Ming Wan1, Jiangyuan Yao2,*, Yuan Jing1, Xi Jin3,4
CMC-Computers, Materials & Continua, Vol.55, No.3, pp. 447-463, 2018, DOI:10.3970/cmc.2018.02195
Abstract As the main communication mediums in industrial control networks, industrial communication protocols are always vulnerable to extreme exploitations, and it is very difficult to take protective measures due to their serious privacy. Based on the SDN (Software Defined Network) technology, this paper proposes a novel event-based anomaly detection approach to identify misbehaviors using non-public industrial communication protocols, and this approach can be installed in SDN switches as a security software appliance in SDN-based control systems. Furthermore, aiming at the unknown protocol specification and message format, this approach first restructures the industrial communication sessions and merges More >