Visible to the public Development of Industrial Network Forensics Lessons

TitleDevelopment of Industrial Network Forensics Lessons
Publication TypeConference Paper
Year of Publication2018
AuthorsNguyen, Thuy D., Irvine, Cynthia E.
Conference NameProceedings of the Fifth Cybersecurity Symposium
ISBN Number978-1-4503-6406-5
Keywordsindustrial control system, industrial control systems, network forensics, pubcrawl, resilience, Resiliency, Scalability, scalable, security education

Most forensic investigators are trained to recognize abusive network behavior in conventional information systems, but they may not know how to detect anomalous traffic patterns in industrial control systems (ICS) that manage critical infrastructure services. We have developed and laboratory-tested hands-on teaching material to introduce students to forensics investigation of intrusions on an industrial network. Rather than using prototypes of ICS components, our approach utilizes commercial industrial products to provide students a more realistic simulation of an ICS network. The lessons cover four different types of attacks and the corresponding post-incident network data analysis.

Citation Keynguyen_development_2018