A survey of intrusion detection on industrial control systems

Top Cited Papers
Open Access
Abstract
The modern industrial control systems now exhibit an increasing connectivity to the corporate Internet technology networks so as to make full use of the rich resource on the Internet. The increasing interaction between industrial control systems and the outside Internet world, however, has made them an attractive target for a variety of cyber attacks, raising a great need to secure industrial control systems. Intrusion detection technology is one of the most important security precautions for industrial control systems. It can effectively detect potential attacks against industrial control systems. In this survey, we elaborate on the characteristics and the new security requirements of industrial control systems. After that, we present a new taxonomy of intrusion detection systems for industrial control systems based on different techniques: protocol analysis based, traffic mining based, and control process analysis based. In addition, we analyze the advantages and disadvantages of different categories of intrusion detection systems and discuss some future developments of intrusion detection systems for industrial control systems, in order to promote further research on intrusion detection technology for industrial control systems.
Funding Information
  • National Natural Science Foundation of China (61502466)
  • National Natural Science Foundation of China (61503365)
  • National Natural Science Foundation of China (61702506)
  • Fundamental Research Funds for the Central Universities (FRF-TP-17-058A1)
  • National Social Science Foundation of China (17ZDA331)