sponsors
help promote
usenix conference policies
Providing SCADA Network Data Sets for Intrusion Detection Research
Antoine Lemay and José M. Fernandez, École Polytechnique de Montréal
High profile attacks such as Stuxnet and the cyber at-tack on the Ukrainian power grid have increased re-search in Industrial Control System (ICS) and Supervi-sory Control and Data Acquisition (SCADA) network security. However, due to the sensitive nature of these networks, there is little publicly available data for re-searchers to evaluate the effectiveness of the proposed solution. The lack of representative data sets makes evaluation and independent validation of emerging se-curity solutions difficult and slows down progress to-wards effective and reusable solutions.
This paper presents our work to generate representative labeled data sets for SCADA networks that security researcher can use freely. The data sets include packet captures including both malicious and non-malicious Modbus traffic and accompanying CSV files that con-tain labels to provide the ground truth for supervised machine learning.
To provide representative data at the network level, the data sets were generated in a SCADA sandbox, where electrical network simulators were used to introduce realism in the physical component. Also, real attack tools, some of them custom built for Modbus networks, were used to generate the malicious traffic. Even though they do not fully replicate a production network, these data sets represent a good baseline to validate detection tools for SCADA systems.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Antoine Lemay and Jose M. Fernandez},
title = {Providing {SCADA} Network Data Sets for Intrusion Detection Research},
booktitle = {9th Workshop on Cyber Security Experimentation and Test (CSET 16)},
year = {2016},
address = {Austin, TX},
url = {https://www.usenix.org/conference/cset16/workshop-program/presentation/lemay},
publisher = {USENIX Association},
month = aug
}
connect with us