A Control Flow Anomaly Detection Algorithm for Industrial Control Systems

被引:0
|
作者
Zhang, Zhigang [1 ,2 ]
Chang, Chaowen [1 ]
Lv, Zhuo [2 ]
Han, Peisheng [1 ]
Wang, Yutong [1 ]
机构
[1] Zhengzhou Inst Informat Sci & Technol, Zhengzhou, Henan, Peoples R China
[2] State Grid HENAN Elect Power Res Inst, Zhengzhou, Henan, Peoples R China
基金
国家重点研发计划;
关键词
Industrial control systems; control flow; anomaly detection; path matching; AUDIT DATA STREAMS; INTRUSION DETECTION; COMPUTER; APPS;
D O I
10.1109/ICDIS.2018.00054
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Industrial control systems are the fundamental infrastructures of a country. Since the intrusion attack methods for industrial control systems have become complex and concealed, the traditional protection methods, such as vulnerability database, virus database and rule matching cannot cope with the attacks hidden inside the terminals of industrial control systems. In this work, we propose a control flow anomaly detection algorithm based on the control flow of the business programs. First, a basic group partition method based on key paths is proposed to reduce the performance burden caused by tabbed-assert control flow analysis method through expanding basic research units. Second, the algorithm phases of standard path set acquisition and path matching are introduced. By judging whether the current control flow path is deviating from the standard set or not, the abnormal operating conditions of industrial control can be detected. Finally, the effectiveness of a control flow anomaly detection (checking) algorithm based on Path Matching (CFCPM) is demonstrated by anomaly detection ability analysis and experiments.
引用
收藏
页码:286 / 293
页数:8
相关论文
共 50 条
  • [1] Anomaly Detection Dataset for Industrial Control Systems
    Dehlaghi-Ghadim, Alireza
    Moghadam, Mahshid Helali
    Balador, Ali
    Hansson, Hans
    IEEE ACCESS, 2023, 11 : 107982 - 107996
  • [2] Attacks on Industrial Control Systems Modeling and Anomaly Detection
    Eigner, Oliver
    Kreimel, Philipp
    Tavolato, Paul
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 581 - 588
  • [3] FALCON: Framework for Anomaly Detection in Industrial Control Systems
    Sapkota, Subin
    Mehdy, A. K. M. Nuhil
    Reese, Stephen
    Mehrpouyan, Hoda
    ELECTRONICS, 2020, 9 (08) : 1 - 20
  • [4] On the Generation of Anomaly Detection Datasets in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Celdran, Alberto Huertas
    Garcia Clemente, Felix J.
    Cadenas Sarmiento, Cristian
    Del Canto Masa, Carlos Javier
    Mendez Nistal, Ruben
    IEEE ACCESS, 2019, 7 : 177460 - 177473
  • [5] MADICS: A Methodology for Anomaly Detection in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Huertas Celdran, Alberto
    Garcia Clemente, Felix J.
    SYMMETRY-BASEL, 2020, 12 (10):
  • [6] WaXAI: Explainable Anomaly Detection in Industrial Control Systems and Water Systems
    Mathuros, Kornkamon
    Venugopalan, Sarad
    Adepu, Sridhar
    PROCEEDINGS OF THE 10TH ACM CYBER-PHYSICAL SYSTEM SECURITY WORKSHOP, ACM CPSS 2024, 2024, : 3 - 15
  • [7] Anomaly Detection of Industrial Control Systems Based on Transfer Learning
    Wang, Weiping
    Wang, Zhaorong
    Zhou, Zhanfan
    Deng, Haixia
    Zhao, Weiliang
    Wang, Chunyang
    Guo, Yongzhen
    TSINGHUA SCIENCE AND TECHNOLOGY, 2021, 26 (06) : 821 - 832
  • [8] Anomaly Detection of Industrial Control Systems Based on Transfer Learning
    Weiping Wang
    Zhaorong Wang
    Zhanfan Zhou
    Haixia Deng
    Weiliang Zhao
    Chunyang Wang
    Yongzhen Guo
    Tsinghua Science and Technology, 2021, 26 (06) : 821 - 832
  • [9] Correlation-Based Anomaly Detection in Industrial Control Systems
    Jadidi, Zahra
    Pal, Shantanu
    Hussain, Mukhtar
    Thanh, Kien Nguyen
    SENSORS, 2023, 23 (03)
  • [10] Unsupervised Learning Approach for Anomaly Detection in Industrial Control Systems
    Choi, Woo-Hyun
    Kim, Jongwon
    APPLIED SYSTEM INNOVATION, 2024, 7 (02)