Unknown Attack Traffic Classification in SCADA Network Using Heuristic Clustering Technique

被引:10
|
作者
Sheng, Chuan [1 ,2 ,3 ]
Yao, Yu [4 ,5 ]
Li, Wenxuan [4 ,5 ]
Yang, Wei [6 ]
Liu, Ying [4 ,5 ]
机构
[1] Chinese Acad Sci, Key Lab Networked Control Syst, Shenyang 110016, Peoples R China
[2] Chinese Acad Sci, Shenyang Inst Automat, Shenyang 110016, Peoples R China
[3] Chinese Acad Sci, Inst Robot & Intelligent Mfg, Shenyang 110169, Peoples R China
[4] Northeastern Univ, Sch Comp Sci & Engn, Minist Educ, Shenyang 110169, Peoples R China
[5] Northeastern Univ, Minist Educ, Engn Res Ctr Secur Technol Complex Network Syst, Shenyang 110169, Peoples R China
[6] Northeastern Univ, Software Coll, Shenyang 110169, Peoples R China
基金
国家重点研发计划;
关键词
Attack traffic classification; heuristic clustering; SCADA network; traffic representation;
D O I
10.1109/TNSM.2023.3238402
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Attack Traffic Classification (ATC) technique is an essential tool for Industrial Control System (ICS) network security, which can be widely used in active defense, situational awareness, attack source traceback and so on. At present, the state-of-the-art ATC methods are usually based on traffic statistical features and machine learning techniques, including supervised classification methods and unsupervised clustering methods. However, it is difficult for these methods to overcome the problems of lack of attack samples and high real-time requirement in ATC in Supervisory Control and Data Acquisition (SCADA) networks. In order to address the above problems, we propose a self-growing ATC model based on a new density-based heuristic clustering method, which can continuously and automatically detect and distinguish different kinds of unknown attack traffic generated by various attack tools against SCADA networks in real time. An effective representation method of SCADA network traffic is proposed to further improve the performance of ATC. In addition, a large number of experiments are conducted on a compound dataset consisting of the SCADA network dataset, the attack tool dataset and the ICS honeypot dataset, to evaluate the proposed method. The experimental results show that the proposed method outperforms existing state-of-the-art ATC methods in the crucial situation of only normal SCADA network traffic.
引用
收藏
页码:2625 / 2638
页数:14
相关论文
共 50 条
  • [1] Unknown Malware Detection Using Network Traffic Classification
    Bekerman, Dmitri
    Shapira, Bracha
    Rokach, Lior
    Bar, Ariel
    2015 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2015, : 134 - 142
  • [2] Classification of Network Traffic Using Fuzzy Clustering for Network Security
    Fries, Terrence P.
    ADVANCES IN DATA MINING: APPLICATIONS AND THEORETICAL ASPECTS, ICDM 2017, 2017, 10357 : 278 - 285
  • [3] Mining of intrusion attack in SCADA network using clustering and genetically seeded flora-based optimal classification algorithm
    Shitharth, Shitharth
    Shaik, Masood
    Ameerjohn, Sirajudeen
    Kannan, Sangeetha
    IET INFORMATION SECURITY, 2020, 14 (01) : 1 - 11
  • [4] A Novel Framework for Network Traffic Classification using Unknown Flow Detection
    Shaikh, Zeba Atique
    Harkut, Dinesh G.
    2015 FIFTH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORK TECHNOLOGIES (CSNT2015), 2015, : 116 - 121
  • [5] Classification and Characterization of Encoded Traffic in SCADA Network using Hybrid Deep Learning Scheme
    Ahakonye, Love Allen Chijioke
    Amaizu, Gabriel Chukwunonso
    Nwakanma, Cosmas Ifeanyi
    Lee, Jae Min
    Kim, Dong-Seong
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2024, 26 (01) : 65 - 79
  • [6] Adaptive Framework for Network Traffic Classification using Dimensionality Reduction and Clustering
    Juvonen, Antti
    Sipola, Tuomo
    IV INTERNATIONAL CONGRESS ON ULTRA MODERN TELECOMMUNICATIONS AND CONTROL SYSTEMS 2012 (ICUMT), 2012, : 274 - 279
  • [7] Classification of DDoS attack traffic on SDN network environment using deep learning
    Clinton, Urikhimbam Boby
    Hoque, Nazrul
    Singh, Khumukcham Robindro
    CYBERSECURITY, 2024, 7 (01):
  • [8] Network Traffic Classification for Attack Detection Using Big Data Tools: A Review
    Al-Araji, Zaid. J.
    Ahmad, Sharifah Sakinah Syed
    Al-Salihi, Mustafa W.
    Al-Lamy, Hayder A.
    Ahmed, Mohammed
    Raad, Wisam
    Yunos, Norhazwani Md
    INTELLIGENT AND INTERACTIVE COMPUTING, 2019, 67 : 355 - 363
  • [9] Efficient Classification of Enciphered SCADA Network Traffic in Smart Factory Using Decision Tree Algorithm
    Ahakonye, Love Allen Chijioke
    Nwakanma, Cosmas Ifeanyi
    Lee, Jae-Min
    Kim, Dong-Seong
    IEEE ACCESS, 2021, 9 : 154892 - 154901
  • [10] Clustering unknown network traffic with dual-path autoencoder
    Yating Fu
    Xuan Li
    Xiaofan Li
    Shuyuan Zhao
    Fengyu Wang
    Neural Computing and Applications, 2023, 35 : 8955 - 8966