遇见数据集

Dataset for Network Intrusion Detection System on SCADA IEC 60870-5-104

收藏
Zenodo2022-08-31 更新2026-05-25 收录
数据链接:
官方服务:

资源简介:

Security is the main challenge in Supervisory Control and Data Acquisition (SCADA) systems since SCADA systems must be connected to heterogeneous networks to save costs. SCADA devices such as RTUs have limited resources, so a small-scale cyber attack on a computer network will have a major impact on the SCADA system. This study discusses the SCADA system with the IEC 60870-5-104 protocol which is widely used in the power plant industry. A physical testbed is built to simulate the electrical distribution process. The SCADA system in the distribution section is more vulnerable than other parts because it is located directly in the community environment so that many holes can be entered by attackers. The purpose of this study is to obtain relevant datasets in the SCADA system. The simulation carried out in this study is a normal communication between the HMI and the RTU, then attacked to disrupt the communication. The attack activities carried out are port scan, brute force and DoS. DoS attacks carried out are ICMP flood, Syn flood, and IEC 104 flood. IEC 104 flood attack is a modified attack to attack RTU where RTU is flooded with an unknown typeid ASDU (Application Service Data Unit). Attacks are carried out using Kali Linux operating system. All scenarios are recorded and saved in pcap. To prove that there is attack data traffic on the IDS dataset Snort and Suricata are used to detect it. In this study, there are also intrusion detection performance results from Snort and Suricata

监控与数据采集(Supervisory Control and Data Acquisition, SCADA)系统的核心安全挑战在于,其为控制成本需接入异构网络。诸如远程终端单元(Remote Terminal Unit, RTU)这类SCADA设备资源有限,因此针对其网络的小规模网络攻击,便会对SCADA系统造成严重影响。本研究聚焦于电力行业广泛应用的IEC 60870-5-104协议SCADA系统,搭建物理测试床以模拟配电流程。配电环节的SCADA系统因直接部署于社区环境,相较于其他系统部件更易受攻击,攻击者可利用诸多攻击入口。本研究的核心目标为获取SCADA系统相关的数据集。本研究的仿真实验分为两个阶段:首先实现人机界面(Human Machine Interface, HMI)与RTU间的正常通信,随后发起攻击以破坏通信链路。本次实验所实施的攻击包括端口扫描、暴力破解与拒绝服务(Denial of Service, DoS)攻击;其中DoS攻击涵盖ICMP泛洪、Syn泛洪与IEC 104泛洪三类。IEC 104泛洪攻击属于定制化攻击手段,通过向RTU发送携带未知类型标识符的应用服务数据单元(Application Service Data Unit, ASDU)实现流量泛洪。本次攻击依托卡利Linux(Kali Linux)操作系统开展,所有攻击场景均被记录并保存为pcap格式数据包文件。为验证数据集中包含攻击流量,本研究采用入侵检测系统(Intrusion Detection System, IDS)工具Snort与Suricata进行流量检测。此外,本研究还给出了Snort与Suricata的入侵检测性能测试结果。

提供机构:
Zenodo
创建时间:
2022-08-31
二维码
社区交流群
二维码
科研交流群
商业服务