EDMAND: Edge-Based Multi-Level Anomaly Detection for SCADA Networks
Title | EDMAND: Edge-Based Multi-Level Anomaly Detection for SCADA Networks |
Publication Type | Conference Paper |
Year of Publication | 2018 |
Authors | Ren, W., Yardley, T., Nahrstedt, K. |
Conference Name | 2018 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm) |
Date Published | Oct. 2018 |
Publisher | IEEE |
ISBN Number | 978-1-5386-7954-8 |
Keywords | anomaly detection, appropriate anomaly detection methods, composability, Detectors, edge detection, edge-based multilevel anomaly detection, EDMAND, event detection, Image edge detection, large-scale distributed industrial systems, malicious attacks, Metrics, Monitoring, network traffic data, network-based intrusion detection, Protocols, pubcrawl, resilience, Resiliency, SCADA network traffic, SCADA systems, Scalability, security, security of data, supervisory control and data acquisition systems, telecommunication traffic |
Abstract | Supervisory Control and Data Acquisition (SCADA) systems play a critical role in the operation of large-scale distributed industrial systems. There are many vulnerabilities in SCADA systems and inadvertent events or malicious attacks from outside as well as inside could lead to catastrophic consequences. Network-based intrusion detection is a preferred approach to provide security analysis for SCADA systems due to its less intrusive nature. Data in SCADA network traffic can be generally divided into transport, operation, and content levels. Most existing solutions only focus on monitoring and event detection of one or two levels of data, which is not enough to detect and reason about attacks in all three levels. In this paper, we develop a novel edge-based multi-level anomaly detection framework for SCADA networks named EDMAND. EDMAND monitors all three levels of network traffic data and applies appropriate anomaly detection methods based on the distinct characteristics of data. Alerts are generated, aggregated, prioritized before sent back to control centers. A prototype of the framework is built to evaluate the detection ability and time overhead of it. |
URL | https://ieeexplore.ieee.org/document/8587533 |
DOI | 10.1109/SmartGridComm.2018.8587533 |
Citation Key | ren_edmand:_2018 |
- network traffic data
- telecommunication traffic
- supervisory control and data acquisition systems
- security of data
- security
- Scalability
- SCADA systems
- SCADA network traffic
- Resiliency
- resilience
- pubcrawl
- Protocols
- network-based intrusion detection
- Anomaly Detection
- Monitoring
- Metrics
- malicious attacks
- large-scale distributed industrial systems
- Image edge detection
- event detection
- EDMAND
- edge-based multilevel anomaly detection
- edge detection
- Detectors
- composability
- appropriate anomaly detection methods