Intrusion Detection System for IEC 60870-5-104 based SCADA networks

Yi Yang, Kieran McLaughlin, Tim Littler, Sakir Sezer, Bernardi Pranggono, Haifeng Wang

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    Abstract

    Increased complexity and interconnectivity of Supervisory Control and Data Acquisition (SCADA) systems in Smart Grids potentially means greater susceptibility to malicious attackers. SCADA systems with legacy communication infrastructure have inherent cyber-security vulnerabilities as these systems were originally designed with little consideration of cyber threats. In order to improve cyber-security of SCADA networks, this paper presents a rule-based Intrusion Detection System (IDS) using a Deep Packet Inspection (DPI) method, which includes signature-based and model-based approaches tailored for SCADA systems. The proposed signature-based rules can accurately detect several known suspicious or malicious attacks. In addition, model-based detection is proposed as a complementary method to detect unknown attacks. Finally, proposed intrusion detection approaches for SCADA networks are implemented and verified via Snort rules.
    Original languageEnglish
    Title of host publicationIEEE Power & Energy Society General Meeting (PESGM) 2013
    PublisherIEEE
    Volume2013
    ISBN (Electronic)9781479913039
    ISBN (Print) 97814799130202
    DOIs
    Publication statusPublished - 21 Jul 2013

    Keywords

    • SCADA
    • intrusion detector system
    • cyber-security
    • IEC 60870-5-104

    Fingerprint Dive into the research topics of 'Intrusion Detection System for IEC 60870-5-104 based SCADA networks'. Together they form a unique fingerprint.

  • Cite this

    Yang, Y., McLaughlin, K., Littler, T., Sezer, S., Pranggono, B., & Wang, H. (2013). Intrusion Detection System for IEC 60870-5-104 based SCADA networks. In IEEE Power & Energy Society General Meeting (PESGM) 2013 (Vol. 2013). IEEE. https://doi.org/10.1109/PESMG.2013.6672100