用于可定制和高效入侵检测的iec61850 MMS流量解析器

Heng Chuan Tan, V. Mohanraj, Binbin Chen, D. Mashima, Shing Kham Shing Nan, Aobo Yang
{"title":"用于可定制和高效入侵检测的iec61850 MMS流量解析器","authors":"Heng Chuan Tan, V. Mohanraj, Binbin Chen, D. Mashima, Shing Kham Shing Nan, Aobo Yang","doi":"10.1109/SmartGridComm51999.2021.9632304","DOIUrl":null,"url":null,"abstract":"Manufacturing Message Specification (MMS) protocol is widely used in IEC 61850-based substations to improve process automation. However, it could be vulnerable to various cyber threats. A common defense solution is to deploy intrusion detection systems (IDSes) to analyze network traffic for anomalies. However, several challenges remain for designing a protocol parser for IDS to dissect MMS packets, such as the need to support many MMS services and the complex data structure. Moreover, processing every MMS packet may overwhelm the IDS to impact the throughput and latency. In this work, we develop an MMS parser for the open-source Zeek IDS to analyze MMS traffic and detect intrusions. We explain the challenges of parsing MMS packets and detail our design choices. To reduce the processing load, we implement filtering rules in our parser to customize which MMS packets are used by Zeek rules for intrusion analysis. We formulated test cases to validate our parser's correctness and conducted experiments to evaluate its throughput and latency. Our results show that custom filtering of MMS packets can achieve higher throughput and lower delay compared to no filtering. We provide a case study to demonstrate how the parsed data can be used for designing IDS rules.","PeriodicalId":378884,"journal":{"name":"2021 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm)","volume":"5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"An IEC 61850 MMS Traffic Parser for Customizable and Efficient Intrusion Detection\",\"authors\":\"Heng Chuan Tan, V. Mohanraj, Binbin Chen, D. Mashima, Shing Kham Shing Nan, Aobo Yang\",\"doi\":\"10.1109/SmartGridComm51999.2021.9632304\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Manufacturing Message Specification (MMS) protocol is widely used in IEC 61850-based substations to improve process automation. However, it could be vulnerable to various cyber threats. A common defense solution is to deploy intrusion detection systems (IDSes) to analyze network traffic for anomalies. However, several challenges remain for designing a protocol parser for IDS to dissect MMS packets, such as the need to support many MMS services and the complex data structure. Moreover, processing every MMS packet may overwhelm the IDS to impact the throughput and latency. In this work, we develop an MMS parser for the open-source Zeek IDS to analyze MMS traffic and detect intrusions. We explain the challenges of parsing MMS packets and detail our design choices. To reduce the processing load, we implement filtering rules in our parser to customize which MMS packets are used by Zeek rules for intrusion analysis. We formulated test cases to validate our parser's correctness and conducted experiments to evaluate its throughput and latency. Our results show that custom filtering of MMS packets can achieve higher throughput and lower delay compared to no filtering. We provide a case study to demonstrate how the parsed data can be used for designing IDS rules.\",\"PeriodicalId\":378884,\"journal\":{\"name\":\"2021 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm)\",\"volume\":\"5 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-10-25\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SmartGridComm51999.2021.9632304\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SmartGridComm51999.2021.9632304","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

制造消息规范(MMS)协议广泛应用于基于IEC 61850的变电站,以提高过程自动化程度。然而,它可能容易受到各种网络威胁。常见的防御方案是部署入侵检测系统(ids),对网络流量进行异常分析。然而,为IDS设计协议解析器来解析MMS数据包仍然存在一些挑战,例如需要支持许多MMS服务和复杂的数据结构。此外,处理每个MMS数据包可能会使IDS不堪重负,从而影响吞吐量和延迟。在这项工作中,我们为开源的Zeek IDS开发了一个彩信解析器,用于分析彩信流量并检测入侵。我们解释了解析MMS数据包的挑战,并详细介绍了我们的设计选择。为了减少处理负载,我们在解析器中实现过滤规则,以自定义哪些MMS数据包被Zeek规则用于入侵分析。我们制定了测试用例来验证解析器的正确性,并进行了实验来评估其吞吐量和延迟。研究结果表明,自定义MMS包过滤比不过滤可以实现更高的吞吐量和更低的延迟。我们提供了一个案例研究来演示如何将解析后的数据用于设计IDS规则。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An IEC 61850 MMS Traffic Parser for Customizable and Efficient Intrusion Detection
Manufacturing Message Specification (MMS) protocol is widely used in IEC 61850-based substations to improve process automation. However, it could be vulnerable to various cyber threats. A common defense solution is to deploy intrusion detection systems (IDSes) to analyze network traffic for anomalies. However, several challenges remain for designing a protocol parser for IDS to dissect MMS packets, such as the need to support many MMS services and the complex data structure. Moreover, processing every MMS packet may overwhelm the IDS to impact the throughput and latency. In this work, we develop an MMS parser for the open-source Zeek IDS to analyze MMS traffic and detect intrusions. We explain the challenges of parsing MMS packets and detail our design choices. To reduce the processing load, we implement filtering rules in our parser to customize which MMS packets are used by Zeek rules for intrusion analysis. We formulated test cases to validate our parser's correctness and conducted experiments to evaluate its throughput and latency. Our results show that custom filtering of MMS packets can achieve higher throughput and lower delay compared to no filtering. We provide a case study to demonstrate how the parsed data can be used for designing IDS rules.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Low-complexity Risk-averse MPC for EMS Modeling framework for study of distributed and centralized smart grid system services Data-Driven Frequency Regulation Reserve Prediction Based on Deep Learning Approach Data Communication Interfaces in Smart Grid Real-time Simulations: Challenges and Solutions Modeling of Cyber Attacks Against Converter-Driven Stability of PMSG-Based Wind Farms with Intentional Subsynchronous Resonance
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1