<div class="csl-bib-body">
<div class="csl-entry">Brenner, B., Hollerer, S., Bhosale, P., Sauter, T., Kastner, W., Fabini, J., & Zseby, T. (2023). Better Safe Than Sorry: Risk Management based on a Safety-augmented Network Intrusion Detection System. <i>IEEE Open Journal of the Industrial Electronics Society</i>. https://doi.org/10.1109/OJIES.2023.3297057</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/187683
-
dc.description.abstract
Interconnected Industrial Control System (ICS) networks based on routable protocols are susceptible to remote attacks similar to classical Information Technology (IT) networks. However, addressing ICS security in an isolated view is dangerous since ICSs have to ensure safety measures for people, processes, and the environment. Safety and security of ICSs are often addressed separately, without considering their important interrelation. Safety measures can violate security policies (e.g., an emergency stop function accessible by anyone); likewise, a security incident can violate safety policies (e.g., by increasing reaction time). In this paper we propose a Network-based Intrusion Detection System (NIDS) with the interrelation between safety and security in mind: It detects security incidents while evaluating possible safety-related consequences of both the detected attack and possible countermeasures. We evaluate our approach with a Proof of Concept (PoC). The alerts generated by the PoC prototype serve as the basis for a risk management strategy proposed in this paper. Our approach provides a basis for safety-aware intrusion detection in smart factories and other cyber-physical systems.
en
dc.description.sponsorship
TÜV Austria Holding AG
-
dc.language.iso
en
-
dc.publisher
Institute of Electrical and Electronics Engineers (IEEE)
-
dc.relation.ispartof
IEEE Open Journal of the Industrial Electronics Society
-
dc.subject
Safety
en
dc.subject
Security
en
dc.subject
Intrusion Detection
en
dc.subject
Telecommunication Traffic
en
dc.subject
Risk Management
en
dc.subject
Machine Learning
en
dc.subject
Integrated Circuits
en
dc.title
Better Safe Than Sorry: Risk Management based on a Safety-augmented Network Intrusion Detection System
en
dc.type
Article
en
dc.type
Artikel
de
dc.type.category
Original Research Article
-
tuw.journal.peerreviewed
true
-
tuw.peerreviewed
true
-
tuw.project.title
SafeSecSystem Modeling
-
tuw.researchinfrastructure
Pilotfabrik
-
tuw.researchTopic.id
I7
-
tuw.researchTopic.id
I4
-
tuw.researchTopic.id
I3
-
tuw.researchTopic.name
Telecommunication
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.name
Automation and Robotics
-
tuw.researchTopic.value
25
-
tuw.researchTopic.value
50
-
tuw.researchTopic.value
25
-
dcterms.isPartOf.title
IEEE Open Journal of the Industrial Electronics Society
-
tuw.publication.orgunit
E389-01 - Forschungsbereich Networks
-
tuw.publication.orgunit
E191-03 - Forschungsbereich Automation Systems
-
tuw.publication.orgunit
E056-16 - Fachbereich SafeSeclab
-
tuw.publication.orgunit
E384-01 - Forschungsbereich Software-intensive Systems
-
tuw.publication.orgunit
E389 - Institute of Telecommunications
-
tuw.publication.orgunit
E191 - Institut für Computer Engineering
-
tuw.publication.orgunit
E384 - Institut für Computertechnik
-
tuw.publication.orgunit
E056 - Doctoral School
-
tuw.publisher.doi
10.1109/OJIES.2023.3297057
-
dc.date.onlinefirst
2023-07-19
-
dc.identifier.eissn
2644-1284
-
dc.description.numberOfPages
17
-
tuw.author.orcid
0000-0001-9549-467X
-
tuw.author.orcid
0000-0002-3814-6019
-
tuw.author.orcid
0000-0001-5760-2342
-
tuw.author.orcid
0000-0001-5420-404X
-
tuw.author.orcid
0000-0002-8285-1591
-
tuw.author.orcid
0000-0002-5391-467X
-
wb.sciencebranch
Informatik
-
wb.sciencebranch
Elektrotechnik, Elektronik, Informationstechnik
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.oefos
2020
-
wb.sciencebranch.value
50
-
wb.sciencebranch.value
50
-
item.fulltext
no Fulltext
-
item.grantfulltext
restricted
-
item.cerifentitytype
Publications
-
item.cerifentitytype
Publications
-
item.openairetype
Article
-
item.openairetype
Artikel
-
item.languageiso639-1
en
-
item.openairecristype
http://purl.org/coar/resource_type/c_18cf
-
item.openairecristype
http://purl.org/coar/resource_type/c_18cf
-
crisitem.author.dept
E389-01 - Forschungsbereich Networks
-
crisitem.author.dept
E191-03 - Forschungsbereich Automation Systems
-
crisitem.author.dept
E191-03 - Forschungsbereich Automation Systems
-
crisitem.author.dept
E384 - Institut für Computertechnik
-
crisitem.author.dept
E191-03 - Forschungsbereich Automation Systems
-
crisitem.author.dept
E389-01 - Forschungsbereich Networks
-
crisitem.author.dept
E389-01 - Forschungsbereich Networks
-
crisitem.author.orcid
0000-0001-9549-467X
-
crisitem.author.orcid
0000-0002-3814-6019
-
crisitem.author.orcid
0000-0001-5420-404X
-
crisitem.author.orcid
0000-0002-8285-1591
-
crisitem.author.orcid
0000-0002-5391-467X
-
crisitem.author.parentorg
E389 - Telecommunications
-
crisitem.author.parentorg
E191 - Institut für Computer Engineering
-
crisitem.author.parentorg
E191 - Institut für Computer Engineering
-
crisitem.author.parentorg
E350 - Fakultät für Elektrotechnik und Informationstechnik