信息网络安全 ›› 2017, Vol. 17 ›› Issue (7): 45-51.doi: 10.3969/j.issn.1671-1122.2017.07.007

• • 上一篇    下一篇

基于规则匹配的分布式工控入侵检测系统设计与实现

程冬梅1, 严彪2,3, 文辉3(), 孙利民2,3   

  1. 1.中国人民解放军第305医院信息中心,北京 100017
    2.中国科学院大学,北京 100049
    3.中国科学院信息工程研究所,北京 100093
  • 收稿日期:2017-05-15 出版日期:2017-07-20 发布日期:2020-05-12
  • 作者简介:

    作者简介: 程冬梅(1964—),女,北京,高级工程师,主要研究方向为信息处理、物联网安全、工业控制系统安全;严彪(1992—),男,湖北,硕士研究生,主要研究方向为物联网安全、工业控制系统安全;文辉(1986—),男,北京,助理研究员,博士,主要研究方向为物联网安全、工业控制系统安全、数据挖掘;孙利民(1966—),男,北京,研究员,博士,主要研究方向为物联网安全、工业控制系统安全、无线传感网。

  • 基金资助:
    国家重点研发计划[2016YFC1202204];中国科学院国防科技创新基金项目[CXJJ-16Z234];北京市科委项目[Z161100002616032];高动态导航技术北京市重点实验室开放课题[HDN2017102]

The Design and Implement of Rule Matching-based Distributed Intrusion Detection Framework for Industry Control System

Dongmei CHENG1, Biao YAN2,3, Hui WEN3(), Limin SUN2,3   

  1. 1. Information Center of the 305 Hospital of Chinese People’s Liberation Army, Beijing 100017, China;
    2. University of Chinese Academy of Sciences, Beijing 100049, China
    3. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
  • Received:2017-05-15 Online:2017-07-20 Published:2020-05-12

摘要:

文章设计了一种基于规则匹配的分布式入侵检测系统(RDIDS),提出了基于规则匹配的入侵检测策略,通过定义网络连接白名单来检测未经授权的非法访问连接,自主分析流量特征并学习相应的判别规则来检测异常的流量变化,提取常态状态下的工控操作功能码序列组成操作规则来判断异常的工控操作,实现对工控系统在网络流量、协议内容、设备操作、设备状态和外部物理感知的全面监测。文章利用各种类型的工控软硬件设备搭建小型工控网络,并在此仿真环境下进行验证及测试,证明RDIDS系统架构及方法具备显著的检测性能。

关键词: 工业控制系统, 入侵检测系统, 分布式系统, 规则匹配

Abstract:

This paper proposed a rule-based distributed intrusion detection system (RDIDS) framework to reduce the impact of traditional industrial control system problems. Furthermore, RDIDS construct a set of rules that contains network status, traffic and industrial operation for intrusion detection. The network status rules that defined by operator can detect unauthorized access for protecting the safety of physical system from information disclosure. The traffic rules learned from the analysis of traffic characteristics can detect abnormal network data flow. The industrial operation rules extracted from the industrial operating sequence can detect abnormal industrial operation. Finally, an industrial control system was built for validation, which contains several hardware or software. The experimental results that conduct on the simulation of industrial control system show that our system have a considerable performance.

Key words: industrial control system, intrusion detection system, distributed system, rule matching

中图分类号: