Detecting Anomalies In Industrial Control Systems
Overview
Cybersecurity skill for detecting anomalies in industrial control systems. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"detecting anomalies in industrial control systems"
"This skill covers deploying anomaly detection systems for industrial control env"
When deploying continuous monitoring for OT environments that lack intrusion detection
When building behavior-based detection to complement signature-based IDS in OT networks
When establishing baselines for deterministic SCADA communications to detect deviations
When integrating machine learning anomaly detection with OT security monitoring platforms
When investigating alerts from Nozomi Guardian or Dragos Platform that require deeper analysis
Do not use for signature-based detection of known exploits (see detecting-attacks-on-scada-systems), for IT network anomaly detection without OT protocols, or as a replacement for process safety systems (SIS).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Passive network monitoring sensors on OT network SPAN/TAP ports
- Minimum 2-4 weeks of baseline traffic capture during normal operations
- Python 3.9+ with scikit-learn, numpy, pandas for ML model training
- Process historian access for physical process correlation data
- Understanding of normal operational patterns including shift changes, batch processes, and maintenance windows
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Detection Scope — Identify the specific anomalies in industrial control systems techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.
- Collect Baseline Data — Gather historical logs and establish normal behavior patterns for anomalies in industrial control systems.
- Build Detection Queries — Write detection rules, Sigma rules, or SIEM queries targeting anomalies in industrial control systems indicators.
- Execute Hunts — Run queries against the collected data, starting with broad filters and narrowing down.
- Triage Results — Investigate alerts, filter false positives, and validate findings against known-good behavior.
- Document Findings — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.
Tools
- SIEM Platform — Central log aggregation and query execution
- Sigma Rules — Vendor-agnostic detection rule format
- MITRE ATT&CK Navigator — Technique mapping and coverage analysis
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: detecting-anomalies-in-industrial-control-systems3description: Use when this skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.4license: Apache-2.05---67# Detecting Anomalies In Industrial Control Systems89## Overview1011Cybersecurity skill for detecting anomalies in industrial control systems. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "detecting anomalies in industrial control systems"16- "This skill covers deploying anomaly detection systems for industrial control env"171819- When deploying continuous monitoring for OT environments that lack intrusion detection20- When building behavior-based detection to complement signature-based IDS in OT networks21- When establishing baselines for deterministic SCADA communications to detect deviations22- When integrating machine learning anomaly detection with OT security monitoring platforms23- When investigating alerts from Nozomi Guardian or Dragos Platform that require deeper analysis2425**Do not use** for signature-based detection of known exploits (see detecting-attacks-on-scada-systems), for IT network anomaly detection without OT protocols, or as a replacement for process safety systems (SIS).262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Passive network monitoring sensors on OT network SPAN/TAP ports38- Minimum 2-4 weeks of baseline traffic capture during normal operations39- Python 3.9+ with scikit-learn, numpy, pandas for ML model training40- Process historian access for physical process correlation data41- Understanding of normal operational patterns including shift changes, batch processes, and maintenance windows4243## Workflow4445```python46# Example: IOC detection47import re4849IOC_PATTERNS = {50 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",51 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",52 "hash_md5": r"\b[a-f0-9]{32}\b",53 "hash_sha256": r"\b[a-f0-9]{64}\b",54}5556def extract_iocs(text: str) -> dict:57 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}58```59601. **Define Detection Scope** — Identify the specific anomalies in industrial control systems techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.612. **Collect Baseline Data** — Gather historical logs and establish normal behavior patterns for anomalies in industrial control systems.623. **Build Detection Queries** — Write detection rules, Sigma rules, or SIEM queries targeting anomalies in industrial control systems indicators.634. **Execute Hunts** — Run queries against the collected data, starting with broad filters and narrowing down.645. **Triage Results** — Investigate alerts, filter false positives, and validate findings against known-good behavior.656. **Document Findings** — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.6667## Tools6869- **SIEM Platform** — Central log aggregation and query execution70- **Sigma Rules** — Vendor-agnostic detection rule format71- **MITRE ATT&CK Navigator** — Technique mapping and coverage analysis727374## Process75761. **Reconnaissance** — Gather target information, identify attack surface, enumerate services771. **Analysis/Exploitation** — Execute the technique, analyze results, document findings781. **Reporting** — Document IOCs, write findings, provide remediation recommendations7980## Verification8182- [ ] All anomalies in industrial control systems procedures executed completely and documented83- [ ] Findings validated against multiple data sources84- [ ] False positives identified and filtered85- [ ] Results documented with evidence and timestamps86- [ ] Recommendations provided with risk-based prioritization8788## Anti-Rationalization Table8990| Rationalization | Reality |91|---|---|92| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |93| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |94| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |