scholarly journals ICSTrace: A Malicious IP Traceback Model for Attacking Data of the Industrial Control System

2021 ◽  
Vol 2021 ◽  
pp. 1-14
Author(s):  
Feng Xiao ◽  
Enhong Chen ◽  
Qiang Xu ◽  
Xianguo Zhang

Considering that the attacks against the industrial control system are mostly organized and premeditated actions, IP traceback is significant for the security of the industrial control system. Based on the infrastructure of the internet, we have developed a novel malicious IP traceback model, ICSTrace, without deploying any new services. The model extracts the function codes and their parameters from the attack data according to the format of the industrial control protocol and employs a short sequence probability method to transform the function codes and their parameters into a vector, which characterizes the attack pattern of malicious IP addresses. Furthermore, a partial seeded K-means algorithm is proposed for the pattern’s clustering, which helps in tracing the attacks back to an organization. ICSTrace is evaluated based on the attack data captured by the large-scale deployed honeypots for the industrial control system, and the results demonstrate that ICSTrace is effective on malicious IP traceback in the industrial control system.

2018 ◽  
Vol 5 (3) ◽  
pp. 2178-2189 ◽  
Author(s):  
Qiang Li ◽  
Xuan Feng ◽  
Haining Wang ◽  
Limin Sun

IEEE Access ◽  
2021 ◽  
Vol 9 ◽  
pp. 16239-16253
Author(s):  
Mohammad Noorizadeh ◽  
Mohammad Shakerpour ◽  
Nader Meskin ◽  
Devrim Unal ◽  
Khashayar Khorasani

Sign in / Sign up

Export Citation Format

Share Document