FPGA-based Real-time Abnormal Packet Detector for Critical Industrial Network

Citations

WEB OF SCIENCE

3
Citations

SCOPUS

4

초록

As the information technology plays an important role in the smart factories, Ethernet-based industrial network has rapidly replaced the traditional field buses. To maintain this critical network secure, it is important to develop the real-time network intrusion detection system (NIDS). The widely used NIDS was developed for the general Internet environment where the average throughput to protect attacks from the large number of unknown network nodes is more important than the real-time detection capability. However, in the critical industrial network, the real-time protection is more important than the average throughput. In this paper, a FPGA-based abnormal Ethernet packet detector is proposed. Since it is designed for the closed industry network, packet detection is based on the whitelist that consists of the allowed network address and protocol numbers. The prototype system has been implemented using the Xilinx Zynq-7030 SoC running at 250MHz. The network header of the Ethernet packet is compared to the 256 whitelist ruleset within 0.032 mu sec, which means that the malicious packets from the abnormal network nodes are filtered out even before the whole packets arrives. This real-time packet filtering feature is useful in protecting highly secure network systems like the critical industrial control systems.

키워드

Ethernet packet detectornetwork intrusion detection systemModbusFPGAINTRUSION DETECTIONSECURITYSOFTWARE
제목
FPGA-based Real-time Abnormal Packet Detector for Critical Industrial Network
저자
Kang, JiwoongKim, TaeinPark, Jaehyun
DOI
10.1109/iscc47284.2019.8969630
발행일
2019
유형
Proceedings Paper
저널명
2019 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC)
페이지
1199 ~ 1203