Machine Learning-Based Detection of Anomalies, Intrusions, and Threats in Industrial Control Systems

被引:1
|
作者
Benka, Denis [1 ]
Horvath, Dusan [2 ]
Spendla, Lukas [1 ]
Gaspar, Gabriel [1 ,3 ]
Stremy, Maximilian [2 ]
机构
[1] Slovak Univ Technol Bratislava, Inst Appl Informat Automat & Mechatron, Fac Mat Sci & Technol, Trnava 91724, Slovakia
[2] Slovak Univ Technol Bratislava, Adv Technol Res Inst, Fac Mat Sci & Technol Trnava, Trnava 91724, Slovakia
[3] Univ Zilina, Res Ctr, Zilina 01026, Slovakia
来源
IEEE ACCESS | 2025年 / 13卷
关键词
Security; Anomaly detection; Automation; Critical infrastructure; Long short term memory; Computer crime; Support vector machines; Programmable logic devices; Encryption; Authentication; intrusion detection systems; machine learning; threat detection; programmable logic controllers;
D O I
10.1109/ACCESS.2025.3530902
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) are critical to the efficient operation of essential sectors such as manufacturing, energy, and water management. However, their increasing integration with IT systems exposes them to sophisticated cyberattacks, particularly lateral attacks targeting Programmable Logic Controllers (PLCs). Advanced preventive measures are necessary because, despite their significance, many ICS continue to rely on outdated technologies with few security features. This paper proposes a machine learning (ML)-based approach to anomaly detection in ICS communication networks, focusing on techniques such as 1D Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM) networks, Support Vector Machines (SVMs), and Isolation Forest (iForest) algorithms. We generated a dataset by capturing both normal and manipulated ICS communication patterns, including TCP/IP traffic. Simulated lateral attacks provided realistic data for training and testing the ML models. The results demonstrate that the 1D CNN model achieved the highest accuracy (0.92) and F1 score (0.91) with minimal processing time, making it ideal for real-time intrusion detection. This research highlights the potential of ML techniques to fortify ICS cybersecurity and lays the groundwork for future advancements in critical infrastructure resilience.
引用
收藏
页码:12502 / 12514
页数:13
相关论文
共 50 条
  • [1] A performance overview of machine learning-based defense strategies for advanced persistent threats in industrial control systems
    Imran, Muhammad
    Siddiqui, Hafeez Ur Rehman
    Raza, Ali
    Raza, Muhammad Amjad
    Rustam, Furqan
    Ashraf, Imran
    COMPUTERS & SECURITY, 2023, 134
  • [2] A machine learning-based workflow for automatic detection of anomalies in machine tools
    Zuefle, Marwin
    Moog, Felix
    Lesch, Veronika
    Krupitzer, Christian
    Kounev, Samuel
    ISA TRANSACTIONS, 2022, 125 : 445 - 458
  • [3] Federated Learning-Based Explainable Anomaly Detection for Industrial Control Systems
    Huong, Truong Thu
    Bac, Ta Phuong
    Ha, Kieu Ngan
    Hoang, Nguyen Viet
    Hoang, Nguyen Xuan
    Hung, Nguyen Tai
    Tran, Kim Phuc
    IEEE ACCESS, 2022, 10 : 53854 - 53872
  • [4] Recent Advances in Machine Learning-based Anomaly Detection for Industrial Control Networks
    Wang, Qian
    Chen, He
    Li, Yonghui
    Vucetic, Branka
    2019 1ST INTERNATIONAL CONFERENCE ON INDUSTRIAL ARTIFICIAL INTELLIGENCE (IAI 2019), 2019,
  • [5] Detecting Cybersecurity Threats for Industrial Control Systems Using Machine Learning
    Choi, Woohyun
    Pandey, Suman
    Kim, Jongwon
    IEEE ACCESS, 2024, 12 : 153550 - 153563
  • [6] Using machine learning to detect network intrusions in industrial control systems: a survey
    Termanini, A.
    Al-Abri, D.
    Bourdoucen, H.
    Al Maashri, A.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 24 (01)
  • [7] Using machine learning to detect network intrusions in industrial control systems: a surveyUsing machine learning to detect network intrusions in industrial control systems: a surveyA. Termanini et al.
    A. Termanini
    D. Al-Abri
    H. Bourdoucen
    A. Al Maashri
    International Journal of Information Security, 2025, 24 (1)
  • [8] Reinforcement learning-based detection method for malware behavior in industrial control systems
    Gao Y.
    Wang L.-W.
    Ren W.
    Xie F.
    Mo X.-F.
    Luo X.
    Wang W.-P.
    Yang X.
    Gongcheng Kexue Xuebao/Chinese Journal of Engineering, 2020, 42 (04): : 455 - 462
  • [9] Comparative Analysis of Machine Learning-Based Algorithms for Detection of Anomalies in IIoT
    Naik, Bhupal D. S.
    Dondeti, Venkatesulu
    Balakrishna, Sivadi
    INTERNATIONAL JOURNAL OF INFORMATION RETRIEVAL RESEARCH, 2022, 12 (01)
  • [10] Survey on Machine Learning-Based Anomaly Detection for Industrial Internet
    Liu Q.
    Chen Y.
    Ni J.
    Luo C.
    Liu C.
    Cao Y.
    Tan R.
    Feng Y.
    Zhang Y.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2022, 59 (05): : 994 - 1014