Přístupnostní navigace
E-application
Search Search Close
Publication detail
KADLEC, J. VRBA, R. KUCHTA, R.
Original Title
Intrusion Detection System for wide Automation Network Based on the Ethernet Compatible Communication Protocols
Type
conference paper
Language
English
Original Abstract
This paper is focused on the description of importance, design, and implementation of the Intrusion Detection Systems for a new automation system based on the Ethernet communication protocol. Newly developed and designed automation networks for complex factory control are composed from several types of automation communication links with different communication protocols, but most of the factory middle layer and top layer communication networks are based on Ethernet communication protocol. Wide use of Ethernet communication protocol not only in IT, but also in automation field, brings not only advantages of easy implementation and interoperability between different automation communication networks, but also brings risks and vulnerabilities, well known form IT. Therefore security incidents are becoming more serious and more common not only in computer networks, but also in automation networks. Actual trends in automation networks are among others wide automation networks covering several manufacture divisions or remote controlling of automation networks through the Internet. Necessity of a remote connection to the automation networks covers all security vulnerabilities and risks, which originate from the Internet. Analogically with IT, an automation network can be secured by the conventional way through firewalls and VPN tunnels, but automation networks have several specific requirements on the QoS, against the IT networks. For this reason a new automation firewall device was defined, designed and tested. The new automation firewall includes messaging system for logging all events and alerts originates form automation network. IDMEF (Intrusion Detection Message Exchange Format) is used, as a basis for automation firewall messaging system.
Keywords
Intrusion detection; automation network; IDMEF
Authors
KADLEC, J.; VRBA, R.; KUCHTA, R.
RIV year
2011
Released
23. 1. 2011
Location
St. Maarten, The Netherlands Antilles
ISBN
978-1-61208-114-4
Book
ICONS 2011, The Sixth International Conference on Systems Proceedings
Pages from
95
Pages to
98
Pages count
4
BibTex
@inproceedings{BUT73601, author="Jaroslav {Kadlec} and Radimír {Vrba} and Radek {Kuchta}", title="Intrusion Detection System for wide Automation Network Based on the Ethernet Compatible Communication Protocols", booktitle="ICONS 2011, The Sixth International Conference on Systems Proceedings", year="2011", pages="95--98", address="St. Maarten, The Netherlands Antilles", isbn="978-1-61208-114-4" }