{"title":"What's under the hood? Improving SCADA security with process awareness","authors":"J. Chromik, Anne Remke, B. Haverkort","doi":"10.1109/CPSRSG.2016.7684100","DOIUrl":null,"url":null,"abstract":"SCADA networks are an essential part of monitoring and controlling physical infrastructures, such as the power grid. Recent news items show that tampering with the data exchanged in a SCADA network occurs and has severe consequences. A possible way of improving the security of SCADA networks is to use intrusion detection systems. By monitoring and analysing the traffic, it is possible to detect whether information has a legitimate source or was tampered with. However, in many cases the knowledge of just the traffic is not enough. Detecting intrusions could be improved by including awareness about the physical processes that are controlled. This paper shows a simple analysis of a small scenario of a power distribution system, to illustrate the benefits of including the knowledge about the process in detecting breaches in SCADA.","PeriodicalId":263733,"journal":{"name":"2016 Joint Workshop on Cyber- Physical Security and Resilience in Smart Grids (CPSR-SG)","volume":"43 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-04-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"24","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 Joint Workshop on Cyber- Physical Security and Resilience in Smart Grids (CPSR-SG)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CPSRSG.2016.7684100","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 24
Abstract
SCADA networks are an essential part of monitoring and controlling physical infrastructures, such as the power grid. Recent news items show that tampering with the data exchanged in a SCADA network occurs and has severe consequences. A possible way of improving the security of SCADA networks is to use intrusion detection systems. By monitoring and analysing the traffic, it is possible to detect whether information has a legitimate source or was tampered with. However, in many cases the knowledge of just the traffic is not enough. Detecting intrusions could be improved by including awareness about the physical processes that are controlled. This paper shows a simple analysis of a small scenario of a power distribution system, to illustrate the benefits of including the knowledge about the process in detecting breaches in SCADA.