Unsupervised Machine Learning for Anomaly Detection in Synchrophasor Network Traffic

被引:0
|
作者
Donner, Phillip [1 ]
Leger, Aaron St. [1 ]
Blaine, Raymond [1 ]
机构
[1] US Mil Acad, Dept Elect Engn & Comp Sci, West Point, NY 10996 USA
关键词
Anomaly Detection; Cyber Security; Industrial Control Systems; Smart Grid; Unsupervised Machine Learning;
D O I
10.1109/naps46351.2019.9000400
中图分类号
TE [石油、天然气工业]; TK [能源与动力工程];
学科分类号
0807 ; 0820 ;
摘要
In this paper, the k-means algorithm is applied to IEEE C37.118.2 synchrophasor network traffic data to model the expected packet features under normal operating conditions. Once the model is trained, anomalies in the data are introduced using packet manipulation and packet injection. Anomalies in this research are defined as any packets in the network traffic from an unknown IP address, irregularities in the byte length of the synchrophasor data, or any packet with a network latency longer than is characteristic of the network. The trained model detects these simulated anomalies by assigning each test packet to a trained cluster centroid and determining if the distortion of the test packet qualifies it as an anomaly. This paper describes the problems and opportunities that arise from smart grid technologies, why using machine learning for anomaly detection is essential in control system environments, and how the model is developed to detect anomalies.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Semi-unsupervised Machine Learning for Anomaly Detection in HTTP Traffic
    Kozik, Rafal
    Choras, Michal
    Renk, Rafal
    Holubowicz, Witold
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON COMPUTER RECOGNITION SYSTEMS, CORES 2015, 2016, 403 : 767 - 775
  • [2] An Unsupervised Deep Learning Model for Early Network Traffic Anomaly Detection
    Hwang, Ren-Hung
    Peng, Min-Chun
    Huang, Chien-Wei
    Lin, Po-Ching
    Van-Linh Nguyen
    [J]. IEEE ACCESS, 2020, 8 (08): : 30387 - 30399
  • [3] Anomaly detection in network traffic using extreme learning machine
    Imamverdiyev, Yadigar
    Sukhostat, Lyudmila
    [J]. 2016 IEEE 10TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT), 2016, : 418 - 421
  • [4] Network Traffic Anomaly Detection using Machine Learning Approaches
    Limthong, Kriangkrai
    Tawsook, Thidarat
    [J]. 2012 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2012, : 542 - 545
  • [5] Unsupervised machine learning for network-centric anomaly detection in IoT
    Bhatia, Randeep
    Benno, Steven
    Esteban, Jairo
    Lakshman, T., V
    Grogan, John
    [J]. BIG-DAMA'19: PROCEEDINGS OF THE 3RD ACM CONEXT WORKSHOP ON BIG DATA, MACHINE LEARNING AND ARTIFICIAL INTELLIGENCE FOR DATA COMMUNICATION NETWORKS, 2019, : 42 - 48
  • [6] Unsupervised network traffic anomaly detection with deep autoencoders
    Dutta, Vibekananda
    Pawlicki, Marek
    Kozik, Rafal
    Choras, Michal
    [J]. LOGIC JOURNAL OF THE IGPL, 2022, 30 (06) : 912 - 925
  • [7] Analysis of Machine Learning Application in Campus Network Traffic Anomaly Detection
    Li, Rongrong
    [J]. Applied Mathematics and Nonlinear Sciences, 2024, 9 (01)
  • [8] Comparative Analysis of Unsupervised Machine Learning Algorithms for Anomaly Detection in Network Data
    Oliveira, Junia Maisa
    Almeida, Jonatan
    Macedo, Daniel
    Nogueira, Jose Marcos
    [J]. 2023 IEEE LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS, LATINCOM, 2023,
  • [9] Unsupervised anomaly detection for network traffic using artificial immune network
    Yuanquan Shi
    Hong Shen
    [J]. Neural Computing and Applications, 2022, 34 : 13007 - 13027
  • [10] Unsupervised anomaly detection for network traffic using artificial immune network
    Shi, Yuanquan
    Shen, Hong
    [J]. NEURAL COMPUTING & APPLICATIONS, 2022, 34 (15): : 13007 - 13027