As the main communication mediums in industrial control networks,industrial communication protocols are always vulnerable to extreme exploitations,and it is very difficult to take protective measures due to their seri...As the main communication mediums in industrial control networks,industrial communication protocols are always vulnerable to extreme exploitations,and it is very difficult to take protective measures due to their serious privacy.Based on the SDN(Software Defined Network)technology,this paper proposes a novel event-based anomaly detection approach to identify misbehaviors using non-public industrial communication protocols,and this approach can be installed in SDN switches as a security software appliance in SDN-based control systems.Furthermore,aiming at the unknown protocol specification and message format,this approach first restructures the industrial communication sessions and merges the payloads from industrial communication packets.After that,the feature selection and event sequence extraction can be carried out by using the N-gram model and K-means algorithm.Based on the obtained event sequences,this approach finally trains an event-based HMM(Hidden Markov Model)to identify aberrant industrial communication behaviors.Experimental results clearly show that the proposed approach has obvious advantages of classification accuracy and detection efficiency.展开更多
SHORTLY after Spring Festival in mid-February, as China prepared for its WTO entry, arbitration took place between a non-public owned enterprise in Zhangjiagang, Jiangsu Province, and an American company,
THE non-public economy has played an important role in China’s economic reforms over the past two decades, bringing about great changes to the economy and soci-
IN order to keep to promisesmade during negotiations to jointhe WTO, as from April 1,2002, the Chinese governmentbegan implementing the revised"Catalogue of Industries for ForeignInvestment" and its appendix.
基金This work is supported by the Hainan Provincial Natural Science Foundation of China(618QN219)the National Natural Science Foundation of China(Grant No.61501447)the General Project of Scientific Research of Liaoning Provincial Department of Education(LYB201616).
文摘As the main communication mediums in industrial control networks,industrial communication protocols are always vulnerable to extreme exploitations,and it is very difficult to take protective measures due to their serious privacy.Based on the SDN(Software Defined Network)technology,this paper proposes a novel event-based anomaly detection approach to identify misbehaviors using non-public industrial communication protocols,and this approach can be installed in SDN switches as a security software appliance in SDN-based control systems.Furthermore,aiming at the unknown protocol specification and message format,this approach first restructures the industrial communication sessions and merges the payloads from industrial communication packets.After that,the feature selection and event sequence extraction can be carried out by using the N-gram model and K-means algorithm.Based on the obtained event sequences,this approach finally trains an event-based HMM(Hidden Markov Model)to identify aberrant industrial communication behaviors.Experimental results clearly show that the proposed approach has obvious advantages of classification accuracy and detection efficiency.
文摘SHORTLY after Spring Festival in mid-February, as China prepared for its WTO entry, arbitration took place between a non-public owned enterprise in Zhangjiagang, Jiangsu Province, and an American company,
文摘THE non-public economy has played an important role in China’s economic reforms over the past two decades, bringing about great changes to the economy and soci-
文摘IN order to keep to promisesmade during negotiations to jointhe WTO, as from April 1,2002, the Chinese governmentbegan implementing the revised"Catalogue of Industries for ForeignInvestment" and its appendix.