首页> 外文会议>IEEE Conference on Communications and Network Security >Modeling Modbus TCP for intrusion detection
【24h】

Modeling Modbus TCP for intrusion detection

机译:为入侵检测建模Modbus TCP

获取原文

摘要

DFAs (Deterministic Finite Automata) and DTMCs (Discrete Time Markov Chain) have been proposed for modeling Modbus/TCP for intrusion detection in SCADA (Supervisory Control and Data Acquisition) systems. While these models can be used to learn the behavior of the system, they require the designer to know the appropriate amount of training data for building the model, to retrain models when configuration changes, and to generate understandable alert messages. In this paper, we propose to complement these learned models with the specification approaches. To build a robust model, we need to consider configuration-level specifications in addition to protocol specification. As Modbus/TCP is a simple protocol with handful function code(s) or commands for each communication channel, designing a specification-based approach is suitable for monitoring this communication. We do a comparison of DFA and DTMC approaches in two datasets and illustrate how to use our inferred specification to complement these models.
机译:已经提出使用DFA(确定性有限自动机)和DTMC(离散时间马尔可夫链)来为Modbus / TCP建模,以在SCADA(监控和数据采集)系统中进行入侵检测。虽然可以使用这些模型来学习系统的行为,但它们要求设计人员知道适当数量的训练数据以构建模型,在配置更改时重新训练模型并生成可理解的警报消息。在本文中,我们建议使用规范方法对这些学习的模型进行补充。为了构建健壮的模型,除了协议规范外,我们还需要考虑配置级规范。由于Modbus / TCP是一个简单的协议,具有用于每个通信通道的少量功能代码或命令,因此设计基于规范的方法适用于监视此通信。我们在两个数据集中比较了DFA和DTMC方法,并说明了如何使用推断的规范来补充这些模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号