Enhancing SCADA Security: Developing a Host-Based Intrusion Detection System to Safeguard Against Cyberattacks (2402.14599v1)
Abstract: With the increasing reliance of smart grids on correctly functioning SCADA systems and their vulnerability to cyberattacks, there is a pressing need for effective security measures. SCADA systems are prone to cyberattacks, posing risks to critical infrastructure. As there is a lack of host-based intrusion detection systems specifically designed for the stable nature of SCADA systems, the objective of this work is to propose a host-based intrusion detection system tailored for SCADA systems in smart grids. The proposed system utilizes USB device identification, flagging, and process memory scanning to monitor and detect anomalies in SCADA systems, providing enhanced security measures. Evaluation in three different scenarios demonstrates the tool's effectiveness in detecting and disabling malware. The proposed approach effectively identifies potential threats and enhances the security of SCADA systems in smart grids, providing a promising solution to protect against cyberattacks.
- B. Babayigit et al., “Industrial internet of things: A review of improvements over traditional scada systems for industrial automation,” IEEE Systems Journal, 2023.
- A. Dehlaghi-Ghadim et al., “Icssim—a framework for building industrial control systems security testbeds,” Computers in Industry, vol. 148, p. 103906, 2023.
- I. A. Khan et al., “Enhancing iiot networks protection: A robust security model for attack detection in internet industrial control systems,” Ad Hoc Networks, 2022.
- S. P. Wang et al., “Security by design: Defense-in-depth iot architecture,” in Journal of The Colloquium for Information Systems Security Education, vol. 4, no. 2, 2017, pp. 15–15.
- A. Abou el Kalam, “Securing scada and critical industrial systems: From needs to security mechanisms,” IJoCIP, 2021.
- M. Alanazi et al., “Scada vulnerabilities and attacks: A review of the state-of-the-art and open issues,” Computers & Security, vol. 125, p. 103028, 2023.
- D. van der Velde et al., “Methods for actors in the electric power system to prevent, detect and react to ict attacks and failures,” in ENERGYCon, 2020.
- M. Alanazi et al., “Scada vulnerabilities and attacks: A review of the state-of-the-art and open issues,” Computers & Security, 2022.
- J. L. Rrushi, “Physics-driven page fault handling for customized deception against cps malware,” TECS, 2022.