Qr code
CN
姚羽

Professor

Supervisor of Doctorate Candidates

Supervisor of Master's Candidates


E-Mail:

Administrative Position:复杂网络系统安全保障技术教育部工程研究中心主任

Education Level:With Certificate of Graduation for Doctorate Study

Gender:Male

Contact Information:yaoyu@mail.neu.edu.cn

Degree:博士

Alma Mater:东北大学

Discipline:Computer Applications Technology
Computer Software and Theory
Computer Architecture

Academic Honor:

2013   Excellent talents of the Ministry of education in the new century

Click:Times

The Last Update Time: ..

Current position: Home >> Scientific Research >> Paper Publications
A Cyber-Physical Model for SCADA System and Its Intrusion Detection

Hits:

Journal:Computer Networks.

Impact Factor:5.493

Abstract:Supervisory Control and Data Acquisition (SCADA) systems are becoming increasingly susceptible to the sophisticated and targeted cyber attacks which are typically carried out by exploiting the vulnerabilities of industrial control devices or protocols. However, most of the existing network intrusion detection methods only focus on detecting and characterizing cyber attacks against the SCADA system, but cannot fully describe their real impact on the system. In this paper, we propose a cyber-physical model for the SCADA system to detect intrusions from the SCADA network and evaluate their risk levels against the industrial process. The model aims at characterizing the network structure and industrial process of the SCADA system through extracting and correlating the communication patterns and states of ICS devices. And any violation of the model is considered abnormal behavior, which can be caused by false operation or network attacks. Through associating network intrusions with the status of the SCADA system, a risk assessment method is proposed to estimate the potential damage degree of the attack on the system, which provides network administrators with richer information about network attacks. Moreover, the comprehensive performance evaluation conducted on public SCADA network data sets shows that the proposed method outperforms the existing methods in detecting and analyzing various cyber attacks against the SCADA system.

Note:https://www.sciencedirect.com/science/article/abs/pii/S1389128620312883

Document Type:JCR 一区

Translation or Not:no