Publication Abstract
A Retrofit Network Intrusion Detection System for MODBUS RTU and ASCII Industrial Control Systems
Morris, T., Vaughn, R., & Dandass, Y. (2012). A Retrofit Network Intrusion Detection System for MODBUS RTU and ASCII Industrial Control Systems. Proceedings of the 45th Hawaii International Conference on System Sciences. Maui, HI: IEEE.
Abstract
MODBUS RTU/ASCII Snort is software to retrofit
serial based industrial control systems to add
Snort intrusion detection and intrusion prevention
capabilities. This article discusses the need for such
a system by describing 4 classes of intrusion vulnerabilities
(denial of service, command injection, response
injection, and system reconnaissance) which
can be exploited on MODBUS RTU/ASCII industrial
control systems. The article provides details on how
Snort rules can detect and prevent such intrusions.
Finally, the article describes the MODBUS
RTU/ASCII Snort implementation, provides details
on placement of a MODBUS RTU/ASCII Snort host
within a control system to maximize intrusion detection
and prevention capabilities, and discusses the
system’s validation.
|