(2018) International Symposium for ICS & SCADA Cyber Security Research 2018, ICS-CSR 2018 — Location: University of Hamburg, Hamburg, Germany (29.August.2018)
The increasing number of attacks against Industrial Control Systems (ICS) have shown the vulnerability of these systems. Many ICS network protocols have no security mechanism and the requirements on high availability and real-time communication make it challenging to apply intrusive security measures. In this paper, we propose a two-level intrusion detection system for ICS networks based on Software Defined Networking (SDN). The first level consists of flow and Modbus whitelists, leveraging P4 for efficient real- time monitoring. The second level is a deep packet inspector communicating with a SDN controller to update the whitelist of the first level. We show by experiments in an emulated environment that our design has only a small impact on communication latencies in the ICS and is efficient against Modbus/TCP oriented attacks.
Kabasele Ndonda, G., & Sadre, R. (2018). A Two-level Intrusion Detection System for Industrial Control System Networks using P4. ICS-CSR 2018. Accepted/in-press. International Symposium for ICS & SCADA Cyber Security Research 2018, ICS-CSR 2018, University of Hamburg, Hamburg, Germany. https://hdl.handle.net/2078.5/256057