错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Structured Defense Model Against DNP3-Based Critical Infrastructure Attacks

  • Erdal Ozdogan

摘要

Critical infrastructures encompass the essential systems required to operate various sectors, including energy, water, communication, finance, health, and transportation. The sophistication and organization of attacks on these infrastructures are escalating. A frequently targeted protocol within these critical infrastructures is the Distributed Network Protocol 3 (DNP3). This study developed a Machine Learning-supported Intrusion Detection System to identify attacks on DNP3 networks. The research utilized a current and balanced dataset containing DNP3 traffic from critical infrastructures. A model incorporating two defense lines, reflecting the structure of the attacks, was proposed. The initial detection of reconnaissance attacks is designed to prevent subsequent attacks. Reconnaissance attacks are identified in the first defense line using Extreme Gradient Boosting. In contrast, attacks on critical infrastructures are classified as the second defense line, with the support of artificial neural networks. In the study’s first phase, the model achieved high accuracy in detecting reconnaissance attacks. In the second phase, the model achieved approximately 99% accuracy in detecting attacks and around 98% average success in classification. The model achieved 96% accuracy in evaluating unknown attack detection capability.