SCADvanceXP—an intelligent Polish system for threat detection and monitoring of industrial networks

Mateusz Twardawa, Marek Smolik, F. Rakowski, Jakub Kwiatkowski, Norbert Meyer
{"title":"SCADvanceXP—an intelligent Polish system for threat detection and monitoring of industrial networks","authors":"Mateusz Twardawa, Marek Smolik, F. Rakowski, Jakub Kwiatkowski, Norbert Meyer","doi":"10.35467/sdq/177655","DOIUrl":null,"url":null,"abstract":"SCADvanceXP is an industrial network intrusion detection system that scans and monitors data exchange between engineering\nstations, field divides, controllers, supervisory control and data acquisition (SCADA), and other elements of the operational technology network in detail. SCADvanceXP has the potential to detect advanced attacks on industrial infrastructures with the use of rulebased, signature-based, and behavioural detection methods, which are supported by sophisticated machine and deep learning models. As a system developed in Poland, it addresses the needs of industry in that region of Europe. The goal of this work was to assess SCADvanceXP’s potential to detect common industrial threats. In order to check SCADvanceXP’s potential, an effort was undertaken to evaluate its functionality on major industrial threats. For that purpose, twelve malware strains interfering with industrial systems were described. Later, the SCADvanceXP functionality was overlapped on malware behavioural and detection markers, pointing out exact mechanisms in SCADvanceXP that would detect analysed threats. The results show that SCADvanceXP is able to detect a wide range of attacks on industrial networks. SCADvanceXP’s rich functionality is able to provide a high standard of security. However, if a threat is affecting systems not directly connected with industrial networks, SCADvanceXP will not be able to detect it. SCADvanceXP only monitors industrial systems; hence, corporate networks must be protected by a different solution to provide the required level of security. Nonetheless, SCADvanceXP is dedicated to operating within industrial networks and does not have access to regular IT networks. It can be concluded that SCADvanceXP is a specialist tool providing desired security for industrial networks.","PeriodicalId":52940,"journal":{"name":"Security and Defence Quarterly","volume":"27 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-03-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Security and Defence Quarterly","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.35467/sdq/177655","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

SCADvanceXP is an industrial network intrusion detection system that scans and monitors data exchange between engineering stations, field divides, controllers, supervisory control and data acquisition (SCADA), and other elements of the operational technology network in detail. SCADvanceXP has the potential to detect advanced attacks on industrial infrastructures with the use of rulebased, signature-based, and behavioural detection methods, which are supported by sophisticated machine and deep learning models. As a system developed in Poland, it addresses the needs of industry in that region of Europe. The goal of this work was to assess SCADvanceXP’s potential to detect common industrial threats. In order to check SCADvanceXP’s potential, an effort was undertaken to evaluate its functionality on major industrial threats. For that purpose, twelve malware strains interfering with industrial systems were described. Later, the SCADvanceXP functionality was overlapped on malware behavioural and detection markers, pointing out exact mechanisms in SCADvanceXP that would detect analysed threats. The results show that SCADvanceXP is able to detect a wide range of attacks on industrial networks. SCADvanceXP’s rich functionality is able to provide a high standard of security. However, if a threat is affecting systems not directly connected with industrial networks, SCADvanceXP will not be able to detect it. SCADvanceXP only monitors industrial systems; hence, corporate networks must be protected by a different solution to provide the required level of security. Nonetheless, SCADvanceXP is dedicated to operating within industrial networks and does not have access to regular IT networks. It can be concluded that SCADvanceXP is a specialist tool providing desired security for industrial networks.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
SCADvanceXP - 用于工业网络威胁检测和监控的波兰智能系统
SCADvanceXP 是一种工业网络入侵检测系统,可详细扫描和监控工程站、现场分区、控制器、监控和数据采集 (SCADA) 之间的数据交换,以及操作技术网络的其他元素。SCADvanceXP 可利用基于规则、签名和行为的检测方法,在复杂的机器和深度学习模型的支持下,检测对工业基础设施的高级攻击。作为一个在波兰开发的系统,它能满足欧洲地区的工业需求。这项工作的目标是评估 SCADvanceXP 检测常见工业威胁的潜力。为了检验 SCADvanceXP 的潜力,我们对其针对主要工业威胁的功能进行了评估。为此,描述了 12 种干扰工业系统的恶意软件。随后,将 SCADvanceXP 的功能与恶意软件的行为和检测标记重叠,指出 SCADvanceXP 中检测所分析威胁的确切机制。结果表明,SCADvanceXP 能够检测到对工业网络的各种攻击。SCADvanceXP 的丰富功能能够提供高标准的安全性。但是,如果威胁影响到与工业网络没有直接连接的系统,SCADvanceXP 将无法检测到。SCADvanceXP 只能监控工业系统;因此,企业网络必须由不同的解决方案来保护,以提供所需的安全级别。然而,SCADvanceXP 专门在工业网络内运行,无法访问常规 IT 网络。可以说,SCADvanceXP 是为工业网络提供所需的安全性的专业工具。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
34
审稿时长
9 weeks
期刊最新文献
Role of the private sector within Latvia’s strategic defence documents: Dimensions of psychological resilience and strategic communication Anti-terrorist cooperation as part of Poland’s geopolitical shift. “Operation Bridge” and the rise of a strategic partnership with the United States The role of military morale as an essential dimension of combat power Gender diversity management in NATO for sustainable security and peace SCADvanceXP—an intelligent Polish system for threat detection and monitoring of industrial networks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1