Skip to main content
QUICK REVIEW

[论文解读] Modern Problems Require Modern Solutions: Hybrid Concepts for Industrial Intrusion Detection

Simon D. Duque Antón, Mathias Strufe|arXiv (Cornell University)|May 15, 2019
Network Security and Intrusion Detection参考文献 29被引用 4
一句话总结

本文提出了一种用于工业4.0工业环境的混合入侵检测框架,结合使用矩阵轮廓(Matrix Profiles)对网络流量和过程数据进行时间序列分析,以检测异常。该方法可在无需专家安全知识的情况下,实现对中小型企业(SMEs)中网络物理攻击的早期检测,通过真实世界仿真和工业数据分析,有效识别通信模式和过程行为的偏离。

ABSTRACT

The concept of Industry 4.0 brings a disruption into the processing industry. It is characterised by a high degree of intercommunication, embedded computation, resulting in a decentralised and distributed handling of data. Additionally, cloud-storage and Software-as-a-Service (SaaS) approaches enhance a centralised storage and handling of data. This often takes place in third-party networks. Furthermore, Industry 4.0 is driven by novel business cases. Lot sizes of one, customer individual production, observation of process state and progress in real-time and remote maintenance, just to name a few. All of these new business cases make use of the novel technologies. However, cyber security has not been an issue in industry. Industrial networks have been considered physically separated from public networks. Additionally, the high level of uniqueness of any industrial network was said to prevent attackers from exploiting flaws. Those assumptions are inherently broken by the concept of Industry 4.0. As a result, an abundance of attack vectors is created. In the past, attackers have used those attack vectors in spectacular fashions. Especially Small and Mediumsized Enterprises (SMEs) in Germany struggle to adapt to these challenges. Reasons are the cost required for technical solutions and security professionals. In order to enable SMEs to cope with the growing threat in the cyberspace, the research project IUNO Insec aims at providing and improving security solutions that can be used without specialised security knowledge. The project IUNO Insec is briefly introduced in this work. Furthermore, contributions in the field of intrusion detection, especially machine learning-based solutions, for industrial environments provided by the authors are presented and set into context.

研究动机与目标

  • 应对德国中小企业因工业4.0应用而日益严峻的网络安全挑战,其中传统安全假设已不再适用。
  • 通过开发适用于非专家且可扩展至小型企业的安全解决方案,克服传统工业系统的局限性。
  • 在IUNO项目的基础上,通过机器学习和异常检测技术,推进工业IT与OT网络入侵检测工具的发展。
  • 集成上下文感知的检测机制,以提升在分段工业网络中横向移动攻击的检测能力。
  • 通过轻量级、易于部署的安全模块,使中小企业能够安全参与工业4.0。

提出的方法

  • 应用矩阵轮廓——一种时间序列分析技术——通过计算固定长度子序列之间的最小距离,检测网络流量中的异常。
  • 使用数据包级别数据(如源/目标IP、端口、数据包数量)生成时间序列以供分析,识别表明攻击的偏离行为。
  • 利用真实工业硬件(如水箱系统)建模工业过程行为,模拟正常与异常运行状态,例如加速回流。
  • 关联网络流量和过程数据中的异常,检测IT与OT层级之间协同发起的攻击。
  • 实施基于上下文的聚合模型,关联跨网络段的攻击源、目标和影响。
  • 利用蜜罐和混淆等欺骗技术,增强检测能力并延缓攻击者推进。

实验结果

研究问题

  • RQ1如何调整异常检测技术,以在工业网络中实现极低误报率的网络物理攻击检测?
  • RQ2对网络和过程数据进行时间序列分析,在多大程度上可提升工业系统中横向移动的早期检测能力?
  • RQ3上下文聚合在提升混合IT/OT环境中入侵检测的准确性与可靠性方面发挥何种作用?
  • RQ4如何使基于机器学习的检测方法在不牺牲安全有效性的前提下,便于中小企业非专家使用?
  • RQ5结合网络层与过程层分析的混合检测方法,是否在工业环境中优于孤立的检测方法?

主要发现

  • 矩阵轮廓成功检测到工业网络流量中的异常,在攻击阶段最小距离显著增加,表明行为偏离正常模式。
  • 在模拟过程数据中,将回流速率加倍导致矩阵轮廓最小距离出现明显且持续的上升,证实了过程层异常的可检测性。
  • 网络层与过程层时间序列分析的结合,实现了对同时影响通信模式和物理系统行为的协同攻击的检测。
  • 该方法在真实工业硬件中验证了可行性,展示了在多种攻击场景下的一致异常检测能力。
  • 通过针对攻击引发的偏离行为进行调优的基于阈值的检测机制,混合检测模型降低了误报率。
  • 上下文感知聚合的集成提升了攻击溯源能力,并增强了跨网络区域的横向移动检测能力。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。