Franka Schuster

dblp:128/0772 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
4since 2021 · last 2024
0009-0008-0687-9155ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 first-author
YearPublicationVenuePosition
2024 Questioning the Myth: Investigating ICS Traffic Homogeneity from an Anomaly Detection Perspective
Franka Schuster, Hartmut König
CRITIS1
2024 No Need for Details: Effective Anomaly Detection for Process Control Traffic in Absence of Protocol and Attack Knowledge
abstract
The rapidly expanding landscape of attack vectors on cyber-physical systems (CPS) has led to the proposal of various attack detection methods for this area. Most approaches focus on analyzing time series of data from physical processes. However, the availability of such well-prepared data is not guaranteed in most infrastructures. In contrast, relatively few approaches address the direct analysis of network traffic, which is the natural basis for interaction between CPS devices. In this paper, we examine traffic-based methods using data flows, packets, and packet sequences as monitoring base. We include the packet payload in the analysis in a protocol-agnostic manner. This offers the possibility to apply the approach in different networks independently of the used CPS technologies or processes. We use one-class machine learning methods applied on only normal traffic in the training phase. This allows us to configure the detection capabilities independently of attack knowledge or given attack examples. Besides the evaluation regarding detection capability and efficiency, we further examine the potential of the protocol-agnostic models for a transfer on foreign detection scenarios.
Franka Schuster, Hartmut König
RAID1
2023 Whitelisting for Characterizing and Monitoring Process Control Communication
Andreas Paul 0003, Franka Schuster, Hartmut König
NSS2
2022 Lights on Power Plant Control Networks
Stefan Mehner, Franka Schuster, Oliver Hohlfeld
PAM2
2018 Attack and Fault Detection in Process Control Communication Using Unsupervised Machine Learning
abstract
In the course of industrial digitalization, the security of process control networks and especially critical infrastructures has become a major issue that requires novel methods to achieve a multi-level protection. An important feature of this protection is a protocol-specific monitoring within the process control networks that identifies faults and attacks which already have overcome the firewall protection. For a wide-spread application in various sites, this monitoring must be self-adaptive to the different traffic characteristics of the respective networks. Protocol knowledge combined with unsupervised machine learning algorithms can leverage this task. In this paper we present the latest results of applying two machine learning methods on real-world traffic datasets from two plant process control networks. The results for different mappings of the considered packet features are discussed in terms of f-score, precision, and recall. They demonstrate the high potential of using unsupervised learning for training anomaly detectors to identify intrusions in industrial networks.
Franka Schuster, Fabian Malte Kopp, Andreas Paul 0003, Hartmut König
INDIN1
2014 Parallelization of Network Intrusion Detection Systems under Attack Conditions
René Rietz, Michael Vogel, Franka Schuster, Hartmut König
DIMVA3
2013 Towards the Protection of Industrial Control Systems - Conclusions of a Vulnerability Analysis of Profinet IO
Andreas Paul 0003, Franka Schuster, Hartmut König
DIMVA2
2012 A distributed intrusion detection system for industrial automation networks
abstract
Modern automation is measured in terms of interoperability and easy administration. Introducing technology focussing on these criteria, however, induce new security risks to existing and future automation installations. Current security approaches in automation do not keep pace with the rising security challenges. Prevalent in automation is the use of access control to protect the system from malicious activity, such as extern attacks. Means to inspect the automation traffic to identify attacks that already have overcome access control or are initiated from inside the automation system are not available, yet. For filling this gap, we investigate in the application of intrusion detection techniques on industrial automation. In this paper, we present the current state of an intrusion detection system tailored to the analysis of operation down to traffic between automation devices on field layer.
Franka Schuster, Andreas Paul 0003
ETFA1