The Effect of Dataset Imbalance on the Performance of SCADA Intrusion Detection Systems

被引:22
|
作者
Balla, Asaad [1 ]
Habaebi, Mohamed Hadi [1 ]
Elsheikh, Elfatih A. A. [2 ]
Islam, Md. Rafiqul [1 ]
Suliman, F. M. [2 ]
机构
[1] Int Islamic Univ Malaysia, Dept Elect & Comp Engn, Kuala Lumpur 53100, Malaysia
[2] King Khalid Univ, Coll Engn, Dept Elect Engn, Abha 61421, Saudi Arabia
关键词
IDS; ICS; SCADA; imbalanced datasets; cyber security;
D O I
10.3390/s23020758
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Integrating IoT devices in SCADA systems has provided efficient and improved data collection and transmission technologies. This enhancement comes with significant security challenges, exposing traditionally isolated systems to the public internet. Effective and highly reliable security devices, such as intrusion detection system (IDSs) and intrusion prevention systems (IPS), are critical. Countless studies used deep learning algorithms to design an efficient IDS; however, the fundamental issue of imbalanced datasets was not fully addressed. In our research, we examined the impact of data imbalance on developing an effective SCADA-based IDS. To investigate the impact of various data balancing techniques, we chose two unbalanced datasets, the Morris power dataset, and CICIDS2017 dataset, including random sampling, one-sided selection (OSS), near-miss, SMOTE, and ADASYN. For binary classification, convolutional neural networks were coupled with long short-term memory (CNN-LSTM). The system's effectiveness was determined by the confusion matrix, which includes evaluation metrics, such as accuracy, precision, detection rate, and F1-score. Four experiments on the two datasets demonstrate the impact of the data imbalance. This research aims to help security researchers in understanding imbalanced datasets and their impact on DL SCADA-IDS.
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Automatic Dataset Labelling and Feature Selection for Intrusion Detection Systems
    Aparicio-Navarro, Francisco J.
    Kyriakopoulos, Konstantinos G.
    Parish, David J.
    2014 IEEE MILITARY COMMUNICATIONS CONFERENCE: AFFORDABLE MISSION SUCCESS: MEETING THE CHALLENGE (MILCOM 2014), 2014, : 46 - 51
  • [32] Machine-Learning Approach to Optimize SMOTE Ratio in Class Imbalance Dataset for Intrusion Detection
    Seo, Jae-Hyun
    Kim, Yong-Hyuk
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2018, 2018
  • [33] Performance Enhancement for Intrusion Detection Systems
    Baz, Abdullah
    Abuayeid, Samah
    Alhakami, Hosam
    Alsubait, Tahani
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2020, 20 (04): : 229 - 239
  • [34] Performance of the Network Intrusion Detection Systems
    Murthy, M. V. Ramana
    Kumar, P. Ram
    Rao, E. Devender
    Sharma, A. C.
    Rajender, S.
    Rambabu, S.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2009, 9 (10): : 198 - 202
  • [35] A Review of Research Work on Network-Based SCADA Intrusion Detection Systems
    Rakas, Slavica V. Bostjancic
    Stojanovic, Mirjana D.
    Markovic-Petrovic, Jasna D.
    IEEE ACCESS, 2020, 8 : 93083 - 93108
  • [36] Security Evaluation of Two Intrusion Detection Systems in Smart Grid SCADA Environment
    Singh, Vivek Kumar
    Ebrahem, Haythem
    Govindarasu, Manimaran
    2018 NORTH AMERICAN POWER SYMPOSIUM (NAPS), 2018,
  • [37] A Testbed for SCADA Cyber Security and Intrusion Detection
    Singh, Prateek
    Garg, Saurabh
    Kumar, Vinod
    Saquib, Zia
    2015 INTERNATIONAL CONFERENCE ON CYBER SECURITY OF SMART CITIES, INDUSTRIAL CONTROL AND COMMUNICATIONS (SSIC), 2015,
  • [38] Intrusion detection and event monitoring in SCADA networks
    Oman, Paul
    Phillips, Matthew
    CRITICAL INFRASTRUCTURE PROTE CTION, 2008, 253 : 161 - +
  • [39] Dynamic Rule Generation for SCADA Intrusion Detection
    Nivethan, Jeyasingam
    Papa, Manioc
    2016 IEEE SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2016,
  • [40] DISTRIBUTED INTRUSION DETECTION SYSTEM FOR SCADA PROTOCOLS
    Fovino, Igor Nai
    Masera, Marcelo
    Guglielmi, Michele
    Carcano, Andrea
    Trombetta, Alberto
    CRITICAL INFRASTRUCTURE PROTECTION IV, 2010, 342 : 95 - +