arrow
返回

Anomaly detection for industrial control systems using process mining

delete2018-09-01
delete68
delete
OA
AI
D
D. Brenton Myers *
S
Suriadi Suriadi
K
Kenneth Radke
E
Ernest Foo
DOI:10.1016/j.cose.2018.06.002delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Industrial control systems (ICS) are moving from dedicated communications to switched and routed corporate networks, exposing them to the Internet and placing them at risk of cyber-attacks. Existing methods of detecting cyber-attacks, such as intrusion detection systems (IDSs), are commonly implemented in ICS and SCADA networks. However, these devices do not detect more complex threats that manifest themselves gradually over a period of time through a combination of unusual sequencing of activities, such as process-related attacks. During the normal operation of ICSs, ICS devices record device logs, capturing their industrial processes over time. These logs are a rich source of information that should be analysed in order to detect such process-related attacks. In this paper, we present a novel process mining anomaly detection method for identifying anomalous behaviour and cyber-attacks using ICS data logs and the conformance checking analysis technique from the process mining discipline. A conformance checking analysis uses logs captured from production systems with a process model (which captures the expected behaviours of a system) to determine the extent to which real behaviours (captured in the logs) matches the expected behaviours (captured in the process model). The contributions of this paper include an experimentally derived recommendation for logging practices on ICS devices, for the purpose of process mining-based analysis; a formalised approach for pre-processing and transforming device logs from ICS systems into event logs suitable for process mining analysis; guidance on how to create a process model for ICSs and how to apply the created process model through a conformance checking analysis to identify anomalous behaviours. Our anomaly detection method has been successfully applied in detecting ICS cyber-attacks, which the widely used IDS Snort does not detect, using logs derived from industry standard ICS devices. (C) 2018 Elsevier Ltd. All rights reserved.
Keyword:
ICS
SCADA
Critical infrastructure
Security
Cyber attack
Process mining
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

暂无机构信息
引用论文

引用论文

err分享
err收藏
Security issues in SCADA networks
err2006-10-01
err378
PREAI
errIgure, Vinay M.; Laughter, Sean A.; Williams, Ronald D.
err分享
err收藏
Linking data and process perspectives for conformance analysis链接数据和流程视角以进行一致性分析
err2018-03-01
err49
PREAI
errAlizadeh, Mandi; Lu, Xixi; Fahland, Dirk; Zannone, Nicola; van der Aalst, Wil M. P.
err分享
err收藏
err分享
err收藏
Event interval analysis: Why do processes take time?
err2015-11-01
err24
errOAAI
errSuriadi, Suriadi; Ouyang, Chun; van der Aalst, Wil M. P.; ter Hofstede, Arthur H. M.
err分享
err收藏
The X-ray structure of human serum ceruloplasmin at 3.1 Å: nature of the copper centres
err1996-02-01
err0
PREAI
errIrina Zaitseva; Vjacheslav Zaitsev; Graeme Card; Kirill Moshkov; Benjamin Bax; Adam Ralph; Peter Lindley
err分享
err收藏
Clients’ perspectives on HIV/AIDS care and treatment and reproductive health services in South Africa
err2008-11-13
err0
PREAI
errPhyllis Orner; Diane Cooper; Landon Myer; Virginia Zweigenthal; Linda-Gail Bekker; Jennifer Moodley
err分享
err收藏
学者 查看更多内容