Anomaly detection using invariant rules in Industrial Control Systems

被引:0
|
作者
Zhu, Qilin [1 ,2 ]
Ding, Yulong [1 ,2 ]
Jiang, Jie [3 ]
Yang, Shuang-Hua [1 ,4 ]
机构
[1] Southern Univ Sci & Technol, Shenzhen Key Lab Safety & Secur Next Generat Ind I, Shenzhen 518055, Peoples R China
[2] Southern Univ Sci & Technol, Dept Comp Sci & Engn, Shenzhen 518055, Peoples R China
[3] Univ Petr Beijing, Coll Artificial Intelligence, Beijing 102249, Peoples R China
[4] Univ Reading, Dept Comp Sci, Reading RG6 6UR, England
基金
中国国家自然科学基金;
关键词
Industrial Control System; Anomaly detection; Invariant rule; Association rule mining; ALGORITHM;
D O I
10.1016/j.conengprac.2024.106164
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) are intelligent control systems that integrate computing, physical processes, and communication to manage critical infrastructures such as power grids, oil and gas processing facilities, and water treatment plants. In recent years, ICS have been increasingly targeted by malicious attacks, causing severe consequences. Anomaly detection systems utilized in ICS are crucial in safeguarding ICS from potential threats by sending out an alert upon detecting any network attacks. However, existing methods for ICS anomaly detection often suffer from limitations. Supervised machine learning methods encounter the issue of imbalanced positive and negative samples, while residual-based anomaly detection methods face challenges in detecting stealthy attacks. This paper presents an unsupervised anomaly detection method for ICS using association rule mining techniques. Utilizing the proposed variation-driven predicate generation strategy, the method incorporates temporal features of sensor readings into the generated predicates, achieving the mining of invariant rules that take into account the temporal dependencies among physical variables. This approach allows for a more comprehensive exploration of the invariant patterns maintained in the dynamic processes of systems. Through experiments conducted on two public datasets, the method demonstrates high detection efficiency, meeting the real-time demands of online detection. Experimental results showcase its notable efficacy in anomaly detection, with a substantial enhancement in the recall rate. Furthermore, the method's capability to promptly issue warnings enables it to detect multiple attacks with low latency.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Anomaly detection for industrial control systems using process mining
    Myers, David
    Suriadi, Suriadi
    Radke, Kenneth
    Foo, Ernest
    COMPUTERS & SECURITY, 2018, 78 : 103 - 125
  • [2] Leveraging Swarm Intelligence for Invariant Rule Generation and Anomaly Detection in Industrial Control Systems
    Song, Yunkai
    Huang, Huihui
    Wang, Hongmin
    Wei, Qiang
    APPLIED SCIENCES-BASEL, 2024, 14 (22):
  • [3] Anomaly Detection Dataset for Industrial Control Systems
    Dehlaghi-Ghadim, Alireza
    Moghadam, Mahshid Helali
    Balador, Ali
    Hansson, Hans
    IEEE ACCESS, 2023, 11 : 107982 - 107996
  • [4] Anomaly detection in Industrial Control Systems using Logical Analysis of Data
    Das, Tanmoy Kanti
    Adepu, Sridhar
    Zhou, Jianying
    COMPUTERS & SECURITY, 2020, 96
  • [5] A Control Flow Anomaly Detection Algorithm for Industrial Control Systems
    Zhang, Zhigang
    Chang, Chaowen
    Lv, Zhuo
    Han, Peisheng
    Wang, Yutong
    2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 286 - 293
  • [6] Attacks on Industrial Control Systems Modeling and Anomaly Detection
    Eigner, Oliver
    Kreimel, Philipp
    Tavolato, Paul
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 581 - 588
  • [7] FALCON: Framework for Anomaly Detection in Industrial Control Systems
    Sapkota, Subin
    Mehdy, A. K. M. Nuhil
    Reese, Stephen
    Mehrpouyan, Hoda
    ELECTRONICS, 2020, 9 (08) : 1 - 20
  • [8] On the Generation of Anomaly Detection Datasets in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Celdran, Alberto Huertas
    Garcia Clemente, Felix J.
    Cadenas Sarmiento, Cristian
    Del Canto Masa, Carlos Javier
    Mendez Nistal, Ruben
    IEEE ACCESS, 2019, 7 : 177460 - 177473
  • [9] MADICS: A Methodology for Anomaly Detection in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Huertas Celdran, Alberto
    Garcia Clemente, Felix J.
    SYMMETRY-BASEL, 2020, 12 (10):
  • [10] WaXAI: Explainable Anomaly Detection in Industrial Control Systems and Water Systems
    Mathuros, Kornkamon
    Venugopalan, Sarad
    Adepu, Sridhar
    PROCEEDINGS OF THE 10TH ACM CYBER-PHYSICAL SYSTEM SECURITY WORKSHOP, ACM CPSS 2024, 2024, : 3 - 15