Anomaly Detection Approach based on Function Code Traffic by Using CUSUM Algorithm

作者:Wan Ming*; Shang Wenli; Zeng Peng
来源:4th National Conference on Electrical, Electronics and Computer Engineering (NCEECE), 2015-12-12 to 2015-12-13.

摘要

There is an increasing consensus that it is necessary to resolve the security issues in today's industrial control system. From this point, this paper proposes an anomaly detection approach based on function code traffic to detect abnormal Modbus/TCP communication behaviors efficiently. Furthermore, this approach analyzes the Modbus/TCP communication packets in depth, and obtains the function code in each packet. According to the function code traffic change, this approach uses the Cumulative Sum (CUSUM) algorithm for change point detection, and generates an alarm. Our simulation results show that, the proposed approach is very available and effective to provide the security for industrial control system. Besides, we also discuss some advantages and drawbacks when using this approach.