Digital Forensics Process of an Attack Vector in ICS environment
At a glance
- Citations
- 1
- References
- 13
- Comments
- 0
Abstract
Industrial control systems (ICS) can be exposed to cyberattacks with potentially catastrophic consequences. Intrusion detection is a fraud prevention technique derived from big data that play a key role in detecting attacks at the earliest stage. Data historian is essential to understanding all events and activities across the network. This article introduces the basic mechanisms by which common attacks on ICS can be detected and analyzed through different forensic tools. We explored the common vulnerabilities and potential attack vectors present in critical infrastructures and described measures that can be deployed to mitigate those threats. We discussed several common attack scenarios and artifacts that a forensic analysis of an affected ICS device can recover to help diagnose an attack. An ICS test lab was implemented and used to examine the common attacks. A menu driven set of forensic tools specific for ICS was developed to allow the extraction and analysis of the resulting attack vector.
Publication details
- DOI
- 10.1109/bigdata52589.2021.9671986
- OpenAlex
- W4205197557
- Document type
- conference-paper
- Language
- EN
- Source
- 2021 IEEE International Conference on Big Data (Big Data)
- Last metadata update
Comments
Log in to join the discussion.