Network-Based Real-Time Detection of Data Manipulation Attacks in Industrial Control Systems
摘要
The increasing connectivity of Industrial Control Systems (ICS) has heightened their exposure to sophisticated data manipulation attacks that exploit vulnerabilities in communication protocols such as EtherNet/IP (ENIP), MODBUS, and DNP3. Existing intrusion detection solutions often rely on abstract traffic features or reactive detection strategies, limiting their effectiveness in preventing real-time disruptions. This paper presents a protocol-aware network intrusion detection system (PA-NIDS) for real-time detection of malicious ENIP traffic targeting controllers. By leveraging contextual information within protocol communications, the proposed system enables early identification of attacker intent before physical impact. The framework was deployed on the operational Secure Water Treatment (SWaT) testbed and evaluated under single-point and coordinated multi-point attack scenarios. Experimental results show that PA-NIDS achieves 100% detection accuracy with zero false positives and an average detection latency below five seconds, providing proactive and interpretable protection for ICS environments.