Back to results

Virginia Tech

Towards Accurate and Reliable Industrial Intrusion Detection Systems Using Shadow Replicas

Abstract

dc:description.abstract

Supervisory Control and Data Acquisition (SCADA) systems manage the operations of a plethora of safety-critical industrial control systems. Due to their sensitive nature, SCADA systems have been the target of adversaries employing a wide range of attacks. This thesis proposes an approach to protect SCADA systems against attacks that evade detection because of the lack of a comprehensive view of both application and network-layer responses. Specifically, we leverage multiple open-source Network Intrusion Detection Systems (NIDSs) paired with a SCADA shadow replica to provide both network and application threat detection. The shadow replica is augmented with a Finite State Machine (FSM) to compute the anticipated states of both the SCADA system and connected devices. Isolated from the operational network, it is protected from direct front-end attacks. When the SCADA system becomes compromised, even without an IDS alert, the replica can expose the attack and offer an operational failover. We implement a prototype of our system and evaluate it against locally executed attacks on commercial out-of-the-box devices and public IoT datasets. Results indicate that incorporating the shadow replica alongside NIDSs can enhance detection coverage in our evaluations.

Degree

thesis:*
Name thesis:degree_name
Master of Science
Level thesis:degree_level
masters
Discipline thesis:degree_discipline
Computer Engineering
Department dc:contributor.department
Electrical and Computer Engineering
Grantor dc:publisher
Virginia Tech
Year dc:date.issued
2023

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Nwodo, Kenechukwu Anthony
Chair dc:contributor.committeechair
  • Stavrou, Angelos
Committee members dc:contributor.committeemember
  • Wang, Haining
  • Ampadu, Paul K.

Subjects

dc:subject × 3

Rights

dc:rights
Statement dc:rights
  • In Copyright
Language dc:language.iso
en

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10919/141648
OAI identifier oai:identifier
oai:vtechworks.lib.vt.edu:10919/141648

Chain of custody

source
Harvested from
Virginia Tech
Base URL
vtechworks.lib.vt.edu/oai/request
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Nwodo, Kenechukwu Anthony. Towards Accurate and Reliable Industrial Intrusion Detection Systems Using Shadow Replicas. masters thesis, Virginia Tech, 2023. https://hdl.handle.net/10919/141648