Skip to main content
SHARE
Publication

Assessing Anomaly-Based Intrusion Detection Configurations for Industrial Control Systems...

by Robert E Gillen, Jason M Carter, Christopher A Craig, Jordan A Johnson, Stephen Scott
Publication Type
Conference Paper
Book Title
2020 IEEE 21st International Symposium on "A World of Wireless, Mobile and Multimedia Networks" (WoWMoM)
Publication Date
Page Numbers
360 to 366
Conference Name
6th IEEE International workshop on Communication Computing and Networking in Cyber Physical Systems
Conference Location
Cork, Ireland
Conference Sponsor
IEEE
Conference Date
-

To reduce cost and ease maintenance, industrial control systems (ICS) have adopted Ethernetbased interconnections that integrate operational technology (OT) systems with information technology (IT) networks. This integration has made these critical systems vulnerable to attack. Security solutions tailored to ICS environments are an active area of research. Anomalybased network intrusion detection systems are well-suited for these environments. Often these systems must be optimized for their specific environment. In prior work, we introduced a method for assessing the impact of various anomaly-based network IDS settings on security. This paper reviews the experimental outcomes when we applied our method to a full-scale ICS test bed using actual attacks. Our method provides new and valuable data to operators enabling more informed decisions about IDS configurations.