Specification Mining for Intrusion Detection in Networked Control Systems
Marco Caselli, Emmanuele Zambon, Johanna Amann, Robin Sommer, Frank Kargl
摘要
This paper discusses a novel approach to specificationbased intrusion detection in the field of networked control systems. Our approach reduces the substantial human effort required to deploy a specification-based intrusion detection system by automating the development of its specification rules. We observe that networked control systems often include comprehensive documentation used by operators to manage their infrastructures. Our approach leverages the same documentation to automatically derive the specification rules and continuously monitor network traffic. In this paper, we implement this approach for BACnet-based building automation systems and test its effectiveness against two real infrastructures deployed at the University of Twente and the Lawrence Berkeley National Laboratory (LBNL). Our implementation successfully identifies process control mistakes and potentially dangerous misconfigurations. This confirms the need for an improved monitoring of networked control system infrastructures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Understanding and Securing Device Vulnerabilities through Automated Bug Report AnalysisXuan Feng, Xiaojing Liao, XiaoFeng Wang, Haining Wang 等USENIX Security 2019 · 被引用 46 次
- Retina: analyzing 100GbE traffic on commodity hardwareGerry Wan, Fengchen Gong, Tom Barbette, Zakir DurumericSIGCOMM 2022 · 被引用 14 次
- BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnetQiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang 等NDSS 2026
- A Cuckoo in the Nest: Multi‑Stage, Multi‑Identifier Hijacking in BACnet/SCQiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang 等USENIX Security 2026
相关 Paper
- Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingYue Zhang, Zhen Ling, Michael Cash, Qiguang Zhang 等CCS 2024 · 被引用 3 次
- Alert Alchemy: SOC Workflows and Decisions in the Management of NIDS RulesMathew Vermeer, Natalia Kadenko, Michel van Eeten, Carlos Gañán 等CCS 2023 · 被引用 16 次
- Internet-scale Probing of CPS: Inference, Characterization and Orchestration AnalysisClaude Fachkha, Elias Bou-Harb, Anastasis Keliris, Nasir D. Memon 等NDSS 2017 · 被引用 81 次
- From Intention to Practice: Towards Systematic Validation of NIDS Rule EnforcementHuan Liu, Haoyu Chen, Biang Xu, Jingyao Zhou 等NSDI 2026
- GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion DetectionKonrad Wolsing, Eric Wagner, Luisa Lux, Klaus Wehrle 等USENIX Security 2025
