Thèse de doctorat (Mémoires et thèses)
Risk Monitoring and Intrusion Detection for Industrial Control Systems
MULLER, Steve
2018
 

Documents


Texte intégral
Risk Monitoring and Intrusion Detection for Industrial Control Systems.pdf
Postprint Auteur (3.35 MB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
real-time risk management; risk monitoring; dependency modelling; industrial control systems; intrusion detection
Résumé :
[en] Cyber-attacks on critical infrastructure such as electricity, gas, and water distribution, or power plants, are more and more considered to be a relevant and realistic threat to the European society. Whereas mature solutions like anti-malware applications, intrusion detection systems (IDS) and even intrusion prevention or self-healing systems have been designed for classic computer systems, these techniques have only been partially adapted to the world of Industrial Control Systems (ICS). As a consequence, organisations and nations fall back upon risk management to understand the risks that they are facing. Today's trend is to combine risk management with real-time monitoring to enable prompt reactions in case of attacks. This thesis aims at providing techniques that assist security managers in migrating from a static risk analysis to a real-time and dynamic risk monitoring platform. Risk monitoring encompasses three steps, each being addressed in detail in this thesis: the collection of risk-related information, the reporting of security events, and finally the inclusion of this real-time information into a risk analysis. The first step consists in designing agents that detect incidents in the system. In this thesis, an intrusion detection system is developed to this end, which focuses on an advanced persistent threat (APT) that particularly targets critical infrastructures. The second step copes with the translation of the obtained technical information in more abstract notions of risk, which can then be used in the context of a risk analysis. In the final step, the information collected from the various sources is correlated so as to obtain the risk faced by the entire system. Since industrial environments are characterised by many interdependencies, a dependency model is elaborated which takes dependencies into account when the risk is estimated.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
MULLER, Steve ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Langue du document :
Anglais
Titre :
Risk Monitoring and Intrusion Detection for Industrial Control Systems
Date de soutenance :
26 juin 2018
Nombre de pages :
xvi, 134 + 24
Institution :
Unilu - University of Luxembourg, Luxembourg
Intitulé du diplôme :
Docteur de l’Université du Luxembourg en Informatique
Promoteur :
LE TRAON, Yves 
Bonnin, Jean-Marie
Président du jury :
Membre du jury :
Ludinard, Romaric
Viet Triem Tong, Valérie
Flaus, Jean-Marie
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR10239425 - Risk Monitoring With Intrusion Detection For Industrial Control Systems, 2015 (01/07/2015-30/06/2018) - Steve Muller
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 19 juillet 2018

Statistiques


Nombre de vues
340 (dont 12 Unilu)
Nombre de téléchargements
495 (dont 9 Unilu)

Bibliographie


Publications similaires



Contacter ORBilu