FALCON: Framework for Anomaly Detection in Industrial Control Systems

被引:9
|
作者
Sapkota, Subin [1 ]
Mehdy, A. K. M. Nuhil [1 ]
Reese, Stephen [2 ]
Mehrpouyan, Hoda [1 ]
机构
[1] Boise State Univ, Dept Comp Sci, Coll Engn, Boise, ID 83725 USA
[2] Idaho Natl Lab, Idaho Falls, ID 83401 USA
基金
美国国家科学基金会;
关键词
industrial controls systems; attack detection; neural networks;
D O I
10.3390/electronics9081192
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) are used to control physical processes in critical infrastructure. These systems are used in a wide variety of operations such as water treatment, power generation and distribution, and manufacturing. While the safety and security of these systems are of serious concern, recent reports have shown an increase in targeted attacks aimed at manipulating physical processes to cause catastrophic consequences. This trend emphasizes the need for algorithms and tools that provide resilient and smart attack detection mechanisms to protect ICS. In this paper, we propose an anomaly detection framework for ICS based on a deep neural network. The proposed methodology uses dilated convolution and long short-term memory (LSTM) layers to learn temporal as well as long term dependencies within sensor and actuator data in an ICS. The sensor/actuator data are passed through a unique feature engineering pipeline where wavelet transformation is applied to the sensor signals to extract features that are fed into the model. Additionally, this paper explores four variations of supervised deep learning models, as well as an unsupervised support vector machine (SVM) model for this problem. The proposed framework is validated on Secure Water Treatment testbed results. This framework detects more attacks in a shorter period of time than previously published methods.
引用
收藏
页码:1 / 20
页数:20
相关论文
共 50 条
  • [1] A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control Systems
    Feng, Cheng
    Palleti, Venkata Reddy
    Mathur, Aditya
    Chana, Deeph
    [J]. 26TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2019), 2019,
  • [2] AADS: A Noise-Robust Anomaly Detection Framework for Industrial Control Systems
    Abdelaty, Maged
    Doriguzzi-Corin, Roberto
    Siracusa, Domenico
    [J]. INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2019), 2020, 11999 : 53 - 70
  • [3] Anomaly Detection Dataset for Industrial Control Systems
    Dehlaghi-Ghadim, Alireza
    Moghadam, Mahshid Helali
    Balador, Ali
    Hansson, Hans
    [J]. IEEE ACCESS, 2023, 11 : 107982 - 107996
  • [4] A Control Flow Anomaly Detection Algorithm for Industrial Control Systems
    Zhang, Zhigang
    Chang, Chaowen
    Lv, Zhuo
    Han, Peisheng
    Wang, Yutong
    [J]. 2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 286 - 293
  • [5] Attacks on Industrial Control Systems Modeling and Anomaly Detection
    Eigner, Oliver
    Kreimel, Philipp
    Tavolato, Paul
    [J]. ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 581 - 588
  • [6] On the Generation of Anomaly Detection Datasets in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Celdran, Alberto Huertas
    Garcia Clemente, Felix J.
    Cadenas Sarmiento, Cristian
    Del Canto Masa, Carlos Javier
    Mendez Nistal, Ruben
    [J]. IEEE ACCESS, 2019, 7 : 177460 - 177473
  • [7] MADICS: A Methodology for Anomaly Detection in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Huertas Celdran, Alberto
    Garcia Clemente, Felix J.
    [J]. SYMMETRY-BASEL, 2020, 12 (10):
  • [8] DRACE: A Framework for Evaluating Anomaly Detectors for Industrial Control Systems
    Christian, Ivan
    Furtado, Francisco
    Mathur, Aditya P.
    [J]. PROCEEDINGS OF THE 10TH ACM CYBER-PHYSICAL SYSTEM SECURITY WORKSHOP, ACM CPSS 2024, 2024, : 77 - 87
  • [9] WaXAI: Explainable Anomaly Detection in Industrial Control Systems and Water Systems
    Mathuros, Kornkamon
    Venugopalan, Sarad
    Adepu, Sridhar
    [J]. PROCEEDINGS OF THE 10TH ACM CYBER-PHYSICAL SYSTEM SECURITY WORKSHOP, ACM CPSS 2024, 2024, : 3 - 15
  • [10] Anomaly Detection of Industrial Control Systems Based on Transfer Learning
    Wang, Weiping
    Wang, Zhaorong
    Zhou, Zhanfan
    Deng, Haixia
    Zhao, Weiliang
    Wang, Chunyang
    Guo, Yongzhen
    [J]. TSINGHUA SCIENCE AND TECHNOLOGY, 2021, 26 (06) : 821 - 832