2017/11/07 by Thomas Marsden, Marsden, Thomas, Nour Moustafa +5
Computer Science · Engineering · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Network Security and Intrusion Detection #Smart Grid Security and Resilience
paper · pdf · doi:10.48550/arxiv.1711.02826
openalex publication_date 2017/11/07 · openalex created_date 2022/10/05 · openalex updated_date 2026/07/28
. As Supervisory Control and Data Acquisition (SCADA) systems control several\ncritical infrastructures, they have connected to the internet. Consequently,\nSCADA systems face different sophisticated types of cyber adversaries. This\npaper suggests a Probability Risk Identification based Intrusion Detection\nSystem (PRI-IDS) technique based on analysing network traffic of Modbus TCP/IP\nfor identifying replay attacks. It is acknowledged that Modbus TCP is usually\nvulnerable due to its unauthenticated and unencrypted nature. Our technique is\nevaluated using a simulation environment by configuring a testbed, which is a\ncus- tom SCADA network that is cheap, accurate and scalable. The testbed is\nexploited when testing the IDS by sending individual packets from an attacker\nlocated on the same LAN as the Modbus master and slave. The experimental\nresults demonstrated that the proposed technique can effectively and\nefficiently recognise replay attacks.\n