Efficient Intrusion Detection on Low-Performance Industrial IoT Edge Node Devices

08/11/2019
by   Matthias Niedermaier, et al.
0

Communication between sensors, actors and Programmable Logic Controllers (PLCs) in industrial systems moves from two-wire field buses to IP-based protocols such as Modbus/TCP. This increases the attack surface because the IP-based network is often reachable from everywhere within the company. Thus, centralized defenses, e.g. at the perimeter of the network do not offer sufficient protection. Rather, decentralized defenses, where each part of the network protects itself, are needed. Network Intrusion Detection Systems (IDSs) monitor the network and report suspicious activity. They usually run on a single host and are not able to capture all events in the network and they are associated with a great integration effort. To bridge this gap, we introduce a method for intrusion detection that combines distributed agents on Industrial Internet of Things (IIoT) edge devices with a centralized logging. In contrast to existing IDSs, the distributed approach is suitable for industrial low performance microcontrollers. We demonstrate a Proof of Concept (PoC) implementation on a MCU running FreeRTOS with LwIP and show the feasibility of our approach in an IIoT application.

READ FULL TEXT

page 8

page 9

page 10

page 11

page 13

research
07/18/2019

Collecting MIB Data from Network Managed by SNMP using Multi Mobile Agents

Network anomalies are destructive to networks. Intrusion detection syste...
research
10/16/2019

Network Scanning and Mapping for IIoT Edge Node Device Security

The amount of connected devices in the industrial environment is growing...
research
10/06/2022

Network Intrusion Detection System in a Light Bulb

Internet of Things (IoT) devices are progressively being utilised in a v...
research
11/05/2021

IPAL: Breaking up Silos of Protocol-dependent and Domain-specific Industrial Intrusion Detection Systems

The increasing interconnection of industrial networks with the Internet ...
research
08/12/2019

A Secure Dual-MCU Architecture for Robust Communication of IIoT Devices

The Industrial Internet of Things (IIoT) has already become a part of ou...
research
09/20/2018

Time is of the Essence: Machine Learning-based Intrusion Detection in Industrial Time Series Data

The Industrial Internet of Things drastically increases connectivity of ...
research
08/09/2021

ABBA: A quasi-deterministic Intrusion Detection System for the Internet of Things

An increasing amount of processes are becoming automated for increased e...

Please sign up or login with your details

Forgot password? Click here to reset