Correlation-Based Anomaly Detection in Industrial Control Systems

被引:5
|
作者
Jadidi, Zahra [1 ,2 ]
Pal, Shantanu [3 ]
Hussain, Mukhtar [1 ]
Thanh, Kien Nguyen [4 ]
机构
[1] Queensland Univ Technol, Sch Comp Sci, Brisbane, Qld 4000, Australia
[2] Griffith Univ, Sch Informat & Commun Technol, Gold Coast, Qld 4222, Australia
[3] Deakin Univ, Sch Informat Technol, Melbourne, Vic 3125, Australia
[4] Queensland Univ Technol, Sch Elect Engn & Robot, Brisbane, Qld 4000, Australia
关键词
industrial control systems; cyber attacks; anomaly detection; recurrent neural networks; correlation analysis;
D O I
10.3390/s23031561
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Industrial Control Systems (ICSs) were initially designed to be operated in an isolated network. However, recently, ICSs have been increasingly connected to the Internet to expand their capability, such as remote management. This interconnectivity of ICSs exposes them to cyber-attacks. At the same time, cyber-attacks in ICS networks are different compared to traditional Information Technology (IT) networks. Cyber attacks on ICSs usually involve a sequence of actions and a multitude of devices. However, current anomaly detection systems only focus on local analysis, which misses the correlation between devices and the progress of attacks over time. As a consequence, they lack an effective way to detect attacks at an entire network scale and predict possible future actions of an attack, which is of significant interest to security analysts to identify the weaknesses of their network and prevent similar attacks in the future. To address these two key issues, this paper presents a system-wide anomaly detection solution using recurrent neural networks combined with correlation analysis techniques. The proposed solution has a two-layer analysis. The first layer targets attack detection, and the second layer analyses the detected attack to predict the next possible attack actions. The main contribution of this paper is the proof of the concept implementation using two real-world ICS datasets, SWaT and Power System Attack. Moreover, we show that the proposed solution effectively detects anomalies and attacks on the scale of the entire ICS network.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] Unsupervised Learning Approach for Anomaly Detection in Industrial Control Systems
    Choi, Woo-Hyun
    Kim, Jongwon
    APPLIED SYSTEM INNOVATION, 2024, 7 (02)
  • [32] Research on Improvement of Anomaly Detection Performance in Industrial Control Systems
    Bae, Sungho
    Hwang, Chanwoong
    Lee, Taejin
    INFORMATION SECURITY APPLICATIONS, 2021, 13009 : 76 - 87
  • [33] State-Aware Anomaly Detection for Industrial Control Systems
    Ghaeini, Hamid Reza
    Antonioli, Daniele
    Brasser, Ferdinand
    Sadeghi, Ahmad-Reza
    Tippenhauer, Nils Ole
    33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1620 - 1628
  • [34] Machine Learning Methods for Anomaly Detection in Industrial Control Systems
    Tai, Johnathan
    Alsmadi, Izzat
    Zhang, Yunpeng
    Qiao, Fengxiang
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 2333 - 2339
  • [35] An Anomaly Detection Technique for Deception Attacks in Industrial Control Systems
    Qassim, Q. S.
    Ahmad, A. R.
    Ismail, R.
    Bakar, Abu A.
    Rahim, Abdul F.
    Mokhtar, M. Z.
    Ramli, R.
    Mohd, Yusof B.
    Mahdi, Mohammed Najah
    2019 IEEE 5TH INTL CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY) / IEEE INTL CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING (HPSC) / IEEE INTL CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2019, : 267 - 272
  • [36] Anomaly detection using invariant rules in Industrial Control Systems
    Zhu, Qilin
    Ding, Yulong
    Jiang, Jie
    Yang, Shuang-Hua
    Control Engineering Practice, 2025, 154
  • [37] A Machine Learning Approach for Anomaly Detection in Industrial Control Systems Based on Measurement Data
    Mokhtari, Sohrab
    Abbaspour, Alireza
    Yen, Kang K.
    Sargolzaei, Arman
    ELECTRONICS, 2021, 10 (04) : 1 - 13
  • [38] TABOR: A Graphical Model-based Approach for Anomaly Detection in Industrial Control Systems
    Lin, Qin
    Adepu, Sridhar
    Verwer, Sicco
    Mathur, Aditya
    PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, : 525 - 536
  • [39] Using timing-based side channels for anomaly detection in industrial control systems
    Dunlap, Stephen
    Butts, Jonathan
    Lopez, Juan
    Rice, Mason
    Mullins, Barry
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2016, 15 : 12 - 26
  • [40] Anomaly Detection based on Robust Spatial-temporal Modeling for Industrial Control Systems
    Li, Shijie
    Liu, Junjiao
    Pan, Zhiwen
    Lv, Shichao
    Si, Shuaizong
    Sun, Limin
    2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 355 - 363