Past attacks against industrial control systems (ICS) show that adversaries often target both the ICS network and the physical process to achieve potential catastrophic impact. To secure ICS, intrusion detection systems promise timely uncovering of such adversaries. However, as these detection mechanisms typically focus on isolated characteristics of ICS (e.g., packet timings), multiple detection systems have to be deployed in parallel, complicating their operation in practice. In this work, to spur discussion and further research, we present challenges encountered during our research towards a holistic intrusion detection system aiming to cover all dimensions of an ICS.
翻译:过去针对工业控制系统的攻击表明,攻击者通常同时针对ICS网络和物理过程,以造成潜在的灾难性影响。为确保ICS安全,入侵检测系统有望及时发现此类攻击者。然而,由于这些检测机制通常专注于ICS的孤立特征(例如数据包时序),实际应用中不得不并行部署多个检测系统,从而增加了操作复杂性。本文旨在促进讨论与进一步研究,我们提出了在研究面向覆盖ICS所有维度的整体入侵检测系统过程中所遇到的挑战。