IIoT (Industrial Internet-of-Things) systems are getting more prone to attacks by APT (Advanced Persistent Threat) adversaries. Past APT attacks on IIoT systems such as the 2016 Ukrainian power grid attack which cut off the capital Kyiv off power for an hour and the 2017 Saudi petrochemical plant attack which almost shut down the plant's safety controllers have shown that APT campaigns can disrupt industrial processes, shut down critical systems and endanger human lives. In this work, we propose RAPTOR, a system to detect APT campaigns in IIoT environments. RAPTOR detects and correlates various APT attack stages (adapted to IIoT) using multiple data sources. Subsequently, it constructs a high-level APT campaign graph which can be used by cybersecurity analysts towards attack analysis and mitigation. A performance evaluation of RAPTOR's APT stage detection stages shows high precision and low false positive/negative rates. We also show that RAPTOR is able to construct the APT campaign graph for APT attacks (modelled after real-world attacks on ICS/OT infrastructure) executed on our IIoT testbed.
翻译:IIoT(工业物联网)系统日益容易受到APT(高级持续性威胁)攻击者的攻击。过去针对IIoT系统的APT攻击事件,例如2016年乌克兰电网攻击(导致首都基辅断电一小时)和2017年沙特石化厂攻击(几乎导致工厂安全控制器停运),表明APT活动能够破坏工业流程、关停关键系统并危及人类生命。本文提出了RAPTOR系统,用于检测IIoT环境中的APT活动。RAPTOR利用多种数据源,检测并关联(经IIoT适配的)各类APT攻击阶段,进而构建高层次的APT攻击活动图,供网络安全分析人员用于攻击分析和缓解。对RAPTOR各APT阶段检测模块的性能评估表明,其具有高精度和低误报/漏报率。我们还证明,RAPTOR能够针对在IIoT测试平台上执行的APT攻击(根据对ICS/OT基础设施的真实攻击建模)构建APT攻击活动图。