Industrial Control System Fingerprinting and Anomaly Detection [chapter]

Yong Peng, Chong Xiang, Haihui Gao, Dongqing Chen, Wang Ren
2015 IFIP Advances in Information and Communication Technology  
Industrial control systems are cyber-physical systems that supervise and control physical processes in critical infrastructures such as electric grids, water and wastewater treatment plants, oil and natural gas pipelines, transportation systems and chemical plants and refineries. Leveraging the stable and persistent control flow communications patterns in industrial control systems, this chapter proposes an innovative control system fingerprinting methodology that analyzes industrial control
more » ... tocols to capture normal behavior characteristics. The methodology can be used to identify specific physical processes and control system components in industrial facilities and detect abnormal behavior. An experimental testbed that incorporates real systems for the cyber domain and simulated systems for the physical domain is used to validate the methodology. The experimental results demonstrate that the fingerprinting methodology holds promise for detecting anomalies in industrial control systems and cyber-physical systems used in the critical infrastructure.
doi:10.1007/978-3-319-26567-4_5 fatcat:zuc7b4hapbfgtmbahym7kxeudy