A performance overview of machine learning-based defense strategies for advanced persistent threats in industrial control systems

被引:13
|
作者
Imran, Muhammad [1 ]
Siddiqui, Hafeez Ur Rehman [1 ]
Raza, Ali [1 ]
Raza, Muhammad Amjad [1 ]
Rustam, Furqan [2 ]
Ashraf, Imran [3 ]
机构
[1] Khwaja Fareed Univ Engn & Informat Technol, Fac Comp Sci & Informat Technol, Rahim Yar Khan 64200, Pakistan
[2] Univ Coll Dublin, Sch Comp Sci, Dublin D04 V1W8, Ireland
[3] Yeungnam Univ, Informat & Commun Engn, Gyeongsan 38541, Egypt
关键词
Cybersecurity; Mitre attack; Advance persistent threats; Industrial control; Machine learning; Feature engineering;
D O I
10.1016/j.cose.2023.103445
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity incident response is a very crucial part of the cybersecurity management system. Adversaries emerge and evolve with new cybersecurity tactics, techniques, and procedures (TTPs). It is essential to detect the TTPs in a timely manner to respond effectively and mitigate the vulnerabilities to secure business operations. This research focuses on TTP identification and detection based on a machine learning approach. Early identification and detection are paramount in protecting, responding to, and recovering from such adversarial attacks. Analyzing use cases is a critical tool to ensure proper and in-depth evaluation of sector-specific cybersecurity challenges. In this regard, this study investigates existing known methodologies for cyber-attacks such as Mitre attacks, and developed a method for identifying threat cases. In addition, Windows-based threat cases are implemented, comprehensive datasets are generated, and supervised machine learning models are applied to detect threats effectively and efficiently. Random forest outperforms other models with the highest accuracy of 99%. Future work can be done for generating threat cases based on multiple log sources, including network security and endpoint protection device, and achieve high accuracy by removing false positives using machine learning. Similarly, real-time threat detection is also envisioned for future work.
引用
收藏
页数:12
相关论文
共 50 条
  • [41] Automated federated learning-based adversarial attack and defence in industrial control systems
    Zeng, Guo-Qiang
    Shao, Jun-Min
    Lu, Kang-Di
    Geng, Guang-Gang
    Weng, Jian
    IET CYBER-SYSTEMS AND ROBOTICS, 2024, 6 (02)
  • [42] Reinforcement learning-based detection method for malware behavior in industrial control systems
    Gao Y.
    Wang L.-W.
    Ren W.
    Xie F.
    Mo X.-F.
    Luo X.
    Wang W.-P.
    Yang X.
    Gongcheng Kexue Xuebao/Chinese Journal of Engineering, 2020, 42 (04): : 455 - 462
  • [43] Bug characterization in machine learning-based systems
    Mohammad Mehdi Morovati
    Amin Nikanjam
    Florian Tambon
    Foutse Khomh
    Zhen Ming (Jack) Jiang
    Empirical Software Engineering, 2024, 29
  • [44] Bug characterization in machine learning-based systems
    Morovati, Mohammad Mehdi
    Nikanjam, Amin
    Tambon, Florian
    Khomh, Foutse
    Jiang, Zhen Ming
    EMPIRICAL SOFTWARE ENGINEERING, 2024, 29 (01)
  • [45] Defense Strategies for Epidemic Cyber Security Threats: Modeling and Analysis by Using a Machine Learning Approach
    Sulaiman, Muhammad
    Waseem, Muhammad
    Ali, Addisu Negash
    Laouini, Ghaylen
    Alshammari, Fahad Sameer
    IEEE ACCESS, 2024, 12 : 4958 - 4984
  • [46] Learning-Based Control Strategies for Soft Robots
    Laschi, Cecilia
    Thuruthel, Thomas George
    Lida, Fumiya
    Merzouki, Rochdi
    Falotico, Egidio
    IEEE CONTROL SYSTEMS MAGAZINE, 2023, 43 (03): : 100 - 113
  • [47] Machine Learning-based Irrigation Control Optimization
    Murthy, Akshay
    Green, Curtis
    Stoleru, Radu
    Bhunia, Suman
    Swanson, Charles
    Chaspari, Theodora
    BUILDSYS'19: PROCEEDINGS OF THE 6TH ACM INTERNATIONAL CONFERENCE ON SYSTEMS FOR ENERGY-EFFICIENT BUILDINGS, CITIES, AND TRANSPORTATION, 2019, : 213 - 222
  • [48] Machine Learning-Based Turbine Vane Position Estimation for Advanced Engine Airpath Control
    Kamath, Rohith
    Venkobarao, Vivek
    Kopold, Richard
    Subramaniam, C. K.
    SAE INTERNATIONAL JOURNAL OF ENGINES, 2021, 14 (06) : 833 - 851
  • [49] A Reinforcement Learning-Based Control Approach for Unknown Nonlinear Systems with Persistent Adversarial Inputs
    Zhong, Xiangnan
    He, Haibo
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [50] Machine learning-based performance prediction for ground source heat pump systems
    Zhang, Xueyou
    Wang, Enyu
    Liu, Liansheng
    Qi, Chengying
    GEOTHERMICS, 2022, 105