FedTIU: Securing Virtualized PLCs Against DDoS Attacks Using a Federated Learning Enabled Threat Intelligence Unit

被引:3
|
作者
Verma, Priyanka [1 ]
De Leon, Miguel Ponce [2 ]
Breslin, John G. [1 ]
O'Shea, Donna [3 ]
机构
[1] Univ Galway, Data Sci Inst, Galway, Ireland
[2] VMware, VMware Res, Cork, Ireland
[3] Munster Technol Univ, Dept Comp Sci, Cork, Ireland
关键词
IIoT; Industry; 4.0; Federated Learning; DDoS Detection; vPLC;
D O I
10.1109/SMARTCOMP58114.2023.00058
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Conventional Programmable Logic Controller (PLC) systems are becoming increasingly challenging to manage due to hardware and software dependencies. Moreover, the number and size of conventional PLCs on factory floors continue to increase, and virtualized PLC (vPLC) offers a solution to address these challenges. The utilization of vPLC offers the advantages of streamlining communication between high-level applications and low-level machine operations, enhancing programming ability in process control systems by abstracting control functions from I/O modules, and increasing automation in industrial control networks. Nevertheless, the connection of vPLC to the internet and cloud services presents a considerable cybersecurity risk, and the crucial aspect of information security for vPLCs is ensuring their availability. Distributed Denial of Service (DDoS) attacks can be particularly devastating for vPLCs, as they rely on internet connectivity to function. DDoS attacks on vPLC overwhelm it and causing it to become unavailable. vPLCs manages control systems and if targeted by a DDoS attack, these systems could become unresponsive, leading to significant disruption to industrial processes. Thus, implementing effective DDoS protection measures is crucial for ensuring the availability and reliability of vPLCs in industrial settings. Therefore, this work proposes a Federated learning enabled Threat Intelligence Unit (FedTIU) for detecting DDoS attacks on vPLCs on an Edge Compute Stack near to vPLC. The proposed approach involves collaborative model training using federated learning techniques to gain knowledge of new attack patterns from other industrial sites while maintaining data privacy.
引用
收藏
页码:233 / 236
页数:4
相关论文
共 25 条