期刊文献+
共找到3篇文章
< 1 >
每页显示 20 50 100
Event-Based Anomaly Detection for Non-Public Industrial Communication Protocols in SDN-Based Control Systems 被引量:4
1
作者 Ming Wan Jiangyuan Yao +1 位作者 Yuan Jing Xi Jin 《Computers, Materials & Continua》 SCIE EI 2018年第6期447-463,共17页
As the main communication mediums in industrial control networks,industrial communication protocols are always vulnerable to extreme exploitations,and it is very difficult to take protective measures due to their seri... As the main communication mediums in industrial control networks,industrial communication protocols are always vulnerable to extreme exploitations,and it is very difficult to take protective measures due to their serious privacy.Based on the SDN(Software Defined Network)technology,this paper proposes a novel event-based anomaly detection approach to identify misbehaviors using non-public industrial communication protocols,and this approach can be installed in SDN switches as a security software appliance in SDN-based control systems.Furthermore,aiming at the unknown protocol specification and message format,this approach first restructures the industrial communication sessions and merges the payloads from industrial communication packets.After that,the feature selection and event sequence extraction can be carried out by using the N-gram model and K-means algorithm.Based on the obtained event sequences,this approach finally trains an event-based HMM(Hidden Markov Model)to identify aberrant industrial communication behaviors.Experimental results clearly show that the proposed approach has obvious advantages of classification accuracy and detection efficiency. 展开更多
关键词 Event sequence anomaly detection non-public industrial communication protocols SDN
下载PDF
桥接未来--LCCF库函数的应用
2
作者 吴剑铭 张志强 《橡塑技术与装备》 CAS 2025年第1期59-65,共7页
本文探讨了Siemens的LCCF库函数在工业自动化项目中的应用,LCCF库提供了一种软件层面的解决方案,通过库函数替代传统硬件协议网关,实现不同通信协议间的数据交换。介绍了Siemens库函数的分类与功能,阐述了LCCF库的主要组件及其在协议转... 本文探讨了Siemens的LCCF库函数在工业自动化项目中的应用,LCCF库提供了一种软件层面的解决方案,通过库函数替代传统硬件协议网关,实现不同通信协议间的数据交换。介绍了Siemens库函数的分类与功能,阐述了LCCF库的主要组件及其在协议转换中的优势,包括简化配置流程、增强系统兼容性、降低技术门槛等。通过具体的应用实例,展示了LCCF库在SIMATIC控制器与Rockwell及Mitsubishi控制器之间通信的实现方法。此外,文章还对LCom与LCCF两个Siemens通信库进行了比较分析,指出了它们的共同点与不同点。 展开更多
关键词 LCCF 协议网关 数据交换CIP(Common industrial protocol) MELSEC Communication protocol(MC协议)
下载PDF
ICPFuzzer:proprietary communication protocol fuzzing by using machine learning and feedback strategies 被引量:3
3
作者 Pei-Yi Lin Chia-Wei Tien +1 位作者 Ting-Chun Huang Chin-Wei Tien 《Cybersecurity》 EI CSCD 2021年第1期427-441,共15页
The fuzzing test is able to discover various vulnerabilities and has more chances to hit the zero-day targets.And ICS(Industrial control system)is currently facing huge security threats and requires security standards... The fuzzing test is able to discover various vulnerabilities and has more chances to hit the zero-day targets.And ICS(Industrial control system)is currently facing huge security threats and requires security standards,like ISO 62443,to ensure the quality of the device.However,some industrial proprietary communication protocols can be customized and have complicated structures,the fuzzing system cannot quickly generate test data that adapt to various protocols.It also struggles to define the mutation field without having prior knowledge of the protocols.Therefore,we propose a fuzzing system named ICPFuzzer that uses LSTM(Long short-term memory)to learn the features of a protocol and generates mutated test data automatically.We also use the responses of testing and adjust the weight strategies to further test the device under testing(DUT)to find more data that cause unusual connection status.We verified the effectiveness of the approach by comparing with the open-source and commercial fuzzers.Furthermore,in a real case,we experimented with the DLMS/COSEM for a smart meter and found that the test data can cause a unusual response.In summary,ICPFuzzer is a black-box fuzzing system that can automatically execute the testing process and reveal vulnerabilities that interrupt and crash industrial control communication.Not only improves the quality of ICS but also improves safety. 展开更多
关键词 industrial communication protocol Network protocol fuzzing Long short-term memory(LSTM) industrial control system(ICS)
原文传递
上一页 1 下一页 到第
使用帮助 返回顶部