Supervisory control and data acquisition (SCADA) systems are widely used in industrial control and automation. Modern SCADA protocols often employ TCP/IP to transport sensor data and control signals. Meanwhile, corporate IT infrastructures are interconnecting with previously isolated SCADA networks. The use of TCP/IP as a carrier protocol and the interconnection of IT and SCADA networks raise serious security issues. This paper describes an architecture for SCADA network forensics. In addition to supporting forensic investigations of SCADA network incidents, the architecture incorporates mechanisms for monitoring process behavior, analyzing trends and optimizing plant performance.
CITATION STYLE
Kilpatrick, T., Gonzalez, J., Chandia, R., Papa, M., & Shenoi, S. (2006). An architecture for SCADA network forensics. IFIP International Federation for Information Processing, 222, 273–285. https://doi.org/10.1007/0-387-36891-4_22
Mendeley helps you to discover research relevant for your work.