A performance overview of machine learning-based defense strategies for advanced persistent threats in industrial control systems

被引:13
|
作者
Imran, Muhammad [1 ]
Siddiqui, Hafeez Ur Rehman [1 ]
Raza, Ali [1 ]
Raza, Muhammad Amjad [1 ]
Rustam, Furqan [2 ]
Ashraf, Imran [3 ]
机构
[1] Khwaja Fareed Univ Engn & Informat Technol, Fac Comp Sci & Informat Technol, Rahim Yar Khan 64200, Pakistan
[2] Univ Coll Dublin, Sch Comp Sci, Dublin D04 V1W8, Ireland
[3] Yeungnam Univ, Informat & Commun Engn, Gyeongsan 38541, Egypt
关键词
Cybersecurity; Mitre attack; Advance persistent threats; Industrial control; Machine learning; Feature engineering;
D O I
10.1016/j.cose.2023.103445
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity incident response is a very crucial part of the cybersecurity management system. Adversaries emerge and evolve with new cybersecurity tactics, techniques, and procedures (TTPs). It is essential to detect the TTPs in a timely manner to respond effectively and mitigate the vulnerabilities to secure business operations. This research focuses on TTP identification and detection based on a machine learning approach. Early identification and detection are paramount in protecting, responding to, and recovering from such adversarial attacks. Analyzing use cases is a critical tool to ensure proper and in-depth evaluation of sector-specific cybersecurity challenges. In this regard, this study investigates existing known methodologies for cyber-attacks such as Mitre attacks, and developed a method for identifying threat cases. In addition, Windows-based threat cases are implemented, comprehensive datasets are generated, and supervised machine learning models are applied to detect threats effectively and efficiently. Random forest outperforms other models with the highest accuracy of 99%. Future work can be done for generating threat cases based on multiple log sources, including network security and endpoint protection device, and achieve high accuracy by removing false positives using machine learning. Similarly, real-time threat detection is also envisioned for future work.
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Advanced integration strategies and machine learning-based superstructure optimization for Power-to-Methanol
    Vo, Dat-Nguyen
    Qi, Meng
    Lee, Chang-Ha
    Yin, Xunyuan
    APPLIED ENERGY, 2025, 378
  • [32] Machine Learning-Based Prediction Models for Control Traffic in SDN Systems
    Yoo, Yeonho
    Yang, Gyeongsik
    Shin, Changyong
    Lee, Junseok
    Yoo, Chuck
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (06) : 4389 - 4403
  • [33] Review on machine learning-based bioprocess optimization, monitoring, and control systems
    Mondal, Partha Pratim
    Galodha, Abhinav
    Verma, Vishal Kumar
    Singh, Vijai
    Show, Pau Loke
    Awasthi, Mukesh Kumar
    Lall, Brejesh
    Anees, Sanya
    Pollmann, Katrin
    Jain, Rohan
    BIORESOURCE TECHNOLOGY, 2023, 370
  • [34] Coordination of Lateral Vehicle Control Systems Using Learning-Based Strategies
    Nemeth, Balazs
    ENERGIES, 2021, 14 (05)
  • [35] Machine learning-based model predictive control of hybrid dynamical systems
    Hu, Cheng
    Wu, Zhe
    AICHE JOURNAL, 2023, 69 (12)
  • [36] Cybersecurity Threats Based on Machine Learning-Based Offensive Technique for Password Authentication
    Lee, Kyungroul
    Yim, Kangbin
    APPLIED SCIENCES-BASEL, 2020, 10 (04):
  • [37] Reinforcement Learning-Based Intelligent Control Strategies for Optimal Power Management in Advanced Power Distribution Systems: A Survey
    Al-Saadi, Mudhafar
    Al-Greer, Maher
    Short, Michael
    ENERGIES, 2023, 16 (04)
  • [38] MLPhishChain: a machine learning-based blockchain framework for reducing phishing threats
    Trad, Fouad
    Semaan-Nasr, Elie
    Chehab, Ali
    FRONTIERS IN BLOCKCHAIN, 2024, 7
  • [39] Machine Learning-based Classification of Online Industrial Datasets
    Faber, Rastislav
    L'ubusky, Karol
    Paulen, Radoslav
    2023 24TH INTERNATIONAL CONFERENCE ON PROCESS CONTROL, PC, 2023, : 132 - 137
  • [40] A machine learning-based visual servoing approach for fast robot control in industrial setting
    Castelli, Francesco
    Michieletto, Stefano
    Ghidoni, Stefano
    Pagello, Enrico
    INTERNATIONAL JOURNAL OF ADVANCED ROBOTIC SYSTEMS, 2017, 14 (06):