CoToRu: Automatic Generation of Network Intrusion Detection Rules from Code
Heng Chuan Tan, Carmen Cheh, Binbin Chen
Abstract
Programmable Logic Controllers (PLCs) are the brains of Industrial Control Systems (ICSes), and thus, are often targeted by attackers. While many intrusion detection systems (IDSes) have been adapted to monitor ICS, they cannot detect malicious network packets from a compromised PLC that con-form to the network protocol. A domain expert needs to manually construct IDS rules to model a PLC’s behavior. That approach is time-consuming and error-prone. Alternatively, machine learning can infer a PLC’s behavior model from network traces, but that model may be inaccurate due to a lack of high-quality training data. This paper presents CoToRu - a toolchain that takes in the PLC’s code to automatically generate a comprehensive set of IDS rules. CoToRu comprises (1) an analyzer that parses PLC code to build a state transition table for modeling the PLC’s behavior, and (2) a generator that instantiates IDS rules for detecting deviations in PLC behavior. The generated rules can be imported into Zeek IDS to detect various attacks. We apply CoToRu to a power grid testbed and show that our generated rules provide superior performance compared to existing IDSes, including those based on statistical analysis, invariant-checking, and machine learning. Our prototype with CoToRu’s generated rules provide sub-millisecond detection latency, even for complex PLC logic.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Watch Me, but Don't Touch Me! Contactless Control Flow Monitoring via Electromagnetic EmanationsYi Han, Sriharsha Etigowni, Hua Liu, Saman A. Zonouz et al.CCS 2017 · 110 citations
- A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control SystemsCheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph ChanaNDSS 2019 · 135 citations
- SAIN: Improving ICS Attack Detection Sensitivity via State-Aware InvariantsSyed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan et al.USENIX Security 2024 · 9 citations
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 90 citations
- Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical SystemYuqi Chen, Christopher M. Poskitt, Jun SunS&P 2018 · 135 citations
