Skip to main content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Securing Manufacturing Industrial Control Systems: Behavioral Anomaly Detection

Published

Author(s)

Michael P. Powell, James J. McCarthy, CheeYee Tang, Keith A. Stouffer, Timothy A. Zimmerman, William C. Barker, Titilayo Ogunyale, Devin M. Wynne

Abstract

Industrial control systems (ICS) are used in many industries to monitor and control physical processes. As ICS continue to adopt commercially available information technology (IT) to promote corporate business systems' connectivity and remote access capabilities, ICS become more vulnerable to cybersecurity threats. The National Institute of Standards and Technology's (NIST's) National Cybersecurity Center of Excellence (NCCoE), in conjunction with NIST's Engineering Laboratory (EL), has demonstrated a set of behavioral anomaly detection capabilities to support cybersecurity in manufacturing organizations. These capabilities enable manufacturers to detect anomalous conditions in their operating environments to mitigate malware attacks and other threats to the integrity of critical operational data. NIST's NCCoE and EL have mapped these demonstrated capabilities to the Cybersecurity Framework and have documented how this set of standards-based controls can support many of the security requirements of manufacturers. This report documents the use of behavioral anomaly detection (BAD) capabilities in two distinct but related demonstration environments: a robotics-based manufacturing system and a process control system that resembles what is being used by chemical manufacturing industries.
Citation
NIST Interagency/Internal Report (NISTIR) - 8219
Report Number
8219

Keywords

BAD, behavioral anomaly detection, cybersecurity, Cybersecurity Framework, ICS, industrial control systems, manufacturing, process control
Created July 16, 2020