arrow
返回

Multilayer Data-Driven Cyber-Attack Detection System for Industrial Control Systems Based on Network, System, and Process Data

delete2019-07-01
delete217
PRE
AI
F
Fan Zhang
H
Hansaka Angel Dias Edirisinghe Kodituwakku
J
J. Wesley Hines
J
Jamie Coble *
DOI:10.1109/TII.2019.2891261delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The growing number of attacks against cyberphysical systems in recent years elevates the concern for cybersecurity of industrial control systems (ICSs). The current efforts of ICS cybersecurity are mainly based on firewalls, data diodes, and other methods of intrusion prevention, which may not be sufficient for growing cyber threats from motivated attackers. To enhance the cybersecurity of ICS, a cyber-attack detection system built on the concept of defense-in-depth is developed utilizing network traffic data, host system data, and measured process parameters. This attack detection system provides multiple-layer defense in order to gain the defenders precious time before unrecoverable consequences occur in the physical system. The data used for demonstrating the proposed detection system are from a real-time ICS testbed. Five attacks, including man in the middle (MITM), denial of service (DoS), data exfiltration, data tampering, and false data injection, are carried out to simulate the consequences of cyber attack and generate data for building data-driven detection models. Four classical classification models based on network data and host system data are studied, including k-nearest neighbor (KNN), decision tree, bootstrap aggregating (bagging), and random forest (RF), to provide a secondary line of defense of cyber-attack detection in the event that the intrusion prevention layer fails. Intrusion detection results suggest that KNN, bagging, and RF have low missed alarm and false alarm rates for MITM and DoS attacks, providing accurate and reliable detection of these cyber attacks. Cyber attacks that may not be detectable by monitoring network and host system data, such as command tampering and false data injection attacks by an insider, are monitored for by traditional process monitoring protocols. In the proposed detection system, an auto-associative kernel regression model is studied to strengthen early attack detection. The result shows that this approach detects physically impactful cyber attacks before significant consequences occur. The proposed multiple-layer data-driven cyber-attack detection system utilizing network, system, and process data is a promising solution for safeguarding an ICS.
Keyword:
Cyber-attack detection
data-driven monitoring
defense-in-depth
industrial control system (ICS)
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Industrial Informatics 封面图
IEEE Transactions on Industrial Informatics
IF:
9.9
论文数:
8.6K
被引数:
6.0W

机构

U
University of Tennessee Knoxville
学者数:
1.1W
论文数: 9.4K
被引数: 17
University of Tennessee System 封面图
University of Tennessee System
学者数:
2.9W
论文数: 2.7W
被引数: 115
引用论文

引用论文

err分享
err收藏
High-performance MW and LW IRFPAs made from HgCdTe grown by MOVPE
err2006-05-05
err0
PREAI
errC. L. Jones; L. G. Hipwood; C. J. Shaw; J. P. Price; R. A. Catchpole; M. Ordish; C. D. Maxey; H. W. Lau; R. C. Mistry; M. C. Wilson; A. D. Parsons; J. Gillespie; L. Baggaley; M. Wallis
err分享
err收藏
err分享
err收藏
学者 查看更多内容