Multigranularity Feature Automatic Marking-Based Deep Learning for Anomaly Detection of Industrial Control Systems

被引:1
|
作者
Du, Xinyi [1 ,2 ,3 ]
Xu, Chi [2 ,3 ]
Li, Lin [2 ]
Li, Xinchun [1 ]
机构
[1] Liaoning Tech Univ, Sch Elect & Informat Engn, Huludao 125105, Peoples R China
[2] Chinese Acad Sci, Shenyang Inst Automat, State Key Lab Robot, Shenyang 110016, Peoples R China
[3] Chinese Acad Sci, Key Lab Networked Control Syst, Shenyang 110016, Peoples R China
基金
中国国家自然科学基金;
关键词
Protocols; Feature extraction; Anomaly detection; Deep learning; Industrial control; Convolutional neural networks; Security; convolutional neural network; deep learning; feature automatic marking; feature extraction; industrial control protocol (ICP);
D O I
10.1109/OJIM.2024.3418466
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Industrial control systems are facing ever-increasing security challenges due to the large-scale access of heterogeneous devices in the open Internet environment. Existing anomaly detection methods are mainly based on the priori knowledge of industrial control protocols (ICPs) whose protocol specifications, communication mechanism, and data format are already known. However, when these knowledge are blank, namely, unknown ICPs, existing methods become powerless to detect the anomaly data. To tackle this challenge, we propose a multigranularity feature automatic marking-based deep learning method to classify unknown ICPs for anomaly detection. First, to obtain the feature sequences without priori knowledge assisting, we propose a multigranularity feature extraction algorithm to extract both byte and half-byte information by fully utilizing the intensive key information in the header field of the application layer. Then, to label the feature sequences for deep learning, we propose a feature automatic marking algorithm that utilizes the inconsistency feature sequences to dynamically update the feature sequence set. With the labeled feature sequences, we employ deep learning with 1-D convolutional neural network and gated recurrent unit to classify the unknown ICPs and realize anomaly detection. Extensive experiments on two public datasets show that both the accuracy and precision of the proposed method reach above 98.4%, which is better than the three benchmark methods.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] SAKMR: Industrial control anomaly detection based on semi-supervised hybrid deep learning
    Shijie Tang
    Yong Ding
    Meng Zhao
    Huiyong Wang
    Peer-to-Peer Networking and Applications, 2024, 17 : 612 - 623
  • [22] SAKMR: Industrial control anomaly detection based on semi-supervised hybrid deep learning
    Tang, Shijie
    Ding, Yong
    Zhao, Meng
    Wang, Huiyong
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (02) : 612 - 623
  • [23] Correlation-Based Anomaly Detection in Industrial Control Systems
    Jadidi, Zahra
    Pal, Shantanu
    Hussain, Mukhtar
    Thanh, Kien Nguyen
    SENSORS, 2023, 23 (03)
  • [24] IMG: Deep Representation Graph Learning for Anomaly Detection in Industrial Control System
    Ge, Binbin
    Bao, Jingru
    Li, Bo
    Mou, Xudong
    Zhao, Jun
    Liu, Xudong
    JOURNAL OF SIGNAL PROCESSING SYSTEMS FOR SIGNAL IMAGE AND VIDEO TECHNOLOGY, 2024, 96 (10): : 555 - 567
  • [25] Industrial Anomaly Detection with Skip Autoencoder and Deep Feature Extractor
    Tang, Ta-Wei
    Hsu, Hakiem
    Huang, Wei-Ren
    Li, Kuan-Ming
    SENSORS, 2022, 22 (23)
  • [26] Anomaly Detection Dataset for Industrial Control Systems
    Dehlaghi-Ghadim, Alireza
    Moghadam, Mahshid Helali
    Balador, Ali
    Hansson, Hans
    IEEE ACCESS, 2023, 11 : 107982 - 107996
  • [27] A Network Traffic Intrusion Detection Method for Industrial Control Systems Based on Deep Learning
    Jin, Kai
    Zhang, Lei
    Zhang, Yujie
    Sun, Duo
    Zheng, Xiaoyuan
    ELECTRONICS, 2023, 12 (20)
  • [28] Automatic Construction of Statechart-Based Anomaly Detection Models for Multi-Threaded Industrial Control Systems
    Kleinmann, Amit
    Wool, Avishai
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2017, 8 (04)
  • [29] Data Clustering-based Anomaly Detection in Industrial Control Systems
    Kiss, Istvan
    Genge, Bela
    Haller, Piroska
    Sebestyen, Gheorghe
    2014 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTER COMMUNICATION AND PROCESSING (ICCP), 2014, : 275 - +
  • [30] ZOE: Content-based Anomaly Detection for Industrial Control Systems
    Wressnegger, Christian
    Kellner, Ansgar
    Rieck, Konrad
    2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2018, : 127 - 138