Visible to the public Modbus Communication Behavior Modeling and SVM Intrusion Detection Method

TitleModbus Communication Behavior Modeling and SVM Intrusion Detection Method
Publication TypeConference Paper
Year of Publication2016
AuthorsShang, Wenli, Cui, Junrong, Wan, Ming, An, Panfeng, Zeng, Peng
Conference NameProceedings of the 6th International Conference on Communication and Network Security
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4783-9
Keywordscomposability, feature extraction, Industrial control network, Intrusion detection, Metrics, Modbus/TCP, network intrusion detection, pubcrawl, Resiliency, SVM
Abstract

The security and typical attack behavior of Modbus/TCP industrial network communication protocol are analyzed. The data feature of traffic flow is extracted through the operation mode of the depth analysis abnormal behavior, and the intrusion detection method based on the support vector machine (SVM) is designed. The method analyzes the data characteristics of abnormal communication behavior, and constructs the feature input structure and detection system based on SVM algorithm by using the direct behavior feature selection and abnormal behavior pattern feature construction. The experimental results show that the method can effectively improve the detection rate of abnormal behavior, and enhance the safety protection function of industrial network.

URLhttp://doi.acm.org/10.1145/3017971.3017978
DOI10.1145/3017971.3017978
Citation Keyshang_modbus_2016