System-Wide Anomaly Detection of Industrial Control Systems via Deep Learning and Correlation Analysis

Author(s):  
Gordon Haylett ◽  
Zahra Jadidi ◽  
Kien Nguyen Thanh
2019 ◽  
Vol 2019 ◽  
pp. 1-11 ◽  
Author(s):  
Yingxu Lai ◽  
Jingwen Zhang ◽  
Zenghui Liu

The massive use of information technology has brought certain security risks to the industrial production process. In recent years, cyber-physical attacks against industrial control systems have occurred frequently. Anomaly detection technology is an essential technical means to ensure the safety of industrial control systems. Considering the shortcomings of traditional methods and to facilitate the timely analysis and location of anomalies, this study proposes a solution based on the deep learning method for industrial traffic anomaly detection and attack classification. We use a convolutional neural network deep learning representation model as the detection model. The original one-dimensional data are mapped using the feature mapping method to make them suitable for model processing. The deep learning method can automatically extract critical features and achieve accurate attack classification. We performed a model evaluation using real network attack data from a supervisory control and data acquisition (SCADA) system. The experimental results showed that the proposed method met the anomaly detection and attack classification needs of a SCADA system. The proposed method also promotes the application of deep learning methods in industrial anomaly detection.


Symmetry ◽  
2020 ◽  
Vol 12 (10) ◽  
pp. 1583
Author(s):  
Ángel Luis Perales Gómez ◽  
Lorenzo Fernández Maimó ◽  
Alberto Huertas Celdrán ◽  
Félix J. García Clemente

Industrial Control Systems (ICSs) are widely used in critical infrastructures to support the essential services of society. Therefore, their protection against terrorist activities, natural disasters, and cyber threats is critical. Diverse cyber attack detection systems have been proposed over the years, in which each proposal has applied different steps and methods. However, there is a significant gap in the literature regarding methodologies to detect cyber attacks in ICS scenarios. The lack of such methodologies prevents researchers from being able to accurately compare proposals and results. In this work, we present a Methodology for Anomaly Detection in Industrial Control Systems (MADICS) to detect cyber attacks in ICS scenarios, which is intended to provide a guideline for future works in the field. MADICS is based on a semi-supervised anomaly detection paradigm and makes use of deep learning algorithms to model ICS behaviors. It consists of five main steps, focused on pre-processing the dataset to be used with the machine learning and deep learning algorithms; performing feature filtering to remove those features that do not meet the requirements; feature extraction processes to obtain higher order features; selecting, fine-tuning, and training the most appropriate model; and validating the model performance. In order to validate MADICS, we used the popular Secure Water Treatment (SWaT) dataset, which was collected from a fully operational water treatment plant. The experiments demonstrate that, using MADICS, we can achieve a state-of-the-art precision of 0.984 (as well as a recall of 0.750 and F1-score of 0.851), which is above the average of other works, proving that the proposed methodology is suitable for use in real ICS scenarios.


2021 ◽  
Vol 132 ◽  
pp. 103509
Author(s):  
Truong Thu Huong ◽  
Ta Phuong Bac ◽  
Dao Minh Long ◽  
Tran Duc Luong ◽  
Nguyen Minh Dan ◽  
...  

Sign in / Sign up

Export Citation Format

Share Document