<p>SCADA (Supervisory Control and Data Acquisition) systems have become more common and complex with the digitization of industrial control systems. In particular, the integration of IoT (Internet of Things) devices has led to new security vulnerabilities. In these systems used in critical infrastructures, beaconing attacks, which take the form of periodic and covert communication, can negatively affect system performance and lead to more serious threats. In this study, a statistical and machine learning-based model is proposed to detect beaconing attacks and abnormal traffic behavior in IoT-based SCADA systems. The proposed model analyzes network traffic logs collected using the Zeek network monitoring tool, utilizing statistical features that include the Coefficient of Variation (CV) of time intervals and average connection duration. Anomaly detection is performed using the Isolation Forest algorithm with an unsupervised learning approach. The developed model achieves high accuracy rates with low resource consumption. The model is particularly suitable for SCADA environments with limited energy and processing power. When integrated with real-time monitoring, strong authentication, and encrypted communication protocols, the proposed approach significantly increases the security level of SCADA systems. This work will make an important contribution to the literature in terms of developing early warning and preventive intervention capabilities against cyber attacks targeting critical infrastructure.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A new method for detecting beaconing attacks in IoT-based scada systems

  • Ferdi Doğan,
  • Onur Polat,
  • Fahri Yardimci

摘要

SCADA (Supervisory Control and Data Acquisition) systems have become more common and complex with the digitization of industrial control systems. In particular, the integration of IoT (Internet of Things) devices has led to new security vulnerabilities. In these systems used in critical infrastructures, beaconing attacks, which take the form of periodic and covert communication, can negatively affect system performance and lead to more serious threats. In this study, a statistical and machine learning-based model is proposed to detect beaconing attacks and abnormal traffic behavior in IoT-based SCADA systems. The proposed model analyzes network traffic logs collected using the Zeek network monitoring tool, utilizing statistical features that include the Coefficient of Variation (CV) of time intervals and average connection duration. Anomaly detection is performed using the Isolation Forest algorithm with an unsupervised learning approach. The developed model achieves high accuracy rates with low resource consumption. The model is particularly suitable for SCADA environments with limited energy and processing power. When integrated with real-time monitoring, strong authentication, and encrypted communication protocols, the proposed approach significantly increases the security level of SCADA systems. This work will make an important contribution to the literature in terms of developing early warning and preventive intervention capabilities against cyber attacks targeting critical infrastructure.