Explainable correlation-based anomaly detection for Industrial Control Systems

被引:0
|
作者
Birihanu, Ermiyas [1 ]
Lendak, Imre [1 ]
机构
[1] Eotvos Lorand Univ, Fac Informat, Data Sci & Engn Dept, Budapest, Hungary
来源
关键词
anomaly detection; correlation; explainable; Industrial Control System; root cause analysis;
D O I
10.3389/frai.2024.1508821
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Anomaly detection is vital for enhancing the safety of Industrial Control Systems (ICS). However, the complicated structure of ICS creates complex temporal correlations among devices with many parameters. Current methods often ignore these correlations and poorly select parameters, missing valuable insights. Additionally, they lack interpretability, operating efficiently with limited resources, and root cause identification. This study proposes an explainable correlation-based anomaly detection method for ICS. The optimal window size of the data is determined using Long Short-Term Memory Networks-Autoencoder (LSTM-AE) and the correlation parameter set is extracted using the Pearson correlation. A Latent Correlation Matrix (LCM) is created from the correlation parameter set and a Latent Correlation Vector (LCV) is derived from LCM. Based on the LCV, the method utilizes a Multivariate Gaussian Distribution (MGD) to identify anomalies. This is achieved through an anomaly detection module that incorporates a threshold mechanism, utilizing alpha and epsilon values. The proposed method utilizes a novel set of input features extracted using the Shapley Additive explanation (SHAP) framework to train and evaluate the MGD model. The method is evaluated on the Secure Water Treatment (SWaT), Hardware-in-the-loop-based augmented ICS security (HIL-HAI), and Internet of Things Modbus dataset using precision, recall, and F-1 score metrics. Additionally, SHAP is used to gain insights into the anomalies and identify their root causes. Comparative experiments demonstrate the method's effectiveness, achieving a better 0.96% precision and 0.84% F1-score. This enhanced performance aids ICS engineers and decision-makers in identifying the root causes of anomalies. Our code is publicly available at a GitHub repository: https://github.com/Ermiyas21/Explainable-correlation-AD.
引用
收藏
页数:14
相关论文
共 50 条
  • [21] Anomaly Detection Approach in Industrial Control Systems Based on Measurement Data
    Zhao, Xiaosong
    Zhang, Lei
    Cao, Yixin
    Jin, Kai
    Hou, Yupeng
    INFORMATION, 2022, 13 (10)
  • [22] A Survey on Explainable Anomaly Detection for Industrial Internet of Things
    Huang, Zijie
    Wu, Yulei
    2022 5TH IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (IEEE DSC 2022), 2022,
  • [23] A Control Flow Anomaly Detection Algorithm for Industrial Control Systems
    Zhang, Zhigang
    Chang, Chaowen
    Lv, Zhuo
    Han, Peisheng
    Wang, Yutong
    2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 286 - 293
  • [24] Attacks on Industrial Control Systems Modeling and Anomaly Detection
    Eigner, Oliver
    Kreimel, Philipp
    Tavolato, Paul
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 581 - 588
  • [25] FALCON: Framework for Anomaly Detection in Industrial Control Systems
    Sapkota, Subin
    Mehdy, A. K. M. Nuhil
    Reese, Stephen
    Mehrpouyan, Hoda
    ELECTRONICS, 2020, 9 (08) : 1 - 20
  • [26] On the Generation of Anomaly Detection Datasets in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Celdran, Alberto Huertas
    Garcia Clemente, Felix J.
    Cadenas Sarmiento, Cristian
    Del Canto Masa, Carlos Javier
    Mendez Nistal, Ruben
    IEEE ACCESS, 2019, 7 : 177460 - 177473
  • [27] MADICS: A Methodology for Anomaly Detection in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Huertas Celdran, Alberto
    Garcia Clemente, Felix J.
    SYMMETRY-BASEL, 2020, 12 (10):
  • [28] etecting a Weakened Encryption Algorithm in Microcontrollers Using Correlation-Based Anomaly Detection
    Wylie, Justin
    Stone, Samuel
    Mullins, Barry
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2016), 2016, : 335 - 343
  • [29] Assessing Anomaly-Based Intrusion Detection Configurations for Industrial Control Systems
    Gillen, Robert E.
    Carter, Jason M.
    Craig, Christopher
    Johnson, Jordan A.
    Scott, Stephen L.
    2020 21ST IEEE INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (IEEE WOWMOM 2020), 2020, : 360 - 366
  • [30] Self-similarity based network anomaly detection for industrial control systems
    Martin, Bryan
    Bollmann, Chad A.
    2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS, 2023,