Anomaly Detection in Communication Networks of Cyber-physical Systems using Cross-over Data Compression

被引:1
|
作者
Schoelnast, Hubert [1 ]
Tavolato, Paul [1 ]
Kreimel, Philipp [2 ]
机构
[1] St Pollen UAS, Inst IT Secur Res, Matthias Corvinus Str 15, St Pollen, Austria
[2] Limes Secur GmbH, Hagenberg, Austria
关键词
Anomaly Detection; Industrial Security; Substation Security; Cross-over Data Compression CDC; INFORMATION;
D O I
10.5220/0008964104980505
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Anomaly detection in operational communication data of cyber-physical systems is an important part of any monitoring activity in such systems. This paper suggests a new method of anomaly detection named crossover data compression (CDC). The method belongs to the group of information theoretic approaches and is based on the notion of Kullback-Leibler Divergence. Data blocks are compressed by a Sequitur-like algorithm and the resulting grammars describing the compression are applied cross-over to the all the other data blocks. Divergences are calculated from the length of the different compressions and the mean values of these divergences are used to classify the data in normal and anomalous. The paper describes the method in detail and shows the results derived from a real-world example (communication data from a substation).
引用
收藏
页码:498 / 505
页数:8
相关论文
共 50 条
  • [1] Communication Anomaly Detection in Cyber-physical Systems
    Blazek, P.
    Fujdiak, R.
    Hodon, M.
    Zolotova, I
    Mlynek, P.
    Misurec, J.
    [J]. SENSORS AND ELECTRONIC INSTRUMENTATION ADVANCES (SEIA' 19), 2019, : 311 - 316
  • [2] ANOMALY DETECTION FOR CYBER-PHYSICAL SYSTEMS USING TRANSFORMERS
    Ma, Yuliang
    Morozov, Andrey
    Ding, Sheng
    [J]. PROCEEDINGS OF ASME 2021 INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION (IMECE2021), VOL 13, 2021,
  • [3] SCALABLE ANOMALY DETECTION AND ISOLATION IN CYBER-PHYSICAL SYSTEMS USING BAYESIAN NETWORKS
    Krishnamurthy, Sudha
    Sarkar, Soumik
    Tewari, Ashutosh
    [J]. 7TH ANNUAL DYNAMIC SYSTEMS AND CONTROL CONFERENCE, 2014, VOL 2, 2014,
  • [4] Multipath neural networks for anomaly detection in cyber-physical systems
    Raphaël M. J. I. Larsen
    Marc-Oliver Pahl
    Gouenou Coatrieux
    [J]. Annals of Telecommunications, 2023, 78 : 149 - 167
  • [5] Multipath neural networks for anomaly detection in cyber-physical systems
    Larsen, Raphael M. J., I
    Pahl, Marc-Oliver
    Coatrieux, Gouenou
    [J]. ANNALS OF TELECOMMUNICATIONS, 2023, 78 (3-4) : 149 - 167
  • [6] Cross-Layer Anomaly Detection in Industrial Cyber-Physical Systems
    Sandor, Hunor
    Genge, Bela
    Haller, Piroska
    Duka, Adrian-Vasile
    Crainicu, Bogdan
    [J]. 2017 25TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2017, : 276 - 280
  • [7] Using Ensemble Learning for Anomaly Detection in Cyber-Physical Systems
    Jeffrey, Nicholas
    Tan, Qing
    Villar, Jose R.
    [J]. ELECTRONICS, 2024, 13 (07)
  • [8] Data-driven anomaly detection in cyber-physical production systems
    Niggemann, Oliver
    Frey, Christian
    [J]. AT-AUTOMATISIERUNGSTECHNIK, 2015, 63 (10) : 821 - 832
  • [9] Deep-RBF Networks for Anomaly Detection in Automotive Cyber-Physical Systems
    Burruss, Matthew
    Ramakrishna, Shreyas
    Dubey, Abhishek
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON SMART COMPUTING (SMARTCOMP 2021), 2021, : 55 - 60
  • [10] A hybrid methodology for anomaly detection in Cyber-Physical Systems
    Jeffrey, Nicholas
    Tan, Qing
    Villar, Jose R.
    [J]. NEUROCOMPUTING, 2024, 568