Anomaly detection using invariant rules in Industrial Control Systems

被引:0
|
作者
Zhu, Qilin [1 ,2 ]
Ding, Yulong [1 ,2 ]
Jiang, Jie [3 ]
Yang, Shuang-Hua [1 ,4 ]
机构
[1] Southern Univ Sci & Technol, Shenzhen Key Lab Safety & Secur Next Generat Ind I, Shenzhen 518055, Peoples R China
[2] Southern Univ Sci & Technol, Dept Comp Sci & Engn, Shenzhen 518055, Peoples R China
[3] Univ Petr Beijing, Coll Artificial Intelligence, Beijing 102249, Peoples R China
[4] Univ Reading, Dept Comp Sci, Reading RG6 6UR, England
基金
中国国家自然科学基金;
关键词
Industrial Control System; Anomaly detection; Invariant rule; Association rule mining; ALGORITHM;
D O I
10.1016/j.conengprac.2024.106164
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) are intelligent control systems that integrate computing, physical processes, and communication to manage critical infrastructures such as power grids, oil and gas processing facilities, and water treatment plants. In recent years, ICS have been increasingly targeted by malicious attacks, causing severe consequences. Anomaly detection systems utilized in ICS are crucial in safeguarding ICS from potential threats by sending out an alert upon detecting any network attacks. However, existing methods for ICS anomaly detection often suffer from limitations. Supervised machine learning methods encounter the issue of imbalanced positive and negative samples, while residual-based anomaly detection methods face challenges in detecting stealthy attacks. This paper presents an unsupervised anomaly detection method for ICS using association rule mining techniques. Utilizing the proposed variation-driven predicate generation strategy, the method incorporates temporal features of sensor readings into the generated predicates, achieving the mining of invariant rules that take into account the temporal dependencies among physical variables. This approach allows for a more comprehensive exploration of the invariant patterns maintained in the dynamic processes of systems. Through experiments conducted on two public datasets, the method demonstrates high detection efficiency, meeting the real-time demands of online detection. Experimental results showcase its notable efficacy in anomaly detection, with a substantial enhancement in the recall rate. Furthermore, the method's capability to promptly issue warnings enables it to detect multiple attacks with low latency.
引用
收藏
页数:13
相关论文
共 50 条
  • [41] Anomaly behavior detection and reliability assessment of control systems based on association rules
    Jie, Xinchun
    Wang, Haikuan
    Fei, Minrui
    Du, Dajun
    Sun, Qing
    Yang, T. C.
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2018, 22 : 90 - 99
  • [42] USING PHYSICAL MODELS FOR ANOMALY DETECTION IN CONTROL SYSTEMS
    Svendsen, Nils
    Wolthusen, Stephen
    CRITICAL INFRASTRUCTURE PROTECTION III, 2009, 311 : 139 - 149
  • [43] Anomaly Detection in Self-Organizing Industrial Systems Using Pathlets
    Kiermeier, Marie
    Werner, Martin
    Linnhoff-Popien, Claudia
    Sauer, Horst
    Wieghardt, Jan
    2017 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY (ICIT), 2017, : 1226 - 1231
  • [44] Assessing Anomaly-Based Intrusion Detection Configurations for Industrial Control Systems
    Gillen, Robert E.
    Carter, Jason M.
    Craig, Christopher
    Johnson, Jordan A.
    Scott, Stephen L.
    2020 21ST IEEE INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (IEEE WOWMOM 2020), 2020, : 360 - 366
  • [45] Self-similarity based network anomaly detection for industrial control systems
    Martin, Bryan
    Bollmann, Chad A.
    2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS, 2023,
  • [46] An improved autoencoder-based approach for anomaly detection in industrial control systems
    Aslam, Muhammad Muzamil
    Tufail, Ali
    De Silva, Liyanage Chandratilak
    Haji Mohd Apong, Rosyzie Anna Awg
    Namoun, Abdallah
    SYSTEMS SCIENCE & CONTROL ENGINEERING, 2024, 12 (01)
  • [47] Federated Learning-Based Explainable Anomaly Detection for Industrial Control Systems
    Huong, Truong Thu
    Bac, Ta Phuong
    Ha, Kieu Ngan
    Hoang, Nguyen Viet
    Hoang, Nguyen Xuan
    Hung, Nguyen Tai
    Tran, Kim Phuc
    IEEE ACCESS, 2022, 10 : 53854 - 53872
  • [48] Dynamic Data Abstraction-Based Anomaly Detection for Industrial Control Systems
    Cho, Jake
    Gong, Seonghyeon
    ELECTRONICS, 2024, 13 (01)
  • [49] Intrusion and anomaly detection for the next-generation of industrial automation and control systems
    Rosa, Luis
    Cruz, Tiago
    de Freitas, Miguel Borges
    Quiterio, Pedro
    Henriques, Joao
    Caldeira, Filipe
    Monteiro, Edmundo
    Simoes, Paulo
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 119 : 50 - 67
  • [50] A Comparative Study of Time Series Anomaly Detection Models for Industrial Control Systems
    Kim, Bedeuro
    Alawami, Mohsen Ali
    Kim, Eunsoo
    Oh, Sanghak
    Park, Jeongyong
    Kim, Hyoungshick
    SENSORS, 2023, 23 (03)