LAPSE:2023.15453
Published Article
LAPSE:2023.15453
Anomaly Detection in Cyclic Communication in OT Protocols
Milosz Smolarczyk, Sebastian Plamowski, Jakub Pawluk, Krzysztof Szczypiorski
March 2, 2023
This paper demonstrates the effectiveness of using anomaly detection in cyclic communication as a method aimed at protecting industrial installations from steganographic communication and a wide range of cyberattacks. The analysis was performed for a method based on deterministic finite automaton and the authors’ method using cycles. In this paper, we discuss the cycle detection algorithm and graph construction as well as demonstrate an anomaly detection method for cyberattack detection that utilizes stochastic elements, such as time-to-response and time-between-messages. We present a novel algorithm that combines finite automaton determinism modeling consecutive admissible messages with a time-domain model allowing for random deviations of regularity. The study was conducted for several test scenarios, including C&C steganographic channels generated using the Modbus TCP/IP protocol. Experimental results demonstrating the effectiveness of the algorithms are presented for both methods. All algorithms described in this paper are implemented and run as part of a passive warden system embedded in a bigger commercial IDS (intrusion detection system).
Keywords
cybersecurity, cyclic communication, deterministic finite automaton, Modbus TCP/IP, steganography
Suggested Citation
Smolarczyk M, Plamowski S, Pawluk J, Szczypiorski K. Anomaly Detection in Cyclic Communication in OT Protocols. (2023). LAPSE:2023.15453
Author Affiliations
Smolarczyk M: Research & Development Department, Cryptomage SA, 50-556 Wrocław, Poland
Plamowski S: Institute of Control and Computation Engineering, Warsaw University of Technology, 00-661 Warsaw, Poland
Pawluk J: Research & Development Department, Cryptomage SA, 50-556 Wrocław, Poland
Szczypiorski K: Research & Development Department, Cryptomage SA, 50-556 Wrocław, Poland; Institute of Telecommunications, Warsaw University of Technology, 00-661 Warsaw, Poland [ORCID]
Journal Name
Energies
Volume
15
Issue
4
First Page
1517
Year
2022
Publication Date
2022-02-18
Published Version
ISSN
1996-1073
Version Comments
Original Submission
Other Meta
PII: en15041517, Publication Type: Journal Article
Record Map
Published Article

LAPSE:2023.15453
This Record
External Link

doi:10.3390/en15041517
Publisher Version
Download
Files
[Download 1v1.pdf] (2.4 MB)
Mar 2, 2023
Main Article
License
CC BY 4.0
Meta
Record Statistics
Record Views
73
Version History
[v1] (Original Submission)
Mar 2, 2023
 
Verified by curator on
Mar 2, 2023
This Version Number
v1
Citations
Most Recent
This Version
URL Here
https://psecommunity.org/LAPSE:2023.15453
 
Original Submitter
Auto Uploader for LAPSE
Links to Related Works
Directly Related to This Work
Publisher Version