Attacks on Industrial Control Systems Modeling and Anomaly Detection

被引:1
|
作者
Eigner, Oliver [1 ]
Kreimel, Philipp [1 ]
Tavolato, Paul [1 ]
机构
[1] Univ Appl Sci St Polten, Matthias Corvinus Str 15, St Polten, Austria
关键词
Industrial Control System; Modeling Procedure; Anomaly Detection; Machine Learning;
D O I
10.5220/0006755405810588
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial control systems play a crucial role in a digital society, particularly when they are part of critical infrastructures. Unfortunately traditional intrusion defense strategies for IT systems are often not applicable in industrial environments. A continuous monitoring of the operation is necessary to detect abnormal behavior of a system. This paper presents an anomaly-based approach for detection and classification of attacks against industrial control systems. In order to stay close to practice we set up a test plant with sensors, actuators and controllers widely used in industry, thus, providing a test environment as close as possible to reality. First, we defined a formal model of normal system behavior, determining the essential parameters through machine learning algorithms. The goal was the definition of outlier scores to differentiate between normal and abnormal system operations. This model of valid behavior is then used to detect anomalies. Further, we launched cyber-attacks against the test setup in order to create an attack model by using naive Bayes classifiers. We applied the model to data from a real industrial plant. The test showed that the model could be transferred to different industrial control systems with reasonable adaption and training effort.
引用
收藏
页码:581 / 588
页数:8
相关论文
共 50 条
  • [41] Assessing Anomaly-Based Intrusion Detection Configurations for Industrial Control Systems
    Gillen, Robert E.
    Carter, Jason M.
    Craig, Christopher
    Johnson, Jordan A.
    Scott, Stephen L.
    2020 21ST IEEE INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (IEEE WOWMOM 2020), 2020, : 360 - 366
  • [42] Opportunities for Early Detection and Prediction of Ransomware Attacks against Industrial Control Systems
    Gazzan, Mazen
    Sheldon, Frederick T.
    FUTURE INTERNET, 2023, 15 (04):
  • [43] Evaluation of Machine Learning Algorithms Used on Attacks Detection in Industrial Control Systems
    Arora, Pallavi
    Kaur, Baljeet
    Teixeira, Marcio Andrey
    Journal of The Institution of Engineers (India): Series B, 2021, 102 (03) : 605 - 616
  • [44] Self-similarity based network anomaly detection for industrial control systems
    Martin, Bryan
    Bollmann, Chad A.
    2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS, 2023,
  • [45] An improved autoencoder-based approach for anomaly detection in industrial control systems
    Aslam, Muhammad Muzamil
    Tufail, Ali
    De Silva, Liyanage Chandratilak
    Haji Mohd Apong, Rosyzie Anna Awg
    Namoun, Abdallah
    SYSTEMS SCIENCE & CONTROL ENGINEERING, 2024, 12 (01)
  • [46] Federated Learning-Based Explainable Anomaly Detection for Industrial Control Systems
    Huong, Truong Thu
    Bac, Ta Phuong
    Ha, Kieu Ngan
    Hoang, Nguyen Viet
    Hoang, Nguyen Xuan
    Hung, Nguyen Tai
    Tran, Kim Phuc
    IEEE ACCESS, 2022, 10 : 53854 - 53872
  • [47] Evaluation of Machine Learning Algorithms Used on Attacks Detection in Industrial Control Systems
    Arora P.
    Kaur B.
    Teixeira M.A.
    Journal of The Institution of Engineers (India): Series B, 2021, 102 (3) : 605 - 616
  • [48] Dynamic Data Abstraction-Based Anomaly Detection for Industrial Control Systems
    Cho, Jake
    Gong, Seonghyeon
    ELECTRONICS, 2024, 13 (01)
  • [49] Adversarial Attacks on Time-Series Intrusion Detection for Industrial Control Systems
    Zizzo, Giulio
    Hankin, Chris
    Maffeis, Sergio
    Jones, Kevin
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 900 - 911
  • [50] Detection and mitigation of deception attacks on cloud-based industrial control systems
    Akbarian, Fatemeh
    Tarneberg, William
    Fitzgerald, Emma
    Kihl, Maria
    25TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS (ICIN 2022), 2022, : 106 - 110