CoToRu: Automatic Generation of Network Intrusion Detection Rules from Code
Heng Chuan Tan, Carmen Cheh, Binbin Chen
摘要
Programmable Logic Controllers (PLCs) are the brains of Industrial Control Systems (ICSes), and thus, are often targeted by attackers. While many intrusion detection systems (IDSes) have been adapted to monitor ICS, they cannot detect malicious network packets from a compromised PLC that con-form to the network protocol. A domain expert needs to manually construct IDS rules to model a PLC’s behavior. That approach is time-consuming and error-prone. Alternatively, machine learning can infer a PLC’s behavior model from network traces, but that model may be inaccurate due to a lack of high-quality training data. This paper presents CoToRu - a toolchain that takes in the PLC’s code to automatically generate a comprehensive set of IDS rules. CoToRu comprises (1) an analyzer that parses PLC code to build a state transition table for modeling the PLC’s behavior, and (2) a generator that instantiates IDS rules for detecting deviations in PLC behavior. The generated rules can be imported into Zeek IDS to detect various attacks. We apply CoToRu to a power grid testbed and show that our generated rules provide superior performance compared to existing IDSes, including those based on statistical analysis, invariant-checking, and machine learning. Our prototype with CoToRu’s generated rules provide sub-millisecond detection latency, even for complex PLC logic.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Watch Me, but Don't Touch Me! Contactless Control Flow Monitoring via Electromagnetic EmanationsYi Han, Sriharsha Etigowni, Hua Liu, Saman A. Zonouz 等CCS 2017 · 被引用 110 次
- A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control SystemsCheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph ChanaNDSS 2019 · 被引用 135 次
- SAIN: Improving ICS Attack Detection Sensitivity via State-Aware InvariantsSyed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan 等USENIX Security 2024 · 被引用 9 次
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 被引用 90 次
- Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical SystemYuqi Chen, Christopher M. Poskitt, Jun SunS&P 2018 · 被引用 135 次
