从真实水厂数据挖掘超十万条攻击模式,发现工业控制系统隐藏威胁
Attack Pattern Mining to Discover Hidden Threats to Industrial Control Systems
- 基于实际运行数据生成攻击模式,避免人工假设偏差
- 在真实水厂数据中挖掘出超过10万条攻击路径
- 适合工控安全研究人员和防御系统设计者参考
本研究聚焦于工业控制系统(ICS)安全中的攻击模式挖掘验证。全面评估ICS安全需生成大量且多样化的攻击模式。为此,我们提出一种数据驱动方法,从实际运行的水处理厂采集的数据中生成攻击模式。该方法成功生成了超过10万条攻击模式,并通过详细案例研究对其有效性进行了验证,揭示了传统方法难以发现的潜在威胁。
原文摘要 · Abstract (English)
This work focuses on validation of attack pattern mining in the context of Industrial Control System (ICS) security. A comprehensive security assessment of an ICS requires generating a large and variety of attack patterns. For this purpose we have proposed a data driven technique to generate attack patterns for an ICS. The proposed technique has been used to generate over 100,000 attack patterns from data gathered from an operational water treatment plant. In this work we present a detailed case study to validate the attack patterns.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。