Network Monitoring on Industrial Control Systems
Alvaro Cardenas, PhD. David I Urbina, PhD. candidate
Network Monitoring on Industrial Control Systems Alvaro Cardenas, - - PowerPoint PPT Presentation
Network Monitoring on Industrial Control Systems Alvaro Cardenas, PhD. David I Urbina, PhD. candidate Introduction of NSM Long term goals Current Research ICS T raffjc Analysis Intrusion Detection Some T ools for NSM
Alvaro Cardenas, PhD. David I Urbina, PhD. candidate
1/13/15 2
– ICS T
– Intrusion Detection
1/13/15 3
1/13/15 4
Network Security Monitoring in ICS
1/13/15 5
1/13/15 6
1/13/15 7
1/13/15 8
IP
Modbus/TCP
Ethernet 2 / 802.3
Data Data TCP Data Data Modbus Data Link Network Transport Application
1/13/15 9
Modbus/TCP
1/13/15 10
1/13/15 11
1/13/15 12
1/13/15 13
T1 T2
Law Abiding “Behavior”
B B B A A A
1/13/15 14
Physical Model
1/13/15 15
1/13/15 16
distribution for NSM.
– Deep Packet Inspection – Protocol Analysis – Traffjc Analysis – Intrusion Detection and Prevention
1/13/15 17
– Standalone – Server-sensor
1/13/15 18
– Full packet capture → netsnifg-ng (http://netsnifg-ng.com) – Network-based IDS
– Host-based IDS
– Analysis T
1/13/15 19
1/13/15 20
1/13/15 21
–
Best Paper Award, "On the Practicality of Detecting Anomalies with Encrypted T raffjc in AMI", IEEE SmartGridComm, 2014.
1/13/15 22