Feature Engineering in Machine Learning-Based Intrusion Detection Systems for OT Networks

被引:0
|
作者
Howe, Alex [1 ]
Papa, Mauricio [1 ]
机构
[1] Univ Tulsa, Tandy Sch Comp Sci, Sch Elect & Comp Engn, Tulsa, OK 74104 USA
关键词
D O I
10.1109/SMARTCOMP58114.2023.00086
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper evaluates the importance of feature exploration and engineering when applying machine learning for intrusion detection in OT (Operational Technology) networks. Data used consisted of raw network traffic captures from a simulated OT environment communicating over the Modbus/TCP protocol. Feature engineering efforts identified thirty eight attributes of interest at the different layers of the network stack. The Random Forest algorithm was used to analyze the importance of each feature for the detection of anomalous network behavior. Both supervised and unsupervised learning methods were evaluated including Random Forest, Support Vector Machines, K-Nearest Neighbors, K-Means Clustering, and Isolation Forest. Results indicate that statistical based features as well as features derived from the protocol and application layers contained information best suited for detecting anomalous OT behavior. Additionally, variable importance-based feature selection helped reduce complexity and improved detection rate when compared with models trained on the original high dimensional data. Random Forest and Support Vector Machines had the best detection performance but required a large amount of labeled data for training and validation. Notably, Isolation Forest shows potential for anomaly detection in OT networks as it requires no labeled data and produced promising results.
引用
收藏
页码:361 / 366
页数:6
相关论文
共 50 条
  • [41] Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction
    Talukder, Md. Alamin
    Islam, Md. Manowarul
    Uddin, Md Ashraf
    Hasan, Khondokar Fida
    Sharmin, Selina
    Alyami, Salem A.
    Moni, Mohammad Ali
    JOURNAL OF BIG DATA, 2024, 11 (01)
  • [42] Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction
    Md. Alamin Talukder
    Md. Manowarul Islam
    Md Ashraf Uddin
    Khondokar Fida Hasan
    Selina Sharmin
    Salem A. Alyami
    Mohammad Ali Moni
    Journal of Big Data, 11
  • [43] Machine Learning-Based Intrusion Detection for Swarm of Unmanned Aerial Vehicles
    Mughal, Umair Ahmad
    Hassler, Samuel Chase
    Ismail, Muhammad
    2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS, 2023,
  • [44] Machine Learning-based Intrusion Detection for Smart Grid Computing: A Survey
    Sahani, Nitasha
    Zhu, Ruoxi
    Cho, Jin-Hee
    Liu, Chen-Ching
    ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2023, 7 (02)
  • [45] A machine learning-based lightweight intrusion detection system for the internet of things
    Fenanir S.
    Semchedine F.
    Baadache A.
    Revue d'Intelligence Artificielle, 2019, 33 (03): : 203 - 211
  • [46] Machine Learning-based Intrusion Detection for IoT Devices in Smart Home
    Li, Taotao
    Hong, Zhen
    Yu, Li
    2020 IEEE 16TH INTERNATIONAL CONFERENCE ON CONTROL & AUTOMATION (ICCA), 2020, : 277 - 282
  • [47] Deep Learning-Based Intrusion Detection Systems: A Systematic Review
    Lansky, Jan
    Ali, Saqib
    Mohammadi, Mokhtar
    Majeed, Mohammed Kamal
    Karim, Sarkhel H. Taher
    Rashidi, Shima
    Hosseinzadeh, Mehdi
    Rahmani, Amir Masoud
    IEEE ACCESS, 2021, 9 : 101574 - 101599
  • [48] Machine Learning-Based Adaptive Synthetic Sampling Technique for Intrusion Detection
    Zakariah, Mohammed
    AlQahtani, Salman A. A.
    Al-Rakhami, Mabrook S. S.
    APPLIED SCIENCES-BASEL, 2023, 13 (11):
  • [49] Internet of Things: A survey on machine learning-based intrusion detection approaches
    da Costa, Kelton A. P.
    Papa, Joao P.
    Lisboa, Celso O.
    Munoz, Roberto
    de Albuquerque, Victor Hugo C.
    COMPUTER NETWORKS, 2019, 151 : 147 - 157
  • [50] Design and Performance Evaluation of a Machine Learning-Based Method for Intrusion Detection
    Zhang, Qinglei
    Hu, Gongzhu
    Feng, Wenying
    SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL-DISTRIBUTED COMPUTING 2010, 2010, 295 : 69 - +