Netinfo Security ›› 2016, Vol. 16 ›› Issue (7): 61-70.doi: 10.3969/j.issn.1671-1122.2016.07.010

• Orginal Article • Previous Articles     Next Articles

Security Supervisory Scheme for Industrial Control Networks

Xiaobing CHEN1,2, Kai CHEN1, Zhen XU1, Liming WANG1   

  1. 1. State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences,Beijing 100093, China
    2. University of Chinese Academy of Sciences, Beijing 100049, China
  • Received:2016-01-15 Online:2016-07-20 Published:2020-05-13

Abstract:

Security events, represented by one nuclear power station of Iran attacked by the “Stuxnet” virus, ring the alarm bell of the industrial control system security situation. The supervision of industrial control system is imperative. Considering the state-of-the-art research, there exists the problems of restraint of the range of data acquisition, the inadequate consideration of the features of industrial control systems and lack of effective detection measures to identify APT attacks, such as “Stuxnet” and “Havex”. Thus, the article propose a supervisory frame for industrial control networks. The frame acquire data from different layers of industrial control networks, utilizing flexible data acquisition strategies, and correlate data acquired from different layers of industrial control networks and analyze abnormal operation behavior. The flexible data acquisition strategies perform preference to the availability of industrial control system, while the correlation and analysis of data acquired from different layers improved the ability of the system to detect some APT attacks.

Key words: security supervision, flexible data acquisition, correlation of security data

CLC Number: