An anomaly-based approach for cyber-physical threat detection using network and sensor data

被引:0
|
作者
Canonico, Roberto [1 ]
Esposito, Giovanni [1 ]
Navarro, Annalisa [1 ]
Romano, Simon Pietro [1 ]
Sperli, Giancarlo [1 ]
Vignali, Andrea [1 ]
机构
[1] Univ Naples Federico II, Dept Elect Engn & Informat Technol DIETI, Via Claudio 21, Naples, Italy
关键词
Threat detection; Anomaly detection; Unsupervised learning; ICS; CPS; SYSTEMS; SECURITY;
D O I
10.1016/j.comcom.2025.108087
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Integrating physical and cyber realms, Cyber-Physical Systems (CPSs) expand the potential attack surface for intruders. Given their deployment in critical infrastructures like Industrial Control Systems (ICSs), ensuring robust security is imperative. Current research has developed various Intrusion Detection techniques to identify and counter malicious activities. However, traditional methods often encounter challenges in detecting several attack types due to reliance on a single data source such as time series data from sensors and actuators. In this study, we meticulously design advanced Deep Learning (DL) anomaly-based techniques trained on either sensor/actuator data or network traffic statistics in an unsupervised setting. We evaluate these techniques on network and physical data collected concurrently from a real-world CPS. Through meticulous hyperparameter tuning, we identify the optimal parameters for each model and compare their efficiency and effectiveness in detecting different types of attacks. In addition to demonstrating superior performance compared to various baselines, we showcase the best model for each data source. Eventually, we show how utilizing diverse data sources can enhance cyber-threat detection, recognizing different kinds of attacks.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] Design of an Anomaly-based Threat Detection & Explication System
    Luh, Robert
    Schrittwieser, Sebastian
    Marschalek, Stefan
    Janicke, Helge
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 397 - 402
  • [32] Anomaly Detection in Cyber-Physical System using Logistic Regression Analysis
    Noureen, Subrina Sultana
    Bayne, Stephen B.
    Shaffer, Edward
    Porschet, Donald
    Berman, Morris
    2019 IEEE TEXAS POWER AND ENERGY CONFERENCE (TPEC), 2019,
  • [33] Anomaly Proposal-based Fire Detection for Cyber-Physical Systems
    Abeyrathna, Dilanga
    Huang, Pei-Chi
    Zhong, Xin
    2019 6TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2019), 2019, : 1203 - 1207
  • [34] Digital Twin-based Anomaly Detection in Cyber-physical Systems
    Xu, Qinghua
    Ali, Shaukat
    Yue, Tao
    2021 14TH IEEE CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST 2021), 2021, : 205 - 216
  • [35] Digital Twins for Cyber-Physical Threat Detection and Response
    Eckhart, Matthias
    Ekelhart, Andreas
    Eisl, Roland
    ERCIM NEWS, 2021, (127): : 12 - 13
  • [36] Robustness Testing of Data and Knowledge Driven Anomaly Detection in Cyber-Physical Systems
    Zhou, Xugui
    Kouzel, Maxfield
    Alemzadeh, Homa
    52ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOP VOLUME (DSN-W 2022), 2022, : 44 - 51
  • [37] A hybrid methodology for anomaly detection in Cyber-Physical Systems
    Jeffrey, Nicholas
    Tan, Qing
    Villar, Jose R.
    NEUROCOMPUTING, 2024, 568
  • [38] Causality Countermeasures for Anomaly Detection in Cyber-Physical Systems
    Shi, Dawei
    Guo, Ziyang
    Johansson, Karl Henrik
    Shi, Ling
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2018, 63 (02) : 386 - 401
  • [39] Diagnosis driven Anomaly Detection for Cyber-Physical Systems
    Steude, Henrik Sebastian
    Moddemann, Lukas
    Diedrich, Alexander
    Ehrhardt, Jonas
    Niggemann, Oliver
    IFAC PAPERSONLINE, 2024, 58 (04): : 13 - 18
  • [40] Relaxation-based anomaly detection in cyber-physical systems using ensemble kalman filter
    Karimipour, Hadis
    Leung, Henry
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2020, 5 (01) : 49 - 59