<p>The increasing connectivity of Industrial Control Systems (ICS) has heightened their exposure to sophisticated data manipulation attacks that exploit vulnerabilities in communication protocols such as EtherNet/IP (ENIP), MODBUS, and DNP3. Existing intrusion detection solutions often rely on abstract traffic features or reactive detection strategies, limiting their effectiveness in preventing real-time disruptions. This paper presents a protocol-aware network intrusion detection system (PA-NIDS) for real-time detection of malicious ENIP traffic targeting controllers. By leveraging contextual information within protocol communications, the proposed system enables early identification of attacker intent before physical impact. The framework was deployed on the operational Secure Water Treatment (SWaT) testbed and evaluated under single-point and coordinated multi-point attack scenarios. Experimental results show that PA-NIDS achieves 100% detection accuracy with zero false positives and an average detection latency below five seconds, providing proactive and interpretable protection for ICS environments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Network-Based Real-Time Detection of Data Manipulation Attacks in Industrial Control Systems

  • Gauthama Raman M R,
  • Sanat Khandekar,
  • Rohit Murarishetti,
  • Chew Zhan Yi Caven,
  • Ng Guo Feng Eric,
  • Jianying Zhou

摘要

The increasing connectivity of Industrial Control Systems (ICS) has heightened their exposure to sophisticated data manipulation attacks that exploit vulnerabilities in communication protocols such as EtherNet/IP (ENIP), MODBUS, and DNP3. Existing intrusion detection solutions often rely on abstract traffic features or reactive detection strategies, limiting their effectiveness in preventing real-time disruptions. This paper presents a protocol-aware network intrusion detection system (PA-NIDS) for real-time detection of malicious ENIP traffic targeting controllers. By leveraging contextual information within protocol communications, the proposed system enables early identification of attacker intent before physical impact. The framework was deployed on the operational Secure Water Treatment (SWaT) testbed and evaluated under single-point and coordinated multi-point attack scenarios. Experimental results show that PA-NIDS achieves 100% detection accuracy with zero false positives and an average detection latency below five seconds, providing proactive and interpretable protection for ICS environments.