A traffic anomaly detection approach based on unsupervised learning for industrial cyber-physical system

被引:6
|
作者
Yang, Tao [1 ]
Jiang, Zhenze [2 ]
Liu, Peiyu [1 ]
Yang, Qiang [2 ]
Wang, Wenhai [1 ]
机构
[1] Zhejiang Univ, Coll Control Sci & Engn, Hangzhou 310027, Peoples R China
[2] Zhejiang Univ, Coll Elect Engn, Hangzhou 310027, Peoples R China
基金
中国国家自然科学基金;
关键词
ICPS; Payload segmentation; Traffic anomaly detection; BERT; 1D-CNN; Unsupervised learning; CLASSIFIER;
D O I
10.1016/j.knosys.2023.110949
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In Industrial Cyber-Physical Systems (ICPSs), the attacker can intrude into the cyber system through many penetration tools and attack the physical system. Payload-based traffic anomaly detection is a popular technique against these attacks. Due to the imbalanced distribution of normal and attack samples in ICPS, existing payload-based detection methods are mostly implemented based on unsupervised learning, typically comprising a word segmentation model and an unsupervised classifier. However, existing methods may disrupt semantic correlations and face challenges in extracting com-plex payload dependence relationships. To address these issues, this paper proposes a traffic anomaly detection approach, which consists of a data preprocessing model, an unsupervised word segmentation model, and an unsupervised classification model based on autoencoder. The unsupervised word segmentation model utilizes Long Short-Term Memory (LSTM) to calculate the probability of each word segmentation combination, effectively addressing the issue of inaccurate segmentation results in existing payload segmentation models. The unsupervised classification model, which combines 1D-Convolutional Neural Network (1D-CNN) and Bidirectional Encoder Representation from Transformers (BERT), addresses the challenge of extracting complex payload dependence relationships in existing classification models. The proposed detection approach is evaluated using a Cyber-Physical Attack Dataset (CPAD). Compared with the state-of-the-art detection approaches, the proposed approach has shown a significant improvement in Precision, with an increase of 18.83%. Additionally, the Recall has also been substantially enhanced, with a gain of 22.3%. Overall, the F1 has demonstrated a comprehensive improvement of 20.60%. (c) 2023 Elsevier B.V. All rights reserved.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] An Autonomous Cyber-Physical Anomaly Detection System Based on Unsupervised Disentangled Representation Learning
    Li, Chunyu
    Guo, Xiaobo
    Wang, Xiaowei
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [2] High-Performance Unsupervised Anomaly Detection for Cyber-Physical System Networks
    Schneider, Peter
    Boettinger, Konstantin
    CPS-SPC'18: PROCEEDINGS OF THE 2018 WORKSHOP ON CYBER-PHYSICAL SYSTEMS SECURITY AND PRIVACY, 2018, : 1 - 12
  • [3] Cloud-edge coordinated traffic anomaly detection for industrial cyber-physical systems
    Yang, Tao
    Hao, Weijie
    Yang, Qiang
    Wang, Wenhai
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 230
  • [4] Unsupervised Stacked Autoencoders for Anomaly Detection on Smart Cyber-physical Grids
    Al-Abassi, Abdulrahman
    Sakhnini, Jacob
    Karimipour, Hadis
    2020 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2020, : 3123 - 3129
  • [5] Approach to Anomaly Detection in Cyber-Physical Object Behavior
    Shulepov, Anton
    Novikova, Evgenia
    Murenin, Ivan
    INTELLIGENT DISTRIBUTED COMPUTING XIV, 2022, 1026 : 417 - 426
  • [6] Adaptive-Correlation-Aware Unsupervised Deep Learning for Anomaly Detection in Cyber-Physical Systems
    Xi, Liang
    Miao, Dehua
    Li, Menghan
    Wang, Ruidong
    Liu, Han
    Huang, Xunhua
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 2888 - 2899
  • [7] Deep Learning-Based Cyber-Physical Feature Fusion for Anomaly Detection in Industrial Control Systems
    Du, Yan
    Huang, Yuanyuan
    Wan, Guogen
    He, Peilin
    MATHEMATICS, 2022, 10 (22)
  • [8] Anomaly-Based Intrusion Detection System for Cyber-Physical System Security
    Colelli, Riccardo
    Magri, Filippo
    Panzieri, Stefano
    Pascucci, Federica
    2021 29TH MEDITERRANEAN CONFERENCE ON CONTROL AND AUTOMATION (MED), 2021, : 428 - 434
  • [9] Industrial Cyber-Physical System Defense Resource Allocation Using Distributed Anomaly Detection
    Hao, Weijie
    Yao, Pengchao
    Yang, Tao
    Yang, Qiang
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (22) : 22304 - 22314
  • [10] Anomaly Detection Based on Zone Partition for Security Protection of Industrial Cyber-Physical Systems
    Yang, Jun
    Zhou, Chunjie
    Yang, Shuanghua
    Xu, Haizhou
    Hu, Bowen
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2018, 65 (05) : 4257 - 4267