EE Seminar: Noam Erez, TAU

~~Noam Erez, 
M.Sc. student under the supervision of Prof. Avishai Wool

Wednesday, December 10, 2014  at  15:00
Room 011, Kitot Bldg., Faculty of Engineering

Control Variable Classification, Modeling and Anomaly Detection in Modbus/TCP SCADA Networks
The seminar describes our work on a novel domain-aware anomaly detection system which detects irregular changes in SCADA control registers' values. Through inspection of Modbus traffic, we were able to identify several general classes of registers: Sensor registers, Counter registers and Constant registers. We developed an automatic classifier that identifies these classes. We also developed parameterized behavior models for each class. In its learning phase, our system instantiates the model for each register, and detects deviations from the model during the enforcement phase. We evaluated our system on 131 hours of traffic from a production SCADA system. Our classifier had a True-Positive classification of 93%. For the correctly classified registers, the enforcement phase achieved a 0.86% false-alarm rate.

10 בדצמבר 2014, 15:00 
חדר 011, בניין כיתות-חשמל 
