Multigranularity Feature Automatic Marking-Based Deep Learning for Anomaly Detection of Industrial Control Systems

被引:1
|
作者
Du, Xinyi [1 ,2 ,3 ]
Xu, Chi [2 ,3 ]
Li, Lin [2 ]
Li, Xinchun [1 ]
机构
[1] Liaoning Tech Univ, Sch Elect & Informat Engn, Huludao 125105, Peoples R China
[2] Chinese Acad Sci, Shenyang Inst Automat, State Key Lab Robot, Shenyang 110016, Peoples R China
[3] Chinese Acad Sci, Key Lab Networked Control Syst, Shenyang 110016, Peoples R China
基金
中国国家自然科学基金;
关键词
Protocols; Feature extraction; Anomaly detection; Deep learning; Industrial control; Convolutional neural networks; Security; convolutional neural network; deep learning; feature automatic marking; feature extraction; industrial control protocol (ICP);
D O I
10.1109/OJIM.2024.3418466
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Industrial control systems are facing ever-increasing security challenges due to the large-scale access of heterogeneous devices in the open Internet environment. Existing anomaly detection methods are mainly based on the priori knowledge of industrial control protocols (ICPs) whose protocol specifications, communication mechanism, and data format are already known. However, when these knowledge are blank, namely, unknown ICPs, existing methods become powerless to detect the anomaly data. To tackle this challenge, we propose a multigranularity feature automatic marking-based deep learning method to classify unknown ICPs for anomaly detection. First, to obtain the feature sequences without priori knowledge assisting, we propose a multigranularity feature extraction algorithm to extract both byte and half-byte information by fully utilizing the intensive key information in the header field of the application layer. Then, to label the feature sequences for deep learning, we propose a feature automatic marking algorithm that utilizes the inconsistency feature sequences to dynamically update the feature sequence set. With the labeled feature sequences, we employ deep learning with 1-D convolutional neural network and gated recurrent unit to classify the unknown ICPs and realize anomaly detection. Extensive experiments on two public datasets show that both the accuracy and precision of the proposed method reach above 98.4%, which is better than the three benchmark methods.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Deep Federated Learning-Based Cyber-Attack Detection in Industrial Control Systems
    Jahromi, Amir Namavar
    Karimipour, Hadis
    Dehghantanha, Ali
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [42] Proposal of VAE-Based Deep Learning Anomaly Detection Model for Industrial Products
    Nakata, Shunta
    Kasahara, Takehiro
    Nambo, Hidetaka
    PROCEEDINGS OF THE SIXTEENTH INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND ENGINEERING MANAGEMENT - VOL 1, 2022, 144 : 336 - 349
  • [43] Anomaly Detection Algorithm of Industrial Internet of Things Data Platform Based on Deep Learning
    Li, Xing
    Xie, Chao
    Zhao, Zhijia
    Wang, Chunbao
    Yu, Huajun
    IEEE TRANSACTIONS ON GREEN COMMUNICATIONS AND NETWORKING, 2024, 8 (03): : 1037 - 1048
  • [44] Attacks on Industrial Control Systems Modeling and Anomaly Detection
    Eigner, Oliver
    Kreimel, Philipp
    Tavolato, Paul
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 581 - 588
  • [45] FALCON: Framework for Anomaly Detection in Industrial Control Systems
    Sapkota, Subin
    Mehdy, A. K. M. Nuhil
    Reese, Stephen
    Mehrpouyan, Hoda
    ELECTRONICS, 2020, 9 (08) : 1 - 20
  • [46] On the Generation of Anomaly Detection Datasets in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Celdran, Alberto Huertas
    Garcia Clemente, Felix J.
    Cadenas Sarmiento, Cristian
    Del Canto Masa, Carlos Javier
    Mendez Nistal, Ruben
    IEEE ACCESS, 2019, 7 : 177460 - 177473
  • [47] MADICS: A Methodology for Anomaly Detection in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Huertas Celdran, Alberto
    Garcia Clemente, Felix J.
    SYMMETRY-BASEL, 2020, 12 (10):
  • [48] MENDEL: Time series anomaly detection using transfer learning for industrial control systems
    Park, Jeongyong
    Kim, Bedeuro
    Kim, Hyoungshick
    2023 IEEE INTERNATIONAL CONFERENCE ON BIG DATA AND SMART COMPUTING, BIGCOMP, 2023, : 261 - 268
  • [49] Detecting cyberattacks using anomaly detection in industrial control systems: A Federated Learning approach
    Huong, Truong Thu
    Bac, Ta Phuong
    Long, Dao Minh
    Luong, Tran Duc
    Dan, Nguyen Minh
    Quang, Le Anh
    Cong, Le Thanh
    Thang, Bui Doan
    Tran, Kim Phuc
    COMPUTERS IN INDUSTRY, 2021, 132 (132)
  • [50] Assessing Anomaly-Based Intrusion Detection Configurations for Industrial Control Systems
    Gillen, Robert E.
    Carter, Jason M.
    Craig, Christopher
    Johnson, Jordan A.
    Scott, Stephen L.
    2020 21ST IEEE INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (IEEE WOWMOM 2020), 2020, : 360 - 366