TY - GEN
T1 - A Reflection-based Channel-State Group Fingerprint to Detect Intrusion Devices in ICS
AU - Meng, Long
AU - Wang, Xiangming
AU - Qiu, Shenjian
AU - Liu, Pengfei
AU - Deng, Nanyi
AU - Liu, Yang
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024
Y1 - 2024
N2 - As the underlying network of the industrial control system (ICS), the fieldbus network can prevent attacks from the network. However, attackers can bypass physical defenses and physically connect intrusion devices to the fieldbus network to carry out various attacks. Many existing methods focus on detecting active intrusion devices by extracting their signal characteristics, but they struggle to detect inactive intrusion devices that are performing eavesdropping attacks without sending signals. This paper proposes a reflection-based channel-state group fingerprint to detect inactive intrusion devices. We theoretically analyze the reflection signals generated by the access of the intrusion device and observe that these reflection signals impact the signals of benign devices. Based on this, we extract the signal from a benign device before the intrusion and utilize it as a channel-state fingerprint. We detect inactive intrusion devices by analyzing the channel-state differences before and after intrusion. Additionally, we combine the channel-state fingerprints of multiple groups of devices to improve detection performance. The experimental results show that our method outperforms 99% in all detection metrics when detecting inactive intrusion devices.
AB - As the underlying network of the industrial control system (ICS), the fieldbus network can prevent attacks from the network. However, attackers can bypass physical defenses and physically connect intrusion devices to the fieldbus network to carry out various attacks. Many existing methods focus on detecting active intrusion devices by extracting their signal characteristics, but they struggle to detect inactive intrusion devices that are performing eavesdropping attacks without sending signals. This paper proposes a reflection-based channel-state group fingerprint to detect inactive intrusion devices. We theoretically analyze the reflection signals generated by the access of the intrusion device and observe that these reflection signals impact the signals of benign devices. Based on this, we extract the signal from a benign device before the intrusion and utilize it as a channel-state fingerprint. We detect inactive intrusion devices by analyzing the channel-state differences before and after intrusion. Additionally, we combine the channel-state fingerprints of multiple groups of devices to improve detection performance. The experimental results show that our method outperforms 99% in all detection metrics when detecting inactive intrusion devices.
KW - Industrial Control System Security
KW - Intrusion Device Detection
KW - Signal Reflection
UR - https://www.scopus.com/pages/publications/85213401408
U2 - 10.1109/ICNSC62968.2024.10760168
DO - 10.1109/ICNSC62968.2024.10760168
M3 - 会议稿件
AN - SCOPUS:85213401408
T3 - ICNSC 2024 - 21st International Conference on Networking, Sensing and Control: Artificial Intelligence for the Next Industrial Revolution
BT - ICNSC 2024 - 21st International Conference on Networking, Sensing and Control
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 21st International Conference on Networking, Sensing and Control, ICNSC 2024
Y2 - 18 October 2024 through 20 October 2024
ER -