2018
DOI: 10.14236/ewic/ics2018.4
|View full text |Cite
|
Sign up to set email alerts
|

A Two-level Intrusion Detection System for Industrial Control System Networks using P4

Abstract: The increasing number of attacks against Industrial Control Systems (ICS) have shown the vulnerability of these systems. Many ICS network protocols have no security mechanism and the requirements on high availability and real-time communication make it challenging to apply intrusive security measures. In this paper, we propose a two-level intrusion detection system for ICS networks based on Software Defined Networking (SDN). The first level consists of flow and Modbus whitelists, leveraging P4 for efficient re… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
6
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
7
1
1

Relationship

0
9

Authors

Journals

citations
Cited by 23 publications
(8 citation statements)
references
References 17 publications
0
6
0
Order By: Relevance
“…Modbus/TCP oriented attack is a major type of control system intrusion. Ndona and Sadre [143] proposed a two-level intrusion detection system to efficient against Modbus/TCP oriented attacks with a small impact on communication latency. In [144], a new intrusion detection algorithm based on oneclass SVM was presented with advantages of fast and strong generalization ability, less support vector, simple mode, and great practical value.…”
Section: Discussionmentioning
confidence: 99%
“…Modbus/TCP oriented attack is a major type of control system intrusion. Ndona and Sadre [143] proposed a two-level intrusion detection system to efficient against Modbus/TCP oriented attacks with a small impact on communication latency. In [144], a new intrusion detection algorithm based on oneclass SVM was presented with advantages of fast and strong generalization ability, less support vector, simple mode, and great practical value.…”
Section: Discussionmentioning
confidence: 99%
“…Furthermore, Scholz et al [212,213] presented a scheme that defends against SYN flood attacks. Ndonda et al [214] implemented an intrusion detection system in P4 that whitelists and filters Modbus protocol packets in industrial control systems.…”
Section: ) Backgroundmentioning
confidence: 99%
“…Their solution blocks users based on packet rate. Ndonda and Sadre [18] take the capabilities of P4 a step further, proposing a two-level Intrusion Detection System (IDS), which implements a flow and Modbus whitelist by leveraging P4, which is updated by a packet inspection application located at the SDN controller.…”
Section: A Data Plane Programming Solutionsmentioning
confidence: 99%