vix.ing · top · new · best · stats · spec

Critical Infrastructure Protection: having SIEM technology cope with network heterogeneity

2014/04/30 by Gianfranco Cerullo, Cerullo, Gianfranco, Valerio Formicola +5
Computer Science · Engineering · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Full-Duplex Wireless Communications #Power Line Communications and Noise #Smart Grid Security and Resilience #cs.CR

paper · pdf · doi:10.48550/arxiv.1404.7563

EDCC-2014, BIG4CIP-2014, Critical Infrastructure Protection, Intrusion Detection and Diagnosis, Complex Event Processing , Security Information and Event Management (SIEM)

arxiv created 2014/04/30 · openalex publication_date 2014/04/30 · arxiv updated 2014/05/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Coordinated and targeted cyber-attacks to Critical Infrastructures (CIs) are becoming more and more frequent and sophisticated. This is due to: i) the recent technology shift towards Commercial Off-The-Shelf (COTS) products, and ii) new economical and socio-political motivations. In this paper, we discuss some of the most relevant security issues resulting from the adoption in CIs of heterogeneous network infrastructures (specifically combining wireless and IP trunks), and suggest techniques to detect, as well as to counter/mitigate attacks. We claim that techniques such as those we propose here should be integrated in future SIEM (Security Information and Event Management) solutions, and we discuss how we have done so in the EC-funded MASSIF project, with respect to a real-world CI scenario, specifically a distributed system for power grid monitoring.

Related