首页> 外文期刊>IEEE transactions on industrial informatics >Autonomic Intelligent Cyber-Sensor to Support Industrial Control Network Awareness
【24h】

Autonomic Intelligent Cyber-Sensor to Support Industrial Control Network Awareness

机译:支持工业控制网络意识的自主智能网络传感器

获取原文
获取原文并翻译 | 示例
           

摘要

The proliferation of digital devices in a networked industrial ecosystem, along with an exponential growth in complexity and scope, has resulted in elevated security concerns and management complexity issues. This paper describes a novel architecture utilizing concepts of autonomic computing and a simple object access protocol (SOAP)-based interface to metadata access points (IF-MAP) external communication layer to create a network security sensor. This approach simplifies integration of legacy software and supports a secure, scalable, and self-managed framework. The contribution of this paper is twofold: 1) A flexible two-level communication layer based on autonomic computing and service oriented architecture is detailed and 2) three complementary modules that dynamically reconfigure in response to a changing environment are presented. One module utilizes clustering and fuzzy logic to monitor traffic for abnormal behavior. Another module passively monitors network traffic and deploys deceptive virtual network hosts. These components of the sensor system were implemented in C++ and PERL and utilize a common internal D-Bus communication mechanism. A proof of concept prototype was deployed on a mixed-use test network showing the possible real-world applicability. In testing, 45 of the 46 network attached devices were recognized and 10 of the 12 emulated devices were created with specific operating system and port configurations. In addition, the anomaly detection algorithm achieved a 99.9% recognition rate. All output from the modules were correctly distributed using the common communication structure.
机译:在联网的工业生态系统中,数字设备的激增以及复杂性和范围的指数级增长,导致了越来越多的安全问题和管理复杂性问题。本文介绍了一种利用自主计算概念和基于简单对象访问协议(SOAP)的元数据访问点(IF-MAP)外部通信层接口创建网络安全传感器的新颖体系结构。这种方法简化了旧版软件的集成,并支持安全,可伸缩和自我管理的框架。本文的贡献是双重的:1)详细介绍了基于自主计算和面向服务的体系结构的灵活的两层通信层,以及2)提出了三个互补模块,这些模块可根据环境的变化而动态地进行重新配置。一个模块利用聚类和模糊逻辑来监视流量中的异常行为。另一个模块被动地监视网络流量并部署欺骗性的虚拟网络主机。传感器系统的这些组件是用C ++和PERL实现的,并利用了通用的内部D-Bus通信机制。概念验证原型已部署在混合使用的测试网络上,显示了现实中的可能适用性。在测试中,识别出46个网络连接设备中的45个,并使用特定的操作系统和端口配置创建了12个仿真设备中的10个。此外,异常检测算法的识别率达到了99.9%。使用公共通信结构正确分配了模块的所有输出。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号