Identification of industrial devices based on payload
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F24%3APU151835" target="_blank" >RIV/00216305:26220/24:PU151835 - isvavai.cz</a>
Result on the web
<a href="https://dl.acm.org/doi/10.1145/3664476.3670462" target="_blank" >https://dl.acm.org/doi/10.1145/3664476.3670462</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1145/3664476.3670462" target="_blank" >10.1145/3664476.3670462</a>
Alternative languages
Result language
angličtina
Original language name
Identification of industrial devices based on payload
Original language description
Identification of industrial devices based on their behavior in network communication is important from a cybersecurity perspective in two areas: attack prevention and digital forensics. In both areas, device identification falls under asset management or asset tracking. Due to the impact of active scanning on these networks, particularly in terms of latency, it is important to use passive scanning in industrial networks. For passive identification, statistical learning algorithms are nowadays the most appropriate. The aim of this paper is to demonstrate the potential for passive identification of PLC devices using statistical learning based on network communication, specifically the payload of the packet. Individual statistical parameters from 15 minutes of traffic based on payload entropy were used to create the features. Three scenarios were performed and the XGBoost algorithm was used for evaluation. In the best scenario, the model achieved an accuracy score of 83% to identify individual devices.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
20203 - Telecommunications
Result continuities
Project
<a href="/en/project/FW06010490" target="_blank" >FW06010490: Smart metering crypto portal</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2024
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
ARES '24: Proceedings of the 19th International Conference on Availability, Reliability and Security
ISBN
979-8-4007-1718-5
ISSN
—
e-ISSN
—
Number of pages
9
Pages from-to
1-9
Publisher name
Association for Computing Machinery
Place of publication
New York, NY, USA
Event location
Vídeň
Event date
Jul 30, 2024
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—