Enhancing Industrial Cyber-Physical Systems Security with Smart Probing Approach

Valeria Bonagura, Chiara Foglietta, S. Panzieri, F. Pascucci
{"title":"Enhancing Industrial Cyber-Physical Systems Security with Smart Probing Approach","authors":"Valeria Bonagura, Chiara Foglietta, S. Panzieri, F. Pascucci","doi":"10.1109/CSR57506.2023.10224912","DOIUrl":null,"url":null,"abstract":"Critical infrastructures and industrial facilities are examples of Cyber-Physical Systems, which are sophisticated systems that integrate physical processes and communication networks. Regrettably, the combination of physical and cyber layers raises the possibility of complications such as a larger surface area for cyberattacks. Due to the unique characteristics of the industrial environment, applying safeguarding architecture similar to that created for the IT sector is not conceivable. Yet, in this study, we exploit the features of industrial communication networks to design the Smart Security Probe, an intrusion detection system for industrial networks. This solution was created to detect potential anomalies in network traffic and to assist in inferring potential anomalies in data connected to physical processes. Smart Security Probe has two operating modes: passive and interactive. When the passive mode is selected, the proposed device analyses the traffic shape in a transparent way, while in the interactive mode it is possible to send packets to allow further analysis and the device is visible in the network. When the interactive mode is activated, a model-based anomaly detection system is included in the suggested approach. Using the Message Queuing Telemetry Transport protocol, the Smart Security Probe can communicate with a remote station to implement an asynchronous Extended Kalman Filter. Smart Security Probe was tested and validated in a system comprised of one Programmable Logic Controller and one Supervisory Control and Data Acquisition system that controls three simulated interconnected tanks.","PeriodicalId":354918,"journal":{"name":"2023 IEEE International Conference on Cyber Security and Resilience (CSR)","volume":"32 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE International Conference on Cyber Security and Resilience (CSR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSR57506.2023.10224912","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Critical infrastructures and industrial facilities are examples of Cyber-Physical Systems, which are sophisticated systems that integrate physical processes and communication networks. Regrettably, the combination of physical and cyber layers raises the possibility of complications such as a larger surface area for cyberattacks. Due to the unique characteristics of the industrial environment, applying safeguarding architecture similar to that created for the IT sector is not conceivable. Yet, in this study, we exploit the features of industrial communication networks to design the Smart Security Probe, an intrusion detection system for industrial networks. This solution was created to detect potential anomalies in network traffic and to assist in inferring potential anomalies in data connected to physical processes. Smart Security Probe has two operating modes: passive and interactive. When the passive mode is selected, the proposed device analyses the traffic shape in a transparent way, while in the interactive mode it is possible to send packets to allow further analysis and the device is visible in the network. When the interactive mode is activated, a model-based anomaly detection system is included in the suggested approach. Using the Message Queuing Telemetry Transport protocol, the Smart Security Probe can communicate with a remote station to implement an asynchronous Extended Kalman Filter. Smart Security Probe was tested and validated in a system comprised of one Programmable Logic Controller and one Supervisory Control and Data Acquisition system that controls three simulated interconnected tanks.
用智能探测方法增强工业网络物理系统的安全性
关键基础设施和工业设施是信息物理系统的例子,它是集成物理过程和通信网络的复杂系统。令人遗憾的是,物理层和网络层的结合会增加网络攻击表面积等复杂问题的可能性。由于工业环境的独特特征,应用类似于为IT部门创建的保护架构是不可想象的。然而,在本研究中,我们利用工业通信网络的特点来设计智能安全探针,一个工业网络的入侵检测系统。创建此解决方案是为了检测网络流量中的潜在异常,并帮助推断连接到物理进程的数据中的潜在异常。智能安全探测器有被动和交互两种工作模式。当选择被动模式时,建议的设备以透明的方式分析流量形状,而在交互模式下,可以发送数据包以允许进一步分析,并且设备在网络中可见。当交互模式被激活时,建议的方法中包含一个基于模型的异常检测系统。利用消息队列遥测传输协议,智能安全探测器可以与远程站点通信,实现异步扩展卡尔曼滤波。智能安全探测器在一个系统中进行了测试和验证,该系统由一个可编程逻辑控制器和一个监控和数据采集系统组成,该系统控制三个模拟互联坦克。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信