Reference : Softwarization of SCADA: Lightweight Statistical SDN-Agents for Anomaly Detection
Scientific congresses, symposiums and conference proceedings : Paper published in a book
Engineering, computing & technology : Computer science
Security, Reliability and Trust
http://hdl.handle.net/10993/40162
Softwarization of SCADA: Lightweight Statistical SDN-Agents for Anomaly Detection
English
Rinaldi, Giulia mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Adamsky, Florian mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Soua, Ridha mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Baiocchi, Andrea mailto [University of Roma La Sapienza > the School of Engineering > > Professor]
Engel, Thomas mailto [University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC) >]
4-Oct-2019
10th International Conference on Networks of the Future (NoF)
Yes
International
10th International Conference on Networks of the Future (NoF)
from 01-10-2019 to 03-10-2019
Rome
Italy
[en] SCADA systems ; Security ; SDN ; Anomaly detection ; Agent/probes
[en] The increasing connectivity of restricted areas suchas Critical Infrastructures (CIs) raises major security concernsfor Supervisory Control And Data Acquisition (SCADA) systems,which are deployed to monitor their operation. Given the impor-tance of an early anomaly detection, Intrusion Detection Systems(IDSs) are introduced in SCADA systems to detect malicious ac-tivities as early as possible. Agents or probes form the cornerstoneof any IDS by capturing network packets and extracting relevantinformation. However, IDSs are facing unprecedented challengesdue to the escalation in the number, scale and diversity of attacks.Software-Defined Network (SDN) then comes into play and canprovide the required flexibility and scalability. Building on that,we introduce Traffic Agent Controllers (TACs) that monitor SDN-enabled switches via OpenFlow. By using lightweight statisticalmetrics such as Kullback-Leibler Divergence (KLD), we are ableto detect the slightest anomalies, such as stealth port scans, evenin the presence of background traffic. The obtained metrics canalso be used to locate the anomalies with precision over 90%inside a hierarchical network topology.
Researchers ; Professionals ; Students ; General public
http://hdl.handle.net/10993/40162
H2020 ; 700581 - ATENA - Advanced Tools to assEss and mitigate the criticality of ICT compoNents and their dependencies over Critical InfrAstructures

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
Softwarization_of_SCADA__Lightweight_Statistical_SDN_Agents_for_Anomaly_Detection (2).pdfAuthor preprint273.9 kBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.