A Control Flow Anomaly Detection Algorithm for Industrial Control Systems

被引:0
|
作者
Zhang, Zhigang [1 ,2 ]
Chang, Chaowen [1 ]
Lv, Zhuo [2 ]
Han, Peisheng [1 ]
Wang, Yutong [1 ]
机构
[1] Zhengzhou Inst Informat Sci & Technol, Zhengzhou, Henan, Peoples R China
[2] State Grid HENAN Elect Power Res Inst, Zhengzhou, Henan, Peoples R China
基金
国家重点研发计划;
关键词
Industrial control systems; control flow; anomaly detection; path matching; AUDIT DATA STREAMS; INTRUSION DETECTION; COMPUTER; APPS;
D O I
10.1109/ICDIS.2018.00054
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Industrial control systems are the fundamental infrastructures of a country. Since the intrusion attack methods for industrial control systems have become complex and concealed, the traditional protection methods, such as vulnerability database, virus database and rule matching cannot cope with the attacks hidden inside the terminals of industrial control systems. In this work, we propose a control flow anomaly detection algorithm based on the control flow of the business programs. First, a basic group partition method based on key paths is proposed to reduce the performance burden caused by tabbed-assert control flow analysis method through expanding basic research units. Second, the algorithm phases of standard path set acquisition and path matching are introduced. By judging whether the current control flow path is deviating from the standard set or not, the abnormal operating conditions of industrial control can be detected. Finally, the effectiveness of a control flow anomaly detection (checking) algorithm based on Path Matching (CFCPM) is demonstrated by anomaly detection ability analysis and experiments.
引用
收藏
页码:286 / 293
页数:8
相关论文
共 50 条
  • [41] Improvement of Anomaly Detection Performance Using Packet Flow Regularity in Industrial Control Networks
    Tamura, Kensuke
    Matsuura, Kanta
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2019, E102A (01): : 65 - 73
  • [42] Automated Anomaly Detection Tool for Industrial Control System
    Varkey, Mariam
    John, Jacob
    Umadevi, K. S.
    2022 5TH IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (IEEE DSC 2022), 2022,
  • [43] Explainable Anomaly Detection for Industrial Control System Cybersecurity
    Do Thu Ha
    Nguyen Xuan Hoang
    Nguyen Viet Hoang
    Nguyen Huu Du
    Truong Thu Huong
    Kim Phuc Tran
    IFAC PAPERSONLINE, 2022, 55 (10): : 1183 - 1188
  • [44] Mining Anomaly Communication Patterns for Industrial Control Systems
    Yu, Tsung-Chiao
    Huang, Jyun-Yao
    Liao, I-En
    Kao, Kuo-Fong
    2018 AUSTRALASIAN UNIVERSITIES POWER ENGINEERING CONFERENCE (AUPEC), 2018,
  • [45] A Machine Learning Approach for Anomaly Detection in Industrial Control Systems Based on Measurement Data
    Mokhtari, Sohrab
    Abbaspour, Alireza
    Yen, Kang K.
    Sargolzaei, Arman
    ELECTRONICS, 2021, 10 (04) : 1 - 13
  • [46] Anomaly Detection for Industrial Control Systems Using K-Means and Convolutional Autoencoder
    Chang, Chun-Pi
    Hsu, Wen-Chiao
    Liao, I-En
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 136 - 141
  • [47] TABOR: A Graphical Model-based Approach for Anomaly Detection in Industrial Control Systems
    Lin, Qin
    Adepu, Sridhar
    Verwer, Sicco
    Mathur, Aditya
    PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, : 525 - 536
  • [48] Leveraging Determinism in Industrial Control Systems for Advanced Anomaly Detection and Reliable Security Configuration
    Hadeli, Hadeli
    Schierholz, Ragnar
    Braendle, Markus
    Tuduce, Cristian
    2009 IEEE CONFERENCE ON EMERGING TECHNOLOGIES & FACTORY AUTOMATION (EFTA 2009), 2009,
  • [49] Anomaly Detection for Industrial Control Systems Using Sequence-to-Sequence Neural Networks
    Kim, Jonguk
    Yun, Jeong-Han
    Kim, Hyoung Chun
    COMPUTER SECURITY, ESORICS 2019, 2020, 11980 : 3 - 18
  • [50] Discovering a data interpreted petri net model of industrial control systems for anomaly detection
    Hussain, Mukhtar
    Fidge, Colin
    Foo, Ernest
    Jadidi, Zahra
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 230