2020
P.R. Grammatikis; P. Sarigiannidis; A. Sarigiannidis; D. Margounakis; A. Tsiakalos; G. Efstathopoulos
An Anomaly Detection Mechanism for IEC 60870-5-104 Conference
2020.
Abstract | BibTeX | Tags: Anomaly Detection, Cybersecurity, IEC-60870-5-104, Supervisory Control and Data Acquisition | Links:
@conference{Grammatikis2020,
title = {An Anomaly Detection Mechanism for IEC 60870-5-104},
author = { P.R. Grammatikis and P. Sarigiannidis and A. Sarigiannidis and D. Margounakis and A. Tsiakalos and G. Efstathopoulos},
url = {https://www.researchgate.net/publication/344386495_An_Anomaly_Detection_Mechanism_for_IEC_60870-5-104},
doi = {10.1109/MOCAST49295.2020.9200285},
year = {2020},
date = {2020-01-01},
journal = {2020 9th International Conference on Modern Circuits and Systems Technologies, MOCAST 2020},
abstract = {The transformation of the conventional electricity grid into a new paradigm called smart grid demands the appropriate cybersecurity solutions. In this paper, we focus on the security of the IEC 60870-5-104 (IEC-104) protocol which is commonly used by Supervisory Control and Data Acquisition (SCADA) systems in the energy domain. In particular, after investigating its security issues, we provide a multivariate Intrusion Detection System (IDS) which adopts both access control and outlier detection mechanisms in order to detect timely possible anomalies against IEC-104. The efficiency of the proposed IDS is reflected by the Accuracy and F1 metrics that reach 98% and 87%, respectively. © 2020 IEEE.},
keywords = {Anomaly Detection, Cybersecurity, IEC-60870-5-104, Supervisory Control and Data Acquisition},
pubstate = {published},
tppubtype = {conference}
}
P. Radoglou-Grammatikis; I. Siniosoglou; T. Liatifis; A. Kourouniadis; K. Rompolos; P. Sarigiannidis
Implementation and detection of modbus cyberattacks Conference
2020.
Abstract | BibTeX | Tags: intrusion detection system, Modbus, Smart Grid, Smod, Supervisory Control and Data Acquisition | Links:
@conference{Radoglou-Grammatikis2020,
title = {Implementation and detection of modbus cyberattacks},
author = { P. Radoglou-Grammatikis and I. Siniosoglou and T. Liatifis and A. Kourouniadis and K. Rompolos and P. Sarigiannidis},
url = {https://www.researchgate.net/publication/344386530_Implementation_and_Detection_of_Modbus_Cyberattacks},
doi = {10.1109/MOCAST49295.2020.9200287},
year = {2020},
date = {2020-01-01},
journal = {2020 9th International Conference on Modern Circuits and Systems Technologies, MOCAST 2020},
abstract = {Supervisory Control and Data Acquisition (SCADA) systems play a significant role in Critical Infrastructures (CIs) since they monitor and control the automation processes of the industrial equipment. However, SCADA relies on vulnerable communication protocols without any cybersecurity mechanism, thereby making it possible to endanger the overall operation of the CI. In this paper, we focus on the Modbus/TCP protocol, which is commonly utilised in many CIs and especially in the electrical grid. In particular, our contribution is twofold. First, we study and enhance the cyberattacks provided by the Smod pen-testing tool. Second, we introduce an anomaly-based Intrusion Detection System (IDS) capable of detecting Denial of Service (DoS) cyberattacks related to Modbus/TCP. The efficacy of the proposed IDS is demonstrated by utilising real data stemming from a hydropower plant. The accuracy and the F1 score of the proposed IDS reach 81% and 77% respectively. © 2020 IEEE.},
keywords = {intrusion detection system, Modbus, Smart Grid, Smod, Supervisory Control and Data Acquisition},
pubstate = {published},
tppubtype = {conference}
}
Address
Internet of Things and Applications Lab
Department of Electrical and Computer Engineering
University of Western Macedonia Campus
ZEP Area, Kozani 50100
Greece
Contact Information
tel: +30 2461 056527
Email: ithaca@uowm.gr