Authors:
Abdullah Al Balushi
;
Kieran McLaughlin
and
Sakir Sezer
Affiliation:
Queens University Belfast, United Kingdom
Keyword(s):
Semantic Web, Intrusion Detection, Knowledge Engineering, SCADA, Modbus TCP, Security Ontology.
Related
Ontology
Subjects/Areas/Topics:
Critical Infrastructure Protection
;
Data and Application Security and Privacy
;
Information and Systems Security
;
Intrusion Detection & Prevention
;
Network Security
;
Security Engineering
;
Security in Information Systems
;
Security Information Systems Architecture and Design and Security Patterns
;
Security Management
;
Security Protocols
;
Wireless Network Security
Abstract:
This paper presents the design, development, and validation of an ontology based SCADA intrusion detection
system. The proposed system analyses SCADA network communications and can derive additional information
based on the background knowledge and ontology models to enhance the intrusion detection data.
The developed intrusion model captures network communications, cyber attacks and the context within the
SCADA domain. Moreover, a set of semantic rules were constructed to detect various attacks and extract logical
relationships among these attacks. The presented framework was extensively evaluated and a comparison
to the state of the art is provided.