本文にスキップ

SCADA Systems Integration

Overview

SCADA systems monitor and control industrial processes. KYRA MDR collects SCADA system logs and network traffic for detecting cyber threats targeting critical infrastructure.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Network access to the SCADA/OT network (read-only)
  • SCADA server with audit logging enabled
  • Network IDS sensor on the OT network segment

Configuration

Configure SCADA security monitoring:

  1. Enable SCADA server audit logging and export to syslog
  2. Deploy a passive network sensor:
collector-config.yaml
sources:
- type: scada
protocols: [modbus, dnp3, s7comm, opc-ua]
listen_interface: eth1
mode: passive
  1. Configure ICS-specific detection rules
  2. Ensure all monitoring is passive (read-only)

Collected Log Types

Log TypeDescriptionSecurity Use
Process EventsControl system state changesProcess integrity monitoring
AlarmsSCADA alarm and notification eventsOperational safety
AuthenticationOperator login eventsAccess control
ConfigurationSystem configuration changesChange management
NetworkICS protocol communicationsNetwork anomaly detection
HistorianHistorical data access eventsData integrity auditing

Troubleshooting

Passive mode only: Never deploy active scanning or inline tools on OT networks.

Protocol support: Verify the collector supports the protocols in use (Modbus, DNP3, S7comm, OPC-UA).

Air-gapped networks: Deploy a local collector with periodic secure data export.

Contact kyra@seekerslab.com for support.