120 The State of the Art in Intrusion Prevention and Detection
detection. Numerous intrusion detection methods have been presented [15] and some of them have
been applied into SCADA systems [16–21]. However, research in a cross-disciplinary context, espe-
cially for critical infrastructure system network operation, is still at an early stage and immature.
Early IDS models were limited in capability and designed to monitor a single host only. However,
more recent models accommodate the monitoring of a number of hosts interconnected by a network.
Another main issue is on the difculty of developing IDS rules for recognizing attacks. It is not a
trivial task as it requires knowledge of the vulnerabilities in the various protocols. This knowledge ...