A traffic anomaly detection approach based on unsupervised learning for industrial cyber-physical system

被引:6
|
作者
Yang, Tao [1 ]
Jiang, Zhenze [2 ]
Liu, Peiyu [1 ]
Yang, Qiang [2 ]
Wang, Wenhai [1 ]
机构
[1] Zhejiang Univ, Coll Control Sci & Engn, Hangzhou 310027, Peoples R China
[2] Zhejiang Univ, Coll Elect Engn, Hangzhou 310027, Peoples R China
基金
中国国家自然科学基金;
关键词
ICPS; Payload segmentation; Traffic anomaly detection; BERT; 1D-CNN; Unsupervised learning; CLASSIFIER;
D O I
10.1016/j.knosys.2023.110949
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In Industrial Cyber-Physical Systems (ICPSs), the attacker can intrude into the cyber system through many penetration tools and attack the physical system. Payload-based traffic anomaly detection is a popular technique against these attacks. Due to the imbalanced distribution of normal and attack samples in ICPS, existing payload-based detection methods are mostly implemented based on unsupervised learning, typically comprising a word segmentation model and an unsupervised classifier. However, existing methods may disrupt semantic correlations and face challenges in extracting com-plex payload dependence relationships. To address these issues, this paper proposes a traffic anomaly detection approach, which consists of a data preprocessing model, an unsupervised word segmentation model, and an unsupervised classification model based on autoencoder. The unsupervised word segmentation model utilizes Long Short-Term Memory (LSTM) to calculate the probability of each word segmentation combination, effectively addressing the issue of inaccurate segmentation results in existing payload segmentation models. The unsupervised classification model, which combines 1D-Convolutional Neural Network (1D-CNN) and Bidirectional Encoder Representation from Transformers (BERT), addresses the challenge of extracting complex payload dependence relationships in existing classification models. The proposed detection approach is evaluated using a Cyber-Physical Attack Dataset (CPAD). Compared with the state-of-the-art detection approaches, the proposed approach has shown a significant improvement in Precision, with an increase of 18.83%. Additionally, the Recall has also been substantially enhanced, with a gain of 22.3%. Overall, the F1 has demonstrated a comprehensive improvement of 20.60%. (c) 2023 Elsevier B.V. All rights reserved.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] Digital Twin-based Anomaly Detection with Curriculum Learning in Cyber-physical Systems
    Xu, Qinghua
    Ali, Shaukat
    Yue, Tao
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2023, 32 (05)
  • [22] Data-Correlation-Aware Unsupervised Deep-Learning Model for Anomaly Detection in Cyber-Physical Systems
    Xi, Liang
    Wang, Ruidong
    Haas, Zygmunt J.
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (22) : 22410 - 22421
  • [23] Image Processing Based Anomaly Detection Approach for Synchronous Movements in Cyber-Physical Systems
    Yetis, Hasan
    Karakose, Mehmet
    2018 23RD INTERNATIONAL SCIENTIFIC-PROFESSIONAL CONFERENCE ON INFORMATION TECHNOLOGY (IT), 2018,
  • [24] Communication Anomaly Detection in Cyber-physical Systems
    Blazek, P.
    Fujdiak, R.
    Hodon, M.
    Zolotova, I
    Mlynek, P.
    Misurec, J.
    SENSORS AND ELECTRONIC INSTRUMENTATION ADVANCES (SEIA' 19), 2019, : 311 - 316
  • [25] Anomaly Detection for Stochastic Networked Cyber-Physical Systems: a Statistical Approach
    Yan, Yamin
    Fu, Minyue
    Seron, Maria M.
    2024 IEEE 18TH INTERNATIONAL CONFERENCE ON CONTROL & AUTOMATION, ICCA 2024, 2024, : 18 - 23
  • [26] Urban traffic monitoring and control as a cyber-physical system approach
    Caramihai, Simona Iuliana
    Dumitrache, Ioan
    Advances in Intelligent Systems and Computing, 2013, 187 AISC : 355 - 366
  • [27] Robust Multivariate Anomaly-Based Intrusion Detection System for Cyber-Physical Systems
    Dutta, Aneet Kumar
    Negi, Rohit
    Shukla, Sandeep Kumar
    CYBER SECURITY CRYPTOGRAPHY AND MACHINE LEARNING, 2021, 12716 : 86 - 93
  • [28] Process-Based Anomaly Detection and Analysis for Cyber-Physical System with MQTT Protocol
    Bin Ahmadon, Mohd Anuaruddin
    Yamaguchi, Shingo
    2020 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2020, : 263 - 268
  • [29] Industrial Cyber-Physical System Evolution Detection and Alert Generation
    Iglesias, Aitziber
    Sagardui, Goiuria
    Arellano, Cristobal
    APPLIED SCIENCES-BASEL, 2019, 9 (08):
  • [30] Advanced Intrusion Detection System for Industrial Cyber-Physical Systems
    Bonagura, Valeria
    Foglietta, Chiara
    Panzieri, Stefano
    Pascucci, Federica
    IFAC PAPERSONLINE, 2022, 55 (40): : 265 - 270