Operation technology networks, i.e. hard- and software used for monitoring and controlling physical/industrial processes, have been considered immune to cyber attacks for a long time. A recent increase of attacks in these networks proves this assumption wrong. Several technical constraints lead to approaches to detect attacks on industrial processes using available sensor data. This setting differs fundamentally from anomaly detection in IT-network traffic and requires new visualization approaches adapted to the common periodical behavior in OT-network data. We present a tailored visualization system that utilizes inherent features of measurements from industrial processes to full capacity to provide insight into the data and support triage analysis by laymen and experts. The novel combination of spiral plots with results from anomaly detection was implemented in an interactive system. The capabilities of our system are demonstrated using sensor and actuator data from a real-world water treatment process with introduced attacks. Exemplary analysis strategies are presented. Finally, we evaluate effectiveness and usability of our system and perform an expert evaluation.
翻译:操作技术网络,即用于监测和控制物理/工业过程的硬件和软件,长期以来被认为是不受网络攻击的。最近这些网络攻击的增加证明这一假设是错误的。一些技术制约因素导致利用现有传感器数据探测工业过程攻击的方法。这种环境与信息技术网络交通中的异常检测截然不同,要求采用适应OT-网络数据中常见周期行为的新的可视化方法。我们提出了一个定制的可视化系统,利用工业过程测量的固有特征,充分提供洞察数据的能力,支持外行人员和专家的三角分析。在互动系统中实施了螺旋图与异常检测结果的新组合。我们系统的能力是通过采用攻击的实时水处理过程的传感器和操作器数据得到证明的。我们提出了示范性分析战略。最后,我们评估了我们系统的有效性和可用性,并进行了专家评估。