Explainable correlation-based anomaly detection for Industrial Control Systems

被引:0
|
作者
Birihanu, Ermiyas [1 ]
Lendak, Imre [1 ]
机构
[1] Eotvos Lorand Univ, Fac Informat, Data Sci & Engn Dept, Budapest, Hungary
来源
关键词
anomaly detection; correlation; explainable; Industrial Control System; root cause analysis;
D O I
10.3389/frai.2024.1508821
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Anomaly detection is vital for enhancing the safety of Industrial Control Systems (ICS). However, the complicated structure of ICS creates complex temporal correlations among devices with many parameters. Current methods often ignore these correlations and poorly select parameters, missing valuable insights. Additionally, they lack interpretability, operating efficiently with limited resources, and root cause identification. This study proposes an explainable correlation-based anomaly detection method for ICS. The optimal window size of the data is determined using Long Short-Term Memory Networks-Autoencoder (LSTM-AE) and the correlation parameter set is extracted using the Pearson correlation. A Latent Correlation Matrix (LCM) is created from the correlation parameter set and a Latent Correlation Vector (LCV) is derived from LCM. Based on the LCV, the method utilizes a Multivariate Gaussian Distribution (MGD) to identify anomalies. This is achieved through an anomaly detection module that incorporates a threshold mechanism, utilizing alpha and epsilon values. The proposed method utilizes a novel set of input features extracted using the Shapley Additive explanation (SHAP) framework to train and evaluate the MGD model. The method is evaluated on the Secure Water Treatment (SWaT), Hardware-in-the-loop-based augmented ICS security (HIL-HAI), and Internet of Things Modbus dataset using precision, recall, and F-1 score metrics. Additionally, SHAP is used to gain insights into the anomalies and identify their root causes. Comparative experiments demonstrate the method's effectiveness, achieving a better 0.96% precision and 0.84% F1-score. This enhanced performance aids ICS engineers and decision-makers in identifying the root causes of anomalies. Our code is publicly available at a GitHub repository: https://github.com/Ermiyas21/Explainable-correlation-AD.
引用
收藏
页数:14
相关论文
共 50 条
  • [41] Research on Improvement of Anomaly Detection Performance in Industrial Control Systems
    Bae, Sungho
    Hwang, Chanwoong
    Lee, Taejin
    INFORMATION SECURITY APPLICATIONS, 2021, 13009 : 76 - 87
  • [42] State-Aware Anomaly Detection for Industrial Control Systems
    Ghaeini, Hamid Reza
    Antonioli, Daniele
    Brasser, Ferdinand
    Sadeghi, Ahmad-Reza
    Tippenhauer, Nils Ole
    33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1620 - 1628
  • [43] An Anomaly Detection Technique for Deception Attacks in Industrial Control Systems
    Qassim, Q. S.
    Ahmad, A. R.
    Ismail, R.
    Bakar, Abu A.
    Rahim, Abdul F.
    Mokhtar, M. Z.
    Ramli, R.
    Mohd, Yusof B.
    Mahdi, Mohammed Najah
    2019 IEEE 5TH INTL CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY) / IEEE INTL CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING (HPSC) / IEEE INTL CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2019, : 267 - 272
  • [44] Anomaly detection using invariant rules in Industrial Control Systems
    Zhu, Qilin
    Ding, Yulong
    Jiang, Jie
    Yang, Shuang-Hua
    CONTROL ENGINEERING PRACTICE, 2025, 154
  • [45] A Machine Learning Approach for Anomaly Detection in Industrial Control Systems Based on Measurement Data
    Mokhtari, Sohrab
    Abbaspour, Alireza
    Yen, Kang K.
    Sargolzaei, Arman
    ELECTRONICS, 2021, 10 (04) : 1 - 13
  • [46] TABOR: A Graphical Model-based Approach for Anomaly Detection in Industrial Control Systems
    Lin, Qin
    Adepu, Sridhar
    Verwer, Sicco
    Mathur, Aditya
    PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, : 525 - 536
  • [47] Using timing-based side channels for anomaly detection in industrial control systems
    Dunlap, Stephen
    Butts, Jonathan
    Lopez, Juan
    Rice, Mason
    Mullins, Barry
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2016, 15 : 12 - 26
  • [48] Anomaly Detection based on Robust Spatial-temporal Modeling for Industrial Control Systems
    Li, Shijie
    Liu, Junjiao
    Pan, Zhiwen
    Lv, Shichao
    Si, Shuaizong
    Sun, Limin
    2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 355 - 363
  • [49] An error neighborhood-based detection mechanism to improve the performance of anomaly detection in industrial control systems
    Shen, Wendi
    Yang, Genke
    2022 INTERNATIONAL CONFERENCE ON MECHANICAL, AUTOMATION AND ELECTRICAL ENGINEERING, CMAEE, 2022, : 25 - 29
  • [50] Scale correlation-based edge detection
    Bao, P
    Lei, Z
    PROCEEDINGS VIPROMCOM-2002, 2002, : 345 - 350