SIA OpenIR  > 工业控制网络与系统研究室
Modbus/TCP Communication Anomaly Detection Based on PSO-SVM
Shang WL(尚文利); Zhang SS(张盛山); Wan M(万明)
Department工业控制网络与系统研究室
Conference Name2013 the 3rd International Conference on Communication and Network Security (ICCNS 2013)
Conference DateNovember 16-17, 2013
Conference PlaceLondon, UK
Source Publication2013 the 3rd International Conference on Communication and Network Security (ICCNS 2013)
2013
Pages1-10
Contribution Rank1
KeywordPso Svm Modbus Function Code Sequence Anomaly Detection Industrial Security Gateway
Abstract

Industrial firewall and intrusion detection system based on Modbus TCP protocol analysis and "whitelist" policy cannot effectively identify attacks on Modbus controller which exactly take advantage of the configured rules. An Industrial control systems simulation environment is established and a data preprocessing method for Modbus TCP traffic captured is designed to meet the need of anomaly detection module. Furthermore a Modbus function code sequence anomaly detection model based on SVM optimized by PSO method is designed. And the model can effectively identify abnormal Modbus TCP traffic, according to frequency of different short mode sequences in a Modbus code sequence.

Language英语
Document Type会议论文
Identifierhttp://ir.sia.cn/handle/173321/13875
Collection工业控制网络与系统研究室
AffiliationShenyang Institute of Automation, Chinese Academy of Science, Shenyang 110016, China
Recommended Citation
GB/T 7714
Shang WL,Zhang SS,Wan M. Modbus/TCP Communication Anomaly Detection Based on PSO-SVM[C],2013:1-10.
Files in This Item: Download All
File Name/Size DocType Version Access License
Modbus TCP Communica(3536KB)会议论文 开放获取CC BY-NC-SAView Download
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Shang WL(尚文利)]'s Articles
[Zhang SS(张盛山)]'s Articles
[Wan M(万明)]'s Articles
Baidu academic
Similar articles in Baidu academic
[Shang WL(尚文利)]'s Articles
[Zhang SS(张盛山)]'s Articles
[Wan M(万明)]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Shang WL(尚文利)]'s Articles
[Zhang SS(张盛山)]'s Articles
[Wan M(万明)]'s Articles
Terms of Use
No data!
Social Bookmark/Share
File name: Modbus TCP Communication Anomaly Detection Based on PSO-SVM.pdf
Format: Adobe PDF
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.