Correlation-Based Anomaly Detection in Industrial Control Systems

被引:5
|
作者
Jadidi, Zahra [1 ,2 ]
Pal, Shantanu [3 ]
Hussain, Mukhtar [1 ]
Thanh, Kien Nguyen [4 ]
机构
[1] Queensland Univ Technol, Sch Comp Sci, Brisbane, Qld 4000, Australia
[2] Griffith Univ, Sch Informat & Commun Technol, Gold Coast, Qld 4222, Australia
[3] Deakin Univ, Sch Informat Technol, Melbourne, Vic 3125, Australia
[4] Queensland Univ Technol, Sch Elect Engn & Robot, Brisbane, Qld 4000, Australia
关键词
industrial control systems; cyber attacks; anomaly detection; recurrent neural networks; correlation analysis;
D O I
10.3390/s23031561
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Industrial Control Systems (ICSs) were initially designed to be operated in an isolated network. However, recently, ICSs have been increasingly connected to the Internet to expand their capability, such as remote management. This interconnectivity of ICSs exposes them to cyber-attacks. At the same time, cyber-attacks in ICS networks are different compared to traditional Information Technology (IT) networks. Cyber attacks on ICSs usually involve a sequence of actions and a multitude of devices. However, current anomaly detection systems only focus on local analysis, which misses the correlation between devices and the progress of attacks over time. As a consequence, they lack an effective way to detect attacks at an entire network scale and predict possible future actions of an attack, which is of significant interest to security analysts to identify the weaknesses of their network and prevent similar attacks in the future. To address these two key issues, this paper presents a system-wide anomaly detection solution using recurrent neural networks combined with correlation analysis techniques. The proposed solution has a two-layer analysis. The first layer targets attack detection, and the second layer analyses the detected attack to predict the next possible attack actions. The main contribution of this paper is the proof of the concept implementation using two real-world ICS datasets, SWaT and Power System Attack. Moreover, we show that the proposed solution effectively detects anomalies and attacks on the scale of the entire ICS network.
引用
下载
收藏
页数:16
相关论文
共 50 条
  • [1] An Improved Correlation-Based Anomaly Detection Approach for Condition Monitoring Data of Industrial Equipment
    Zhong, Shisheng
    Luo, Hui
    Lin, Lin
    Fu, Xuyun
    2016 IEEE INTERNATIONAL CONFERENCE ON PROGNOSTICS AND HEALTH MANAGEMENT (ICPHM), 2016,
  • [2] Advanced Correlation-Based Anomaly Detection Method for Predictive Maintenance
    Zhao, Pushe
    Kurihara, Masaru
    Tanaka, Junichi
    Noda, Tojiro
    Chikuma, Shigeyoshi
    Suzuki, Tadashi
    2017 IEEE INTERNATIONAL CONFERENCE ON PROGNOSTICS AND HEALTH MANAGEMENT (ICPHM), 2017, : 78 - 83
  • [3] Improving CAN anomaly detection with correlation-based signal clustering
    Koltai B.
    Gazdag A.
    Ács G.
    Infocommunications Journal, 2023, 15 (04): : 17 - 25
  • [4] Correlation-based Streaming Anomaly Detection in Cyber-Security
    Noble, Jordan
    Adams, Niall M.
    2016 IEEE 16TH INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW), 2016, : 311 - 318
  • [5] A Spatial Correlation-Based Anomaly Detection Method for Subsurface Modeling
    Wendi Liu
    Michael J. Pyrcz
    Mathematical Geosciences, 2021, 53 : 809 - 822
  • [6] A Spatial Correlation-Based Anomaly Detection Method for Subsurface Modeling
    Liu, Wendi
    Pyrcz, Michael J.
    MATHEMATICAL GEOSCIENCES, 2021, 53 (05) : 809 - 822
  • [7] Anomaly Detection of Industrial Control Systems Based on Transfer Learning
    Wang, Weiping
    Wang, Zhaorong
    Zhou, Zhanfan
    Deng, Haixia
    Zhao, Weiliang
    Wang, Chunyang
    Guo, Yongzhen
    TSINGHUA SCIENCE AND TECHNOLOGY, 2021, 26 (06) : 821 - 832
  • [8] Anomaly Detection of Industrial Control Systems Based on Transfer Learning
    Weiping Wang
    Zhaorong Wang
    Zhanfan Zhou
    Haixia Deng
    Weiliang Zhao
    Chunyang Wang
    Yongzhen Guo
    Tsinghua Science and Technology, 2021, 26 (06) : 821 - 832
  • [9] Correlation-based feature partition regression method for unsupervised anomaly detection
    Liu, Zhiyu
    Gao, Xin
    Jia, Xin
    Xue, Bing
    Fu, Shiyuan
    Li, Kangsheng
    Huang, Xu
    Huang, Zijian
    APPLIED INTELLIGENCE, 2022, 52 (13) : 15074 - 15090
  • [10] Anomaly Detection Dataset for Industrial Control Systems
    Dehlaghi-Ghadim, Alireza
    Moghadam, Mahshid Helali
    Balador, Ali
    Hansson, Hans
    IEEE ACCESS, 2023, 11 : 107982 - 107996