IIoT (Industrial Internet-of-Things) systems are getting more prone to attacks by APT (Advanced Persistent Threat) adversaries. Past APT attacks on IIoT systems such as the 2016 Ukrainian power grid attack which cut off the capital Kyiv off power for an hour and the 2017 Saudi petrochemical plant attack which almost shut down the plant's safety controllers have shown that APT campaigns can disrupt industrial processes, shut down critical systems and endanger human lives. In this work, we propose RAPTOR, a system to detect APT campaigns in IIoT environments. RAPTOR detects and correlates various APT attack stages (adapted to IIoT) using multiple data sources. Subsequently, it constructs a high-level APT campaign graph which can be used by cybersecurity analysts towards attack analysis and mitigation. A performance evaluation of RAPTOR's APT stage detection stages shows high precision and low false positive/negative rates. We also show that RAPTOR is able to construct the APT campaign graph for APT attacks (modelled after real-world attacks on ICS/OT infrastructure) executed on our IIoT testbed.
翻译:工业物联网(IIoT)系统正日益面临高级持续性威胁(APT)攻击者的风险。过去针对IIoT系统的APT攻击事件——例如2016年乌克兰电网攻击导致首都基辅断电一小时,以及2017年沙特石化厂攻击险些使该厂安全控制器瘫痪——表明APT行动能够扰乱工业流程、关闭关键系统并危及人类生命。本研究中,我们提出RAPTOR系统,用于检测IIoT环境中的APT攻击行动。RAPTOR利用多源数据检测并关联(经IIoT适配的)各类APT攻击阶段,进而构建高级APT攻击图,以供网络安全分析师用于攻击分析与缓解。针对RAPTOR各APT阶段检测模块的性能评估显示,该系统具有高精度与低误报/漏报率。我们还证明,RAPTOR能够为在IIoT测试平台上执行的(基于现实ICS/OT基础设施攻击建模的)APT攻击构建相应的APT攻击图。