Intrusion Detection in SCADA Systems

Description of research

 

Large industrial facilities, such as water distribution infrastructures, electricity generation plants and oil refineries, need to be continuously monitored and controlled to assure proper functioning. SCADA (Supervisory Control and Data Acquisition) systems are commonly deployed to aid these actions, by automating telemetry and data acquisition. With the goal of reducing costs and increase efficiency, SCADA systems are becoming increasingly more interconnected. However this has also exposed them to a wide range of network security problems.

This Ph.D. project will investigate how to perform intrusion detection based in the observation on network-wide behaviors, by studying flow patterns. Monitoring techniques like Flexible NetFlow/IPFIX will be used as the research is focused in flow analysis, in contrast to deep packet inspection.

Advisor(s)

Dr. ir. Aiko Pras

Prof.dr. ir. Boudewijn Haverkort

Duration

2009-2013

Project

SRO DSN - Dependable Systems and Networks and SRO Istrice Integrated Security and Privacy in a Networked World

Funding institution

CTIT

Strategic Research Orientations

DSN - Dependable Systems and Networks and Istrice - Integrated Security and Privacy in a Networked World

Publications

Links to relevant web pages:

·

http://dacs.ewi.utwente.nl

·

http://www.ctit.utwente.nl/research/sro/dsn/

·

http://www.ctit.utwente.nl/research/sro/istrice/

·

http://wwwhome.cs.utwente.nl/~barbosarr/

Pictures

Rafael Barbosa