns and Passive-Fingerprinting Approach
    Al Ghazo, Alaa T.
    Kumar, Ratnesh
    2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019,
  • [3] Automated IoT Device Identification using Network Traffic
    Aksoy, Ahmet
    Gunes, Mehmet Hadi
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [4] Passive Ankle Dorsiflexion by an Automated Device and the Reactivity of the Motor Cortical Network
    Pittaccio, Simone
    Zappasodi, Filippo
    Tamburro, Gabriella
    Viscuso, Stefano
    Marzetti, Laura
    Garavaglia, Lorenzo
    Tecchio, Franca
    Pizzella, Vittorio
    2013 35TH ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2013, : 6353 - 6356
  • [5] Selecting a Passive Network Monitoring Solution for Medical Device Cybersecurity Management
    Upendra P.
    Biomedical Instrumentation and Technology, 2021, 55 (04): : 121 - 130
  • [6] Development of Passive In-line Monitoring (PIM) Device Prototype for FTTH Access Network
    Ng, Boonchuan
    Ab-Rahmani, Mohammad Syuhaimi
    Ismail, Rosmawati
    Ehsan, Abang Anuar
    Shaari, Sahbudin
    INTERNATIONAL CONFERENCE ON FUTURE COMPUTER AND COMMUNICATIONS, PROCEEDINGS, 2009, : 690 - +
  • [7] PNW-Cnet v4: Automated species identification for passive acoustic monitoring
    Ruff, Zachary J.
    Lesmeister, Damon B.
    Jenkins, Julianna M. A.
    Sullivan, Christopher M.
    SOFTWAREX, 2023, 23
  • [8] The implementation of Passive In-line Monitoring (PIM) device in tree-structured FTTH access network
    Ab-Rahman, Mohammad Syuhaimi
    Ng, Boonchuan
    Ismail, Rosmawati
    Ehsan, Abang Anuar
    Journal of Optical Communications, 2009, 30 (02) : 91 - 94
  • [9] Cloud Server-Assisted Remote Monitoring and Core Device Fault Identification for Dynamically Tuned Passive Power Filters
    Wang, Yifei
    Chen, Zhenglong
    Deng, Yi
    APPLIED SCIENCES-BASEL, 2023, 13 (17):
  • [10] Automated IoT Device Identification Based on Full Packet Information Using Real-Time Network Traffic
    Yousefnezhad, Narges
    Malhi, Avleen
    Framling, Kary
    SENSORS, 2021, 21 (08)