An anomaly-based approach for cyber-physical threat detection using network and sensor data

被引:0
|
作者
Canonico, Roberto [1 ]
Esposito, Giovanni [1 ]
Navarro, Annalisa [1 ]
Romano, Simon Pietro [1 ]
Sperli, Giancarlo [1 ]
Vignali, Andrea [1 ]
机构
[1] Univ Naples Federico II, Dept Elect Engn & Informat Technol DIETI, Via Claudio 21, Naples, Italy
关键词
Threat detection; Anomaly detection; Unsupervised learning; ICS; CPS; SYSTEMS; SECURITY;
D O I
10.1016/j.comcom.2025.108087
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Integrating physical and cyber realms, Cyber-Physical Systems (CPSs) expand the potential attack surface for intruders. Given their deployment in critical infrastructures like Industrial Control Systems (ICSs), ensuring robust security is imperative. Current research has developed various Intrusion Detection techniques to identify and counter malicious activities. However, traditional methods often encounter challenges in detecting several attack types due to reliance on a single data source such as time series data from sensors and actuators. In this study, we meticulously design advanced Deep Learning (DL) anomaly-based techniques trained on either sensor/actuator data or network traffic statistics in an unsupervised setting. We evaluate these techniques on network and physical data collected concurrently from a real-world CPS. Through meticulous hyperparameter tuning, we identify the optimal parameters for each model and compare their efficiency and effectiveness in detecting different types of attacks. In addition to demonstrating superior performance compared to various baselines, we showcase the best model for each data source. Eventually, we show how utilizing diverse data sources can enhance cyber-threat detection, recognizing different kinds of attacks.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Combined Danger Signal and Anomaly-Based Threat Detection in Cyber-Physical Systems
    Degeler, Viktoriya
    French, Richard
    Jones, Kevin
    INTERNET OF THINGS: IOT INFRASTRUCTURES, PT I, 2016, 169 : 27 - 39
  • [2] Anomaly-Based Detection and Classification of Attacks in Cyber-Physical Systems
    Kreimel, Philipp
    Eigner, Oliver
    Tavolato, Paul
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017), 2017,
  • [3] Anomaly-Based Intrusion Detection System for Cyber-Physical System Security
    Colelli, Riccardo
    Magri, Filippo
    Panzieri, Stefano
    Pascucci, Federica
    2021 29TH MEDITERRANEAN CONFERENCE ON CONTROL AND AUTOMATION (MED), 2021, : 428 - 434
  • [4] Robust Multivariate Anomaly-Based Intrusion Detection System for Cyber-Physical Systems
    Dutta, Aneet Kumar
    Negi, Rohit
    Shukla, Sandeep Kumar
    CYBER SECURITY CRYPTOGRAPHY AND MACHINE LEARNING, 2021, 12716 : 86 - 93
  • [5] A Novel Anomaly Detection Method in Sensor Based Cyber-Physical Systems
    Muthulakshmi, K.
    Krishnaraj, N.
    Sankar, R. S. Ravi
    Balakumar, A.
    Kanimozhi, S.
    Kiruthika, B.
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2022, 34 (03): : 2083 - 2096
  • [6] Approach to Anomaly Detection in Cyber-Physical Object Behavior
    Shulepov, Anton
    Novikova, Evgenia
    Murenin, Ivan
    INTELLIGENT DISTRIBUTED COMPUTING XIV, 2022, 1026 : 417 - 426
  • [7] Robust Anomaly-Based Insider Threat Detection Using Graph Neural Network
    Xiao, Junchao
    Yang, Lin
    Zhong, Fuli
    Wang, Xiaolei
    Chen, Hongbo
    Li, Dongyang
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (03): : 3717 - 3733
  • [8] Cyber-physical anomaly detection for inverter-based microgrid using autoencoder neural network
    Tabassum, Tambiara
    Toker, Onur
    Khalghani, Mohammad Reza
    APPLIED ENERGY, 2024, 355
  • [9] ANOMALY DETECTION FOR CYBER-PHYSICAL SYSTEMS USING TRANSFORMERS
    Ma, Yuliang
    Morozov, Andrey
    Ding, Sheng
    PROCEEDINGS OF ASME 2021 INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION (IMECE2021), VOL 13, 2021,
  • [10] Cyber-Physical Anomaly Detection for ICS
    Wuestrich, Lars
    Schroeder, Lukas
    Pahl, Marc-Oliver
    2021 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2021), 2021, : 950 - 955