中国科学院机构知识库网格
Chinese Academy of Sciences Institutional Repositories Grid
Event-based anomaly detection for non-public industrial communication protocols in SDN-based control systems

文献类型:期刊论文

作者Yao, Jiangyuan4; Jin X(金曦)1,3; Wan M(万明)2; Jing, Yuan2
刊名Computers, Materials and Continua
出版日期2018
卷号55期号:3页码:447-463
关键词Event Sequence Anomaly Detection Non-public Industrial Communication Protocols Sdn
ISSN号1546-2218
产权排序4
英文摘要

As the main communication mediums in industrial control networks, industrial communication protocols are always vulnerable to extreme exploitations, and it is very difficult to take protective measures due to their serious privacy. Based on the SDN (Software Defined Network) technology, this paper proposes a novel event-based anomaly detection approach to identify misbehaviors using non-public industrial communication protocols, and this approach can be installed in SDN switches as a security software appliance in SDN-based control systems. Furthermore, aiming at the unknown protocol specification and message format, this approach first restructures the industrial communication sessions and merges the payloads from industrial communication packets. After that, the feature selection and event sequence extraction can be carried out by using the N-gram model and K-means algorithm. Based on the obtained event sequences, this approach finally trains an event-based HMM (Hidden Markov Model) to identify aberrant industrial communication behaviors. Experimental results clearly show that the proposed approach has obvious advantages of classification accuracy and detection efficiency.

语种英语
WOS记录号WOS:000438476000006
资助机构Hainan Provincial Natural Science Foundation of China (618QN219), the National Natural Science Foundation of China (Grant No. 61501447) and the General Project of Scientific Research of Liaoning Provincial Department of Education (LYB201616)
源URL[http://119.78.100.139/handle/173321/22148]  
专题沈阳自动化研究所_工业控制网络与系统研究室
通讯作者Yao, Jiangyuan
作者单位1.Shenyang Institute of Automation, Chinese Academy of Sciences, Shenyang 110016, China
2.School of Information, Liaoning University, Shenyang 110036, China
3.Department of Computer Science and Engineering, Washington University, St Louis, MO 63130, United States
4.College of Information Science and Technology, University of Hainan, Haikou 570228, China
推荐引用方式
GB/T 7714
Yao, Jiangyuan,Jin X,Wan M,et al. Event-based anomaly detection for non-public industrial communication protocols in SDN-based control systems[J]. Computers, Materials and Continua,2018,55(3):447-463.
APA Yao, Jiangyuan,Jin X,Wan M,&Jing, Yuan.(2018).Event-based anomaly detection for non-public industrial communication protocols in SDN-based control systems.Computers, Materials and Continua,55(3),447-463.
MLA Yao, Jiangyuan,et al."Event-based anomaly detection for non-public industrial communication protocols in SDN-based control systems".Computers, Materials and Continua 55.3(2018):447-463.

入库方式: OAI收割

来源:沈阳自动化研究所

浏览0
下载0
收藏0
其他版本

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。