Truth Will Out: Departure-Based Process-Level Detection of Stealthy Attacks on Control Systems
- Wissam Aoudi, Mikel Iturbe, M. Almgren
- Computer ScienceConference on Computer and Communications…
- 8 October 2018
Experimental results show that PASAD is capable of detecting not only significant deviations in the process behavior, but also subtle attack-indicating changes, significantly raising the bar for strategic adversaries who may attempt to maintain their malicious manipulation within the noise level.
On the Feasibility of Distinguishing Between Process Disturbances and Intrusions in Process Control Systems Using Multivariate Statistical Process Control
- Mikel Iturbe, J. Camacho, Iñaki Garitano, Urko Zurutuza, Roberto Uribeetxeberria
- Computer Science46th Annual IEEE/IFIP International Conference on…
- 1 June 2016
An anomaly detection and diagnostic system based on Multivariate Statistical Process Control, that aims to distinguish between attacks and disturbances, is presented and results show that the approach can be used to distinguish disturbances from intrusions to a certain extent.
Visualizing Network Flows and Related Anomalies in Industrial Networks using Chord Diagrams and Whitelisting
- Mikel Iturbe, Iñaki Garitano, Urko Zurutuza, Roberto Uribeetxeberria
- Computer ScienceVISIGRAPP
- 4 December 2016
This paper presents a network flow and related alert visualization system based on chord diagrams that represents the detected network flows within a time interval, highlighting the ones that do not comply with the whitelisting rules.
A Mood Analysis on Youtube Comments and a Method for Improved Social Spam Detection
- Enaitz Ezpeleta, Mikel Iturbe, Iñaki Garitano, I. D. Mendizabal, Urko Zurutuza
- Computer ScienceHybrid Artificial Intelligence Systems
- 20 June 2018
A comparison between obtained results with and without mood information shows that this feature can help to improve social spam filtering results: the best accuracy is improved in two different datasets, and the number of false positives is reduced.
Deep packet inspection for intelligent intrusion detection in software-defined industrial networks: A proof of concept
- M. Sainz, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza
- Computer ScienceLogic Journal of the IGPL
- 31 December 2019
The potential benefits of using software-defined networks in industrial networks with security purposes are described and the set up and results of a pilot experiment carried out in a scaled physical implementation point to the potential viability of the technology for intrusion detection and the need of researching in architectural scalability.
Towards Large-Scale, Heterogeneous Anomaly Detection Systems in Industrial Networks: A Survey of Current Trends
- Mikel Iturbe, Iñaki Garitano, Urko Zurutuza, Roberto Uribeetxeberria
- Computer ScienceSecur. Commun. Networks
- 22 November 2017
A novel taxonomy to classify existing IN-based ADSs and a discussion of open problems in the field of Big Data ADSs for INs that can lead to further development are presented.
Fuzzing the Internet of Things: A Review on the Techniques and Challenges for Efficient Vulnerability Discovery in Embedded Systems
- Maialen Eceiza, J. L. Flores, Mikel Iturbe
- Computer ScienceIEEE Internet of Things Journal
- 2 February 2021
The particularities of the embedded world as far as security is concerned are listed, a literature review on fuzzing techniques and proposals are performed, and future research directions are presented by pointing out the gaps identified in the review.
Null is Not Always Empty: Monitoring the Null Space for Field-Level Anomaly Detection in Industrial IoT Environments
- E. Zugasti, Mikel Iturbe, Iñaki Garitano, Urko Zurutuza
- Computer ScienceGlobal Internet of Things Summit
- 1 June 2018
This work presents an Anomaly Detection System for industrial environments that monitors physical quantities to detect intrusions based in the null space detection, which is at the same time, based on Stochastic Subspace Identification (SSI).
Software Defined Networking Opportunities for Intelligent Security Enhancement of Industrial Control Systems
- M. Sainz, Mikel Iturbe, Iñaki Garitano, Urko Zurutuza
- Computer ScienceInternational Conference on European…
- 6 September 2017
The affinities between SDN and ICSs are described and implementation strategies are discussed and the potential opportunities that Software Defined Networking provides for the security enhancement of Industrial Control Networks are presented.
Improving fuzzing assessment methods through the analysis of metrics and experimental conditions
- Maialen Eceiza, J. L. Flores, Mikel Iturbe
- Computer ScienceComputers & security
- 1 October 2022
...
...