A performance overview of machine learning-based defense strategies for advanced persistent threats in industrial control systems

被引:13
|
作者
Imran, Muhammad [1 ]
Siddiqui, Hafeez Ur Rehman [1 ]
Raza, Ali [1 ]
Raza, Muhammad Amjad [1 ]
Rustam, Furqan [2 ]
Ashraf, Imran [3 ]
机构
[1] Khwaja Fareed Univ Engn & Informat Technol, Fac Comp Sci & Informat Technol, Rahim Yar Khan 64200, Pakistan
[2] Univ Coll Dublin, Sch Comp Sci, Dublin D04 V1W8, Ireland
[3] Yeungnam Univ, Informat & Commun Engn, Gyeongsan 38541, Egypt
关键词
Cybersecurity; Mitre attack; Advance persistent threats; Industrial control; Machine learning; Feature engineering;
D O I
10.1016/j.cose.2023.103445
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity incident response is a very crucial part of the cybersecurity management system. Adversaries emerge and evolve with new cybersecurity tactics, techniques, and procedures (TTPs). It is essential to detect the TTPs in a timely manner to respond effectively and mitigate the vulnerabilities to secure business operations. This research focuses on TTP identification and detection based on a machine learning approach. Early identification and detection are paramount in protecting, responding to, and recovering from such adversarial attacks. Analyzing use cases is a critical tool to ensure proper and in-depth evaluation of sector-specific cybersecurity challenges. In this regard, this study investigates existing known methodologies for cyber-attacks such as Mitre attacks, and developed a method for identifying threat cases. In addition, Windows-based threat cases are implemented, comprehensive datasets are generated, and supervised machine learning models are applied to detect threats effectively and efficiently. Random forest outperforms other models with the highest accuracy of 99%. Future work can be done for generating threat cases based on multiple log sources, including network security and endpoint protection device, and achieve high accuracy by removing false positives using machine learning. Similarly, real-time threat detection is also envisioned for future work.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Machine Learning-Based Detection of Anomalies, Intrusions, and Threats in Industrial Control Systems
    Benka, Denis
    Horvath, Dusan
    Spendla, Lukas
    Gaspar, Gabriel
    Stremy, Maximilian
    IEEE ACCESS, 2025, 13 : 12502 - 12514
  • [2] Securing Industrial Control Systems: Components, Cyber Threats, and Machine Learning-Driven Defense Strategies
    Nankya, Mary
    Chataut, Robin
    Akl, Robert
    SENSORS, 2023, 23 (21)
  • [3] Machine Learning for Human-Machine Systems With Advanced Persistent Threats
    Chen, Long
    Zhang, Wei
    Song, Yanqing
    Chen, Jianguo
    IEEE TRANSACTIONS ON HUMAN-MACHINE SYSTEMS, 2024, 54 (06) : 753 - 761
  • [4] Machine Learning-based Defense Against Process-Aware Attacks on Industrial Control Systems
    Keliris, Anastasis
    Salehghaffari, Hossein
    Cairl, Brian
    Krishnamurthy, Prashanth
    Maniatakos, Michail
    Khorrami, Farshad
    PROCEEDINGS 2016 IEEE INTERNATIONAL TEST CONFERENCE (ITC), 2016,
  • [5] Mitigating Advanced Persistent Threats Using A Combined Static-Rule And Machine Learning-Based Technique
    Adelaiye, Oluwasegun
    Ajibola, Aminat
    2019 15TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTER AND COMPUTATION (ICECCO), 2019,
  • [6] Deep Reinforcement Learning-Based Adversarial Attack and Defense in Industrial Control Systems
    Kim, Mun-Suk
    MATHEMATICS, 2024, 12 (24)
  • [7] Advanced Persistent Threats and Their Defense Methods in Industrial Internet of Things: A Survey
    Gan, Chenquan
    Lin, Jiabin
    Huang, Da-Wen
    Zhu, Qingyi
    Tian, Liang
    MATHEMATICS, 2023, 11 (14)
  • [8] Detecting Cybersecurity Threats for Industrial Control Systems Using Machine Learning
    Choi, Woohyun
    Pandey, Suman
    Kim, Jongwon
    IEEE ACCESS, 2024, 12 : 153550 - 153563
  • [9] Analysis and Computation of Adaptive Defense Strategies Against Advanced Persistent Threats for Cyber-Physical Systems
    Huang, Linan
    Zhu, Quanyan
    DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2018, 2018, 11199 : 205 - 226
  • [10] The Use of Machine Learning Algorithms for Detecting Advanced Persistent Threats
    Eke, Hope Nkiruka
    Petrovski, Andrei
    Ahriz, Hatem
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS (SIN'19), 2019,