Detecting Anomalies in Industrial Control Systems with LSTM Neural Networks and UEBA

被引:1
|
作者
Pinon-Blanco, Camilo [1 ]
Otero-Vazquez, Fabian [1 ]
Ortega-Fernandez, Ines [1 ,2 ]
Sestelo, Marta [2 ]
机构
[1] GRADIANT, Vigo, Spain
[2] Univ Vigo, Vigo, Spain
关键词
Anomaly Detection; Industrial Control Systems; User and Entity Behaviour Analytics; Neural Networks; LongShort Term Memory; PERFORMANCE;
D O I
10.23919/JNIC58574.2023.10205609
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increasing adoption of the Industrial Internet of Things and integration of operational technology with information technology networks have made industrial control systems (ICS) more vulnerable to cyber-attacks, which can cause severe consequences such as disruption of critical infrastructure, loss of data, and significant financial losses. To enhance the security and resilience of these systems, anomaly detection in ICS has gained significant attention in recent years. This paper introduces ongoing research focused on using Long Short-Term Memory (LSTM) neural networks for forecasting and subsequent anomaly detection over device logs. This approach involves User and Entity Behaviour Analytics (UEBA) to analyze and define entities of interest from a real industrial plant and extract a baseline behaviour model through features that are fed into the LSTM model for predicting future events and detecting anomalies. The proposed solution has the potential to provide real-time detection of cyber and physical threats, thereby enhancing the security and resilience of industrial control systems.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] LSTM Neural Networks for Detecting Anomalies Caused by Web Application Cyber Attacks
    Kotenko, Igor
    Lauta, Oleg
    Kribel, Kseniya
    Saenko, Igor
    [J]. NEW TRENDS IN INTELLIGENT SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2021, 337 : 127 - 140
  • [2] Detecting Cyber Attacks in Industrial Control Systems Using Convolutional Neural Networks
    Kravchik, Moshe
    Shabtai, Asaf
    [J]. CPS-SPC'18: PROCEEDINGS OF THE 2018 WORKSHOP ON CYBER-PHYSICAL SYSTEMS SECURITY AND PRIVACY, 2018, : 72 - 83
  • [3] Detecting Unseen Anomalies in Network Systems by Leveraging Neural Networks
    Hashemi, Mohammad J.
    Keller, Eric
    Tizpaz-Niari, Saeid
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (03): : 2515 - 2528
  • [4] DETECTING ANOMALIES IN PROCESS CONTROL NETWORKS
    Rrushi, Julian
    Kang, Kyoung-Don
    [J]. CRITICAL INFRASTRUCTURE PROTECTION III, 2009, 311 : 151 - 165
  • [5] EFFECTIVENESS OF RSOM NEURAL MODEL IN DETECTING INDUSTRIAL ANOMALIES
    Salhi M.S.
    Barhoumi E.M.
    Lachiri Z.
    [J]. Diagnostyka, 2022, 23 (01):
  • [6] Detecting Anomalies in Cyber-Physical Systems Using Graph Neural Networks
    Vasil'eva, K. V.
    Lavrova, D. S.
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2021, 55 (08) : 1051 - 1060
  • [7] Detecting Anomalies in Cyber-Physical Systems Using Graph Neural Networks
    K. V. Vasil’eva
    D. S. Lavrova
    [J]. Automatic Control and Computer Sciences, 2021, 55 : 1051 - 1060
  • [8] Graph neural networks for detecting anomalies in scientific workflows
    Jin, Hongwei
    Raghavan, Krishnan
    Papadimitriou, George
    Wang, Cong
    Mandal, Anirban
    Kiran, Mariam
    Deelman, Ewa
    Balaprakash, Prasanna
    [J]. INTERNATIONAL JOURNAL OF HIGH PERFORMANCE COMPUTING APPLICATIONS, 2023, 37 (3-4): : 394 - 411
  • [9] Assessment of the Applicability of Autoencoders in the Problem of Detecting Anomalies in the Work of Industrial Control Systems.
    Pyatnisky, Ilya A.
    Sokolov, Alexander N.
    [J]. 2020 GLOBAL SMART INDUSTRY CONFERENCE (GLOSIC), 2020, : 234 - 239
  • [10] Detecting and Diagnosing Anomalies in Cellular Networks using Random Neural Networks
    Casas, Pedro
    D'Alconzo, Alessandro
    Fiadino, Pierdomenico
    Callegari, Christian
    [J]. 2016 INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2016, : 351 - 356