A traffic anomaly detection approach based on unsupervised learning for industrial cyber-physical system

被引:6
|
作者
Yang, Tao [1 ]
Jiang, Zhenze [2 ]
Liu, Peiyu [1 ]
Yang, Qiang [2 ]
Wang, Wenhai [1 ]
机构
[1] Zhejiang Univ, Coll Control Sci & Engn, Hangzhou 310027, Peoples R China
[2] Zhejiang Univ, Coll Elect Engn, Hangzhou 310027, Peoples R China
基金
中国国家自然科学基金;
关键词
ICPS; Payload segmentation; Traffic anomaly detection; BERT; 1D-CNN; Unsupervised learning; CLASSIFIER;
D O I
10.1016/j.knosys.2023.110949
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In Industrial Cyber-Physical Systems (ICPSs), the attacker can intrude into the cyber system through many penetration tools and attack the physical system. Payload-based traffic anomaly detection is a popular technique against these attacks. Due to the imbalanced distribution of normal and attack samples in ICPS, existing payload-based detection methods are mostly implemented based on unsupervised learning, typically comprising a word segmentation model and an unsupervised classifier. However, existing methods may disrupt semantic correlations and face challenges in extracting com-plex payload dependence relationships. To address these issues, this paper proposes a traffic anomaly detection approach, which consists of a data preprocessing model, an unsupervised word segmentation model, and an unsupervised classification model based on autoencoder. The unsupervised word segmentation model utilizes Long Short-Term Memory (LSTM) to calculate the probability of each word segmentation combination, effectively addressing the issue of inaccurate segmentation results in existing payload segmentation models. The unsupervised classification model, which combines 1D-Convolutional Neural Network (1D-CNN) and Bidirectional Encoder Representation from Transformers (BERT), addresses the challenge of extracting complex payload dependence relationships in existing classification models. The proposed detection approach is evaluated using a Cyber-Physical Attack Dataset (CPAD). Compared with the state-of-the-art detection approaches, the proposed approach has shown a significant improvement in Precision, with an increase of 18.83%. Additionally, the Recall has also been substantially enhanced, with a gain of 22.3%. Overall, the F1 has demonstrated a comprehensive improvement of 20.60%. (c) 2023 Elsevier B.V. All rights reserved.
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Anomaly Detection in Cyber-Physical System using Logistic Regression Analysis
    Noureen, Subrina Sultana
    Bayne, Stephen B.
    Shaffer, Edward
    Porschet, Donald
    Berman, Morris
    2019 IEEE TEXAS POWER AND ENERGY CONFERENCE (TPEC), 2019,
  • [32] Behavior Analysis and Anomaly Detection for a Digital Substation on Cyber-Physical System
    Kwon, Yoojin
    Lee, Sang Youm
    King, Ralph
    Lim, Jong In
    Kim, Huy Kang
    ELECTRONICS, 2019, 8 (03):
  • [33] Unsupervised Learning Approach for Anomaly Detection in Industrial Control Systems
    Choi, Woo-Hyun
    Kim, Jongwon
    APPLIED SYSTEM INNOVATION, 2024, 7 (02)
  • [34] Aquila Optimization with Machine Learning-Based Anomaly Detection Technique in Cyber-Physical Systems
    Ramachandran A.
    Gayathri K.
    Alkhayyat A.
    Malik R.Q.
    Computer Systems Science and Engineering, 2023, 46 (02): : 2177 - 2194
  • [35] Meta-Learning to Improve Unsupervised Intrusion Detection in Cyber-Physical Systems
    Zoppi, Tommaso
    Gharib, Mohamad
    Atif, Muhammad
    Bondavalli, Andrea
    ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2021, 5 (04)
  • [36] Explainable Unsupervised Machine Learning for Cyber-Physical Systems
    Wickramasinghe, Chathurika S.
    Amarasinghe, Kasun
    Marino, Daniel L.
    Rieger, Craig
    Manic, Milos
    IEEE ACCESS, 2021, 9 : 131824 - 131843
  • [37] An anomaly-based approach for cyber-physical threat detection using network and sensor data
    Canonico, Roberto
    Esposito, Giovanni
    Navarro, Annalisa
    Romano, Simon Pietro
    Sperli, Giancarlo
    Vignali, Andrea
    COMPUTER COMMUNICATIONS, 2025, 234
  • [38] Lattice hydrodynamic model based traffic control: A transportation cyber-physical system approach
    Liu, Hui
    Sun, Dihua
    Liu, Weining
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2016, 461 : 795 - 801
  • [39] Hybrid Statistical-Machine Learning for Real-Time Anomaly Detection in Industrial Cyber-Physical Systems
    Hao, Weijie
    Yang, Tao
    Yang, Qiang
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2023, 20 (01) : 32 - 46
  • [40] Unsupervised and incremental learning orchestration for cyber-physical security
    Reis, Lucio Henrik A.
    Murillo Piedrahita, Andres
    Rueda, Sandra
    Fernandes, Natalia C.
    Medeiros, Dianne S., V
    de Amorim, Marcelo Dias
    Mattos, Diogo M. F.
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2020, 31 (07)