Composite instrusion detection in process control networks : dottorato di ricerca in informatica

Rrushi, Julian L. <1979- >

Tesi o dissertazioni - 2009

In this dissertation, I present a novel multi-algorithmic approach to real-time detection of known and unknown computer network attacks on process control systems. I begin with the discussion of an unconventional means of characterizing the normal behavior of a process control network, namely evolutions of bytes stored in specific locations in the random access memory (RAM) of a process control system. Then, I show how the set of normal evolutions of RAM content, i.e. evolutions that characterize the normal behavior of a process control network, is estimated and specified probabilistically and deterministically, respectively. More specifically, I explore an inductive machine-learning algorithm called the Estimation-Inspection algorithm, which uses estimation methods from applied statistics and probability theory to probabilistically estimate normal evolutions of RAM content. I also explore a specification-based approach, which is referred to as being physical process aware, that takes a deterministic approach to the specification of the set of normal evolutions of RAM content [...]
Archivio Tesi di dottorato

