USENIX Security2016Top-tier venue
Specification Mining for Intrusion Detection in Networked Control Systems
Marco Caselli, Emmanuele Zambon, Johanna Amann, Robin Sommer, Frank Kargl
Abstract
This paper discusses a novel approach to specificationbased intrusion detection in the field of networked control systems. Our approach reduces the substantial human effort required to deploy a specification-based intrusion detection system by automating the development of its specification rules. We observe that networked control systems often include comprehensive documentation used by operators to manage their infrastructures. Our approach leverages the same documentation to automatically derive the specification rules and continuously monitor network traffic. In this paper, we implement this approach for BACnet-based building automation systems and test its effectiveness against two real infrastructures deployed at the University of Twente and the Lawrence Berkeley National Laboratory (LBNL). Our implementation successfully identifies process control mistakes and potentially dangerous misconfigurations. This confirms the need for an improved monitoring of networked control system infrastructures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cfb6e0ea-6a2f-412b-b587-4ce586fd3148Cited by top-tier papers4
- Understanding and Securing Device Vulnerabilities through Automated Bug Report AnalysisXuan Feng, Xiaojing Liao, XiaoFeng Wang, Haining Wang et al.USENIX Security 2019 · 46 citations
- Retina: analyzing 100GbE traffic on commodity hardwareGerry Wan, Fengchen Gong, Tom Barbette, Zakir DurumericSIGCOMM 2022 · 14 citations
- BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnetQiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang et al.NDSS 2026
- A Cuckoo in the Nest: Multi‑Stage, Multi‑Identifier Hijacking in BACnet/SCQiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang et al.USENIX Security 2026
Related papers
- Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingYue Zhang, Zhen Ling, Michael Cash, Qiguang Zhang et al.CCS 2024 · 3 citations
- Alert Alchemy: SOC Workflows and Decisions in the Management of NIDS RulesMathew Vermeer, Natalia Kadenko, Michel van Eeten, Carlos Gañán et al.CCS 2023 · 16 citations
- Internet-scale Probing of CPS: Inference, Characterization and Orchestration AnalysisClaude Fachkha, Elias Bou-Harb, Anastasis Keliris, Nasir D. Memon et al.NDSS 2017 · 81 citations
- From Intention to Practice: Towards Systematic Validation of NIDS Rule EnforcementHuan Liu, Haoyu Chen, Biang Xu, Jingyao Zhou et al.NSDI 2026
- GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion DetectionKonrad Wolsing, Eric Wagner, Luisa Lux, Klaus Wehrle et al.USENIX Security 2025
