Network intrusion detection system for DDoS attacks in ICS using deep autoencoders

被引:27
|
作者
Ortega-Fernandez, Ines [1 ,3 ,4 ]
Sestelo, Marta [2 ,3 ]
Burguillo, Juan C. [4 ,5 ]
Pinon-Blanco, Camilo [1 ,4 ]
机构
[1] Galician Res & Dev Ctr Adv Telecommun GRADIANT, Carretera Vilar 56-58, Vigo 36214, Spain
[2] Univ Vigo, Dept Stat & OR, SiDOR Res Grp, Vigo 36310, Spain
[3] CITMAga, Santiago De Compostela 15782, Spain
[4] Univ Vigo, Escola Enxenaria Telecomunicac, Vigo 36310, Spain
[5] Univ Vigo, atlanTTic Res Ctr, Vigo 36310, Spain
关键词
Network intrusion detection system; Anomaly detection; Industrial control systems; Cyber-physical systems; Industrial cybersecurity; Deep autoencoder;
D O I
10.1007/s11276-022-03214-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection in industrial control and cyber-physical systems has gained much attention over the past years due to the increasing modernisation and exposure of industrial environments. Current dangers to the connected industry include the theft of industrial intellectual property, denial of service, or the compromise of cloud components; all of which might result in a cyber-attack across the operational network. However, most scientific work employs device logs, which necessitate substantial understanding and preprocessing before they can be used in anomaly detection. In this paper, we propose a network intrusion detection system (NIDS) architecture based on a deep autoencoder trained on network flow data, which has the advantage of not requiring prior knowledge of the network topology or its underlying architecture. Experimental results show that the proposed model can detect anomalies, caused by distributed denial of service attacks, providing a high detection rate and low false alarms, outperforming the state-of-the-art and a baseline model in an unsupervised learning environment. Furthermore, the deep autoencoder model can detect abnormal behaviour in legitimate devices after an attack. We also demonstrate the suitability of the proposed NIDS in a real industrial plant from the alimentary sector, analysing the false positive rate and the viability of the data generation, filtering and preprocessing procedure for a near real time scenario. The suggested NIDS architecture is a low-cost solution that uses only fifteen network-based features, requires minimal processing, operates in unsupervised mode, and is straightforward to deploy in real-world scenarios.
引用
收藏
页码:5059 / 5075
页数:17
相关论文
共 50 条
  • [1] Hybrid Intrusion Detection System for DDoS Attacks
    Cepheli, Ozge
    Buyukcorak, Saliha
    Kurt, Gunes Karabulut
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2016, 2016
  • [2] Deep network approach with stacked sparse autoencoders in detection of DDoS attacks on SDN-based VANET
    Polat, Huseyin
    Turkoglu, Muammer
    Polat, Onur
    IET COMMUNICATIONS, 2020, 14 (22) : 4089 - 4100
  • [3] Detecting DoS and DDoS Attacks by using an Intrusion Detection and Remote Prevention System
    Leu, Fang-Yie
    Li, Zhi-Yang
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 251 - 254
  • [4] A Network Intrusion Detection System using Deep Learning against MQTT Attacks in IoT
    Mosaiyebzadeh, Fatemeh
    Araujo Rodriguez, Luis Gustavo
    Batista, Daniel Macedo
    Hirata Jr, R.
    2021 IEEE LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS (LATINCOM 2021), 2021,
  • [5] Intrusion Detection System Model Implementation against DDOS attacks
    Nenova, Maria
    Atanasov, Denis
    Kassev, Kiril
    Nenov, Andon
    2019 IEEE INTERNATIONAL CONFERENCE ON MICROWAVES, ANTENNAS, COMMUNICATIONS AND ELECTRONIC SYSTEMS (COMCAS), 2019,
  • [6] Unsupervised learning approach for network intrusion detection system using autoencoders
    Hyunseung Choi
    Mintae Kim
    Gyubok Lee
    Wooju Kim
    The Journal of Supercomputing, 2019, 75 : 5597 - 5621
  • [7] Study of Intrusion Detection System for DDoS Attacks in Cloud Computing
    Kumar, Naresh
    Sharma, Shalini
    2013 TENTH INTERNATIONAL CONFERENCE ON WIRELESS AND OPTICAL COMMUNICATIONS NETWORKS (WOCN), 2013,
  • [8] An Intrusion Detection System Against DDoS Attacks in IoT Networks
    Roopak, Monika
    Tian, Gui Yun
    Chambers, Jonathon
    2020 10TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2020, : 562 - 567
  • [9] Unsupervised learning approach for network intrusion detection system using autoencoders
    Choi, Hyunseung
    Kim, Mintae
    Lee, Gyubok
    Kim, Wooju
    JOURNAL OF SUPERCOMPUTING, 2019, 75 (09): : 5597 - 5621
  • [10] Designing Ensemble Deep Learning Intrusion Detection System for DDoS attacks in Software Defined Networks
    Mbasuva, Uakomba
    Zodi, Guy-Alain Lusilao
    PROCEEDINGS OF THE 2022 16TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2022), 2022,