Skip to main content
QUICK REVIEW

[논문 리뷰] Putting Together the Pieces: A Concept for Holistic Industrial Intrusion Detection

Simon D. Duque Antón, Hans D. Schotten|arXiv (Cornell University)|2019. 05. 28.
Network Security and Intrusion Detection인용 수 6
한 줄 요약

이 논문은 산업 시스템을 위한 통합된 침입 탐지 프레임워크를 제안하며, 사무실 IT, 공장 현장 OT, 외부 연결망 등 다양한 계층에서 네트워크 및 프로세스 데이터를 통합하여 이질적 이상 탐지 기법을 적용한다. 다양한 공격 단계와 계층에 맞춘 다수의 탐지 기법을 융합함으로써, 산업 4.0 환경에서 고도로 발전한 산업 사이버공격을 조기에 탐지할 수 있음을 입증한다.

ABSTRACT

Besides the advantages derived from the ever present communication properties, it increases the attack surface of a network as well. As industrial protocols and systems were not designed with security in mind, spectacular attacks on industrial systems occurred over the last years. Most industrial communication protocols do not provide means to ensure authentication or encryption. This means attackers with access to a network can read and write information. Originally not meant to be connected to public networks, the use cases of Industry 4.0 require interconnectivity, often through insecure public networks. This lead to an increasing interest in information security products for industrial applications. In this work, the concept for holistic intrusion detection methods in an industrial context is presented. It is based on different works considering several aspects of industrial environments and their capabilities to identify intrusions as an anomaly in network or process data. These capabilities are based on preceding experiments on real and synthetic data. In order to justify the concept, an overview of potential and actual attack vectors and attacks on industrial systems is provided. It is shown that different aspects of industrial facilities, e.g. office IT, shop floor OT, firewalled connections to customers and partners are analysed as well as the different layers of the automation pyramid require different methods to detect attacks. Additionally, the singular steps of an attack on industrial applications are characterised. Finally, a resulting concept for integration of these methods is proposed, providing the means to detect the different stages of an attack by different means.

연구 동기 및 목표

  • 네트워크 상호 연결성 증가와 원천으로 보안이 구비되지 않은 노하우 프로토콜의 증가로 인해 산업 시스템에 대한 사이버공격 위험이 증가하고 있음을 고려하여 대응한다.
  • 특히 OT와 IT 시스템 간의 상호 연결성이 높아지는 환경에서 산업 네트워크를 대상으로 하는 공격 벡터를 식별하고 분석한다.
  • 산업 자동화 피라미드의 여러 계층과 다양한 통신 채널을 아우르는 종합적인 탐지 전략을 개발한다.
  • 초기 접근에서 횡단 이동, 데이터 유출에 이르기까지 공격 전 과정을 커버할 수 있도록 이질적인 탐지 방법을 통합한다.
  • 네트워크 트래픽과 프로세스 동작에서의 이상을 분석함으로써 조기에 정확하게 침입을 탐지할 수 있도록 통합된 프레임워크를 제공한다.

제안 방법

  • 실제 및 합성된 산업 환경 데이터를 분석하여 네트워크 및 프로세스 데이터의 패턴과 이상을 식별한다.
  • 공격 단계(예: 정찰, 공격 실행, 횡단 이동 등)를 분류하고, 각 시스템 계층에 맞는 특정 탐지 기법에 매핑한다.
  • 사무실 IT, 공장 현장 OT, 외부 파artner와의 방화벽 통합 연결 환경 등 각기 다른 환경에 맞춘 탐지 메커니즘을 설계한다.
  • 네트워크 기반 이상 탐지, 프로세스 동작 분석, 프로토콜 전용 모니터링 등의 다수 탐지 방법을 통합하여 유기적인 아키텍처를 구성한다.
  • 현장 장치에서 기업 시스템에 이르기까지의 자동화 피라미드 모델을 활용하여 제어 계층 간의 탐지 구조를 설계한다.
  • 다양한 계층 간 신호를 상호 연계하여 다단계 공격을 탐지할 수 있도록, 계층 기반의 통합 탐지 프레임워크를 제안한다.

실험 결과

연구 질문

  • RQ1산업 자동화 피라미드의 다양한 계층을 커버함으로써 산업 시스템의 침입 탐지 방식을 어떻게 종합적으로 구현할 수 있는가?
  • RQ2레거시 프로토콜을 사용하는 시스템을 대상으로 하는 현대의 산업 사이버공격에서 핵심적인 공격 벡터와 단계는 무엇인가?
  • RQ3네트워크 기반 이상 탐지와 프로세스 기반 이상 탐지를 효과적으로 융합하여 탐지 정확도를 향상시킬 수 있는가?
  • RQ4복잡한 산업 환경에서의 시점 기반 또는 단일 계층 탐지의 한계는 무엇인가?
  • RQ5OT, IT, 외부 파artner 연결 등 다양한 시스템 맥락에 맞춰 탐지 메커니즘을 어떻게 적응시킬 수 있는가?

주요 결과

  • 인증 및 암호화가 없는 레거시 프로토콜로 인해 산업 시스템은 매우 취약하며, 공격자가 데이터를 읽고 수정할 수 있다.
  • 산업 4.0 환경에서의 상호 연결성은 사무실 IT, 공장 현장 OT, 외부 연결망을 모두 공격 대상으로 삼으며, 이에 따라 계층 기반 탐지 전략이 필수적이다.
  • 정찰, 횡단 이동 등 공격 단계에 따라 다른 탐지 기법이 필요하며, 어떤 단일 기법으로도 모든 단계를 커버할 수 없다.
  • 네트워크 및 프로세스 데이터를 다양한 계층에서 통합하는 종합적인 탐지 접근 방식은 고도로 발전한 공격의 조기 탐지 능력을 크게 향상시킨다.
  • 제안된 프레임워크는 각 계층의 기능적 특성과 통신 특성에 맞춰 탐지 논리를 정렬함으로써 이질적인 시스템 간 이상 탐지를 가능하게 한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.