Cargando…
A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks
Supervisory and Data Acquisition (SCADA) systems control and monitor modern power networks. As attacks targeting SCADA systems are increasing, significant research is conducted to defend SCADA networks including variations of anomaly detection. Due to the sensitivity of real data, many defence mecha...
Autores principales: | , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
2021
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7888297/ http://dx.doi.org/10.1007/978-3-030-69781-5_14 |
_version_ | 1783652133132828672 |
---|---|
author | Lin, C.-Y. Nadjm-Tehrani, Simin |
author_facet | Lin, C.-Y. Nadjm-Tehrani, Simin |
author_sort | Lin, C.-Y. |
collection | PubMed |
description | Supervisory and Data Acquisition (SCADA) systems control and monitor modern power networks. As attacks targeting SCADA systems are increasing, significant research is conducted to defend SCADA networks including variations of anomaly detection. Due to the sensitivity of real data, many defence mechanisms have been tested only in small testbeds or emulated traffic that were designed with assumptions on how SCADA systems behave. This work provides a timing characterization of IEC-104 spontaneous traffic and compares the results from emulated traffic and real traffic to verify if the network characteristics appearing in testbeds and emulated traffic coincide with real traffic. Among three verified characteristics, two of them appear in the real dataset but in a less regular way, and one does not appear in the collected real data. The insights from these observations are discussed in terms of presumed differences between emulated and real traffic and how those differences are generated. |
format | Online Article Text |
id | pubmed-7888297 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2021 |
record_format | MEDLINE/PubMed |
spelling | pubmed-78882972021-02-17 A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks Lin, C.-Y. Nadjm-Tehrani, Simin Cyber-Physical Security for Critical Infrastructures Protection Article Supervisory and Data Acquisition (SCADA) systems control and monitor modern power networks. As attacks targeting SCADA systems are increasing, significant research is conducted to defend SCADA networks including variations of anomaly detection. Due to the sensitivity of real data, many defence mechanisms have been tested only in small testbeds or emulated traffic that were designed with assumptions on how SCADA systems behave. This work provides a timing characterization of IEC-104 spontaneous traffic and compares the results from emulated traffic and real traffic to verify if the network characteristics appearing in testbeds and emulated traffic coincide with real traffic. Among three verified characteristics, two of them appear in the real dataset but in a less regular way, and one does not appear in the collected real data. The insights from these observations are discussed in terms of presumed differences between emulated and real traffic and how those differences are generated. 2021-01-28 /pmc/articles/PMC7888297/ http://dx.doi.org/10.1007/978-3-030-69781-5_14 Text en © The Author(s) 2021 Open Access This chapter is licensed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license and indicate if changes were made. The images or other third party material in this chapter are included in the chapter's Creative Commons license, unless indicated otherwise in a credit line to the material. If material is not included in the chapter's Creative Commons license and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. |
spellingShingle | Article Lin, C.-Y. Nadjm-Tehrani, Simin A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks |
title | A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks |
title_full | A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks |
title_fullStr | A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks |
title_full_unstemmed | A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks |
title_short | A Comparative Analysis of Emulated and Real IEC-104 Spontaneous Traffic in Power System Networks |
title_sort | comparative analysis of emulated and real iec-104 spontaneous traffic in power system networks |
topic | Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7888297/ http://dx.doi.org/10.1007/978-3-030-69781-5_14 |
work_keys_str_mv | AT lincy acomparativeanalysisofemulatedandrealiec104spontaneoustrafficinpowersystemnetworks AT nadjmtehranisimin acomparativeanalysisofemulatedandrealiec104spontaneoustrafficinpowersystemnetworks AT lincy comparativeanalysisofemulatedandrealiec104spontaneoustrafficinpowersystemnetworks AT nadjmtehranisimin comparativeanalysisofemulatedandrealiec104spontaneoustrafficinpowersystemnetworks |